Burp Suite User Forum

Create new post

Restrict Sites on Burp Enterprise API

Michael | Last updated: Mar 25, 2019 06:54PM UTC

We'd like to restrict the sites users can run scans against in Burp Enterprise, and I've configured Groups with site restrictions and have added the sites in folders on the site tree. So basically looks like Group 1 Name (top) - Site 1 - Site 2 Group 2 Name (top) - Site 1 - SIte 2 Yet when I call the API to run the scan using their API key, I constantly get a 401. I don't want them be able to scan every site out there, just the ones we've configured. Any clues on how to run scans on the configured sites?

Liam, PortSwigger Agent | Last updated: Mar 26, 2019 10:03AM UTC

Michael, we've just tried this set up out and it worked for us. Could you send us screenshots of your: - Site tree - Group config with site restrictions - Site and scan data settings - API builder view including the curl command. You can send relevant information to support@portswigger.net. Thanks.

You must be an existing, logged-in customer to reply to a thread. Please email us for additional support.