Burp Suite User Forum

Create new post

Automatic Header Token Problem

Marco | Last updated: May 24, 2019 11:27AM UTC

Hello, Most websites are using header token. But token is changing after every payload. Tokens does not appear on the Response. How to generate automatic header token with Burp Suite? For example(request header); x-api-key: 34931ab55d095c37cb78f7ad2061922e32d235e1 x-api-hash: 0358df659215415a347405743a0b74a3 x-timestamp: 1558694341251 x-xsrf-token: 8129ea0d08c5bgc6f1ba9db2ds3361415fbd3357 Thanks.

Rose, PortSwigger Agent | Last updated: May 24, 2019 02:24PM UTC

Have you tried using the Add Custom Header extension from the BApp store? - https://portswigger.net/bappstore/807907f5380c4cb38748ef4fc1d8cdbc

Burp User | Last updated: Jun 07, 2019 12:40PM UTC

Yes, But I need more than one header parameter. This extension doesn't meet my need.

Liam, PortSwigger Agent | Last updated: Jun 07, 2019 12:51PM UTC

Marco, it sounds like you'll need to code your own version of this extension: - https://portswigger.net/burp/extender Alternatively, you could contact the authors of the extension with a feature request: - https://github.com/portswigger/add-custom-header

You must be an existing, logged-in customer to reply to a thread. Please email us for additional support.