The Burp Suite User Forum will be discontinued on the 1st November 2024.

Burp Suite User Forum

For support requests, go to the Support Centre. To discuss with other Burp users, head to our Discord page.

SUPPORT CENTRE DISCORD

Create new post

Can Scanner works with Match and Replace option from Proxy?

Roman | Last updated: Jun 09, 2016 11:46AM UTC

Hi, Can Scanner works with Match and Replace options from Proxy? I have several instances of web applications with different versions and fixes. UI part has not been changed for all instances. But test data like accounts are different. So I would like to use saved state (pages) for one web app instance to scan other instances using different domains and test data.

Liam, PortSwigger Agent | Last updated: Jun 09, 2016 01:08PM UTC

Hi Roman Thanks for your message. You can use the Match and Replace rules to alter base requests and the Scanner will scan these requests while respecting the applied rule/s. However, for your use case you may have to look at creating an extension that would perform the required functionality. - https://portswigger.net/burp/extender/ Please let us know if you need any further assistance.

Burp User | Last updated: Apr 20, 2019 02:29AM UTC

Hi Liam, I have searched for a while on the issue about the match and replace operations in scanning. Is there any feature or solutions to match and replace the based requests in sitemap or history? I need to scan those requests by changing their custom auth header. I couldn't find a good extension or plugin to work it out.

Liam, PortSwigger Agent | Last updated: Apr 23, 2019 02:33PM UTC

Have you tried using Burp's session handling rules? Do be aware that these settings won't apply to auth headers, you'll need to use session handling rules in conjunction with the Add Custom Header extension: - https://support.portswigger.net/customer/en/portal/articles/2363088-configuring-burp-s-session-handling-rules - https://portswigger.net/bappstore/807907f5380c4cb38748ef4fc1d8cdbc Please let us know if you need any further assistance.

You must be an existing, logged-in customer to reply to a thread. Please email us for additional support.