Burp Suite User Forum

Create new post

Burp Suite Professional Depended Session Macros

Aditya | Last updated: Aug 06, 2021 06:34PM UTC

Hi Team, Currently, my application requires a certain cookie to be present for each request. When crawling the application automatically I am currently using the "Set a specific cookie or parameter value" before every request and setting the cookie. The above cookie expires after a certain time. I have a macro that can generate the new value of the cookie, is it possible for the macro to pass on the new cookie to the "Set a specific cookie or parameter value" session handling rule in case of an invalid session or after a specific time? Note: I am using the "Set a specific cookie or parameter value" session rule and not the cookie jar as for automated crawl tasks it was vetoing the other session handling rules, and I read a post that said the automated crawler has its own cookie jar. If the above is not possible do you have certain suggestions which can automate the scanning(crawling) of the application without using the login recorder as currently, it can't successfully record my sequence as posted here https://forum.portswigger.net/thread/burp-suite-login-recorder-b779ada1fb

Uthman, PortSwigger Agent | Last updated: Aug 09, 2021 08:58AM UTC

Hi Aditya, Have you tried using one of the extensions below instead? - Reshaper - https://portswigger.net/bappstore/7bcec7656b5746e9a85c427f243e6d5a - Authentication Token Obtain and Replace - https://portswigger.net/bappstore/51327b097b354243b307b4ed87ba39eb

You must be an existing, logged-in customer to reply to a thread. Please email us for additional support.