Burp Suite User Forum

Create new post

Active Site scan with dynamic session id.

Whitlock, | Last updated: May 02, 2022 07:06PM UTC

I am attempting to complete a authenticated crawl and audit of my site that is configured to dynamically change the session ID for each login attempt. How do I capture the session ID and complete an authenticated crawl and audit without disruption. I have attempted static application login credentials in which the scan fails and starts looping through session ids. The recorded login just fails when configured within a scan.

Ben, PortSwigger Agent | Last updated: May 03, 2022 11:09AM UTC

Hi Jake, If you run a replay of your recorded login sequence (the details on how to perform a replay are documented here if you are unsure of how to carry this out - https://portswigger.net/burp/documentation/desktop/scanning/recorded-logins) does the replay work successfully outside of a scan? In addition to the above, are you able to provide us with some more details regarding both the site (is it publicly facing, for example) and the sequence that you have recorded? If you would prefer to share the details via email then please feel free to send us an email to support@portswigger.net.

You must be an existing, logged-in customer to reply to a thread. Please email us for additional support.