The Burp Suite User Forum was discontinued on the 1st November 2024.

Burp Suite User Forum

For support requests, go to the Support Center. To discuss with other Burp users, head to our Discord page.

SUPPORT CENTER DISCORD

Burp 2FA integration - Disable human intervention during 2FA process

Tal | Last updated: Dec 29, 2016 09:49AM UTC

Hi, In today's best practice, medium risk and above applications implement some form of 2FA solution with sensitive functionality like authentication , forgot password, enabling transaction, account activation etc. Challenge: If the application implements 2FA, then the user that operates Burp suite must intervene in the process of the 2FA when the session becomes invalid. Solution: Burp needs a mobile application that can communicate with burp suite instance that supports few common mobile 2FA solutions like SMS, soft-tokens etc. Best regards, Tal

PortSwigger Agent | Last updated: Jan 03, 2017 10:21AM UTC