Burp Suite User Forum

Create new post

Burp v2.0.03beta - Session Handling Rule can't be applied to Spider

Andrej | Last updated: Sep 03, 2018 01:06PM UTC

Iv'e tried to Edit the Session Handling Rule to include Spider in Scope, but without success. Every time I check it and press OK, it disappears. Since my app has a complex session management, I'd like my own session rule instead of the default username+password (since I have to enter PIN and that option is not present at the moment). Is this a feature, or bug?

PortSwigger Agent | Last updated: Sep 03, 2018 01:14PM UTC

At present this is intentional. The crawler has its own mechanisms that are somewhat similar to session handling rules. At this stage we're concerned that session handling rules will interfere with the crawler so they are not available. We are going to look at this area in future. We may be able to make session handling rules operate effectively with the crawler, or we may implement new functionality that replaces them. We'll let you know when we make progress.

You must be an existing, logged-in customer to reply to a thread. Please email us for additional support.