Burp Suite User Forum

Create new post

Burp Pro v2022.2 How to minimize number of logging in during crawl and audit

Michael | Last updated: Feb 28, 2022 09:06PM UTC

Watching the Logger tab, I notice during the audit phase it's constantly re-logging into the site. When it was auditing one URL it took about 35-40mins. I see for every 2-3 requests it logs in again. It seems like it's starting a new session every few URLs, which seems to slow down the audit. The crawler found like 800+ locations for auditing. If it averages 40mins per location that's about 533 hours of auditing... Is there a way to not log in as much?

Hannah, PortSwigger Agent | Last updated: Mar 01, 2022 09:18AM UTC

Hi You could use our newly released "ultra-fast" crawl. This disables features like automated session handling and state recovery, so will log in far less frequently. You can use this by setting your "Crawl configuration > Crawl optimization" to "Fastest", or by setting up your scan as normal and going to "Crawl configuration > Crawl optimization > Cog button > Customize crawl strategy" and check the "Incy Wincy" box. You will need to be using the latest "Early Adopter" version of Burp to use this feature. You can find out more information about this crawl mode in our release notes here: https://portswigger.net/burp/releases/professional-community-2022-2

Michael | Last updated: Mar 01, 2022 09:52PM UTC

Thanks! I definitely don't see it constantly need to log in again. It's crawling and auditing a lot faster with this setting.

You must be an existing, logged-in customer to reply to a thread. Please email us for additional support.