Burp Suite User Forum

Create new post

Feed response of first response for other request as input during scan

Praveen | Last updated: May 30, 2019 06:56AM UTC

I am facing issue when I trigger the scan on few requests. The scenario is, many of the requests in my application required API key as authorization value and key the can be used only once per request. If I trigger the scan on these requests, I am not able to perform the scans because of invalid keys because the Scanner use same key through out the scan. I have a request where I can generate the keys but I am not able to figure out, how to feed the key for every request when the scan is running on it. Is there any way of doing this with Scanner requests.

Liam, PortSwigger Agent | Last updated: May 30, 2019 02:38PM UTC

Praveen, which version of Burp are you using?

Burp User | Last updated: Jun 06, 2019 06:09AM UTC

We use 1.7.37 version

PortSwigger Agent | Last updated: Jun 06, 2019 10:28AM UTC

The features that can help you with this are macros and session handling rules. This tutorial is similar to your situation: - https://support.portswigger.net/customer/portal/articles/2906338-using-burp-s-session-handling-rules-with-anti-csrf-tokens

You must be an existing, logged-in customer to reply to a thread. Please email us for additional support.