Burp Suite User Forum

Create new post

Can I use Burp Suite Professional with SAML and Okta (w/ security code).

Clinton | Last updated: Aug 17, 2021 02:36PM UTC

I'm Using Burpsuite Professional and have a new scan that I need to conduct that requires the following: Can I use Burp Professional for sites that are SAML enabled? Okta has a MFA process. After entering the okta credentials, they text message a security code that has to be entered. How do I work around this with the current professional version of the scanner?

Uthman, PortSwigger Agent | Last updated: Aug 18, 2021 08:10AM UTC

Hi Clinton, I have replied directly to you via email regarding the same issue. Adding here too in the interest of clarity: The recorded login sequence feature will handle the Okta login provided it meets the prerequisites in the documentation below: - https://portswigger.net/burp/documentation/desktop/scanning/recorded-logins - https://portswigger.net/blog/recorded-logins-in-burp-scanner In terms of the 2FA code, these are notoriously difficult for automated scanners to handle. I presume the token needs to be refreshed every X minutes so there is no accurate way for the scanner to record/replay a sequence with a new code received via SMS. The exception to this could be a static token i.e. it only needs to be entered once and never expires. You can ask the user to either disable the 2FA code whilst scanning the application or try to configure a second step (e.g. a security question) that can be easily replayed by the scanner. For anyone else facing this issue, please reach out to support@portswigger.net if you have any questions.

You must be an existing, logged-in customer to reply to a thread. Please email us for additional support.