The Burp Suite User Forum was discontinued on the 1st November 2024.

Burp Suite User Forum

For support requests, go to the Support Center. To discuss with other Burp users, head to our Discord page.

SUPPORT CENTER DISCORD

automatically scan the web site

hong | Last updated: Jan 06, 2017 05:11PM UTC

Hi, my goal is to using Burp as a vulnerability scanner and scan the web site automatically. I built site map using spider and content discover, followed the instruction "using burp as a point-and-click scanner". Then I did "active scan" on the host/branch. In the middle of the active scan, seems it automatically logged out of web server, and all the subsequent scan are redirected to log in page, which did not scan the real pages. How do I solve this problem? Also, if I save the site map, I am not able to do "active scan" on the host, since the request has the expired login info, the tokens are all expired. How do I achieve my goal? my plan was to save the site map, and load it each time I need to do automatic scan. Really need some help here! I did set up the user/password in the spider and the options->connections. Thanks

PortSwigger Agent | Last updated: Jan 09, 2017 09:14AM UTC