The Burp Suite User Forum was discontinued on the 1st November 2024.

Burp Suite User Forum

For support requests, go to the Support Center. To discuss with other Burp users, head to our Discord page.

SUPPORT CENTER DISCORD

Autorize - IDOR Test

Alberto | Last updated: Sep 21, 2021 02:28PM UTC

Hi, Right now I'm using Burp Extension Autorize to test for IDOR. I'm curious if there is any way, or maybe another extension, to make Autorize more automatic. For example, now I click on every button on the site to be sure I got all possible path or api. Then I start analyzing the result to find if there are false positive and I put them out of scope. Then, If I i want to see the effect of removing them from the scope I need to click all again and If the web application is big I can't click again every single time I remove something from the scope. So I would like to know if there is any way to automatically update the list I already done. Thanks, Alberto

Hannah, PortSwigger Agent | Last updated: Sep 22, 2021 08:52AM UTC