The Burp Suite User Forum was discontinued on the 1st November 2024.

Burp Suite User Forum

For support requests, go to the Support Center. To discuss with other Burp users, head to our Discord page.

SUPPORT CENTER DISCORD

Can Burp Pro find areas in a site where a token replay is possible?

Rick | Last updated: Nov 07, 2022 06:07PM UTC

I'm not sure I have seen this in Burp Pro auditing crawls I have done but is Burp able to see where a SessionID token can replace an existing SessionID to impersonate a different user? For example, if the cookie in the request Cookie: JSESSIONID=5XXXXXXXXXXXXXXXXXXXXX1 can be grabbed during an Intercept and then plugged in somewhere else. If so, I'd love to know where that is discovered in the audit reports. Thanks, Rick

Hannah, PortSwigger Agent | Last updated: Nov 08, 2022 09:47AM UTC