The Burp Suite User Forum was discontinued on the 1st November 2024.

Burp Suite User Forum

For support requests, go to the Support Center. To discuss with other Burp users, head to our Discord page.

SUPPORT CENTER DISCORD

Burp authenticated scans

Anton | Last updated: Oct 21, 2020 04:29PM UTC

Hello, QA version of my web-site contains standard authentication form, so I need scanner to use credentials to perform vulnerability scan. I tried to provide credentials to the Burp Scanner, but it seems that it didn't even try to use them (requests didn't contain any credentials, and scan resulted in error). I was trying both methods - just simply added user and password to scan settings, and tried to use "Burp Suite Navigation Recorder". I didn't get any output from the recorder, because for some reason it always starting the record AFTER i put my credentials into the login form. Could you please advice me an approach to perform credentials scan ?

Ben, PortSwigger Agent | Last updated: Oct 22, 2020 11:11AM UTC