Burp Suite User Forum

Create new post

Configuring Macro Item

Karthik | Last updated: May 19, 2016 10:23AM UTC

I am trying to configure a login Macro and in the Macro Editor, Under the Macro Items, I have added sequence of URLs to be executed (I took this from Proxy) I click on one of the URLs and select, 'Configure Item'. In the 'Configure Macro Item', under 'Cookie Handling' I can see two options - Add cookies received in responses to the session handling cookie jar' - Use cookies from the session handling cookie jar in requests Question 1: I feel that these two options are mutually exclusive and only one option should be allowed - Could you please confirm ? Question 2: If I select both the options, if new cookies are received while macro gets executed, then cookies will be updated to the session handling cookie jar. and the newly updated cookies will be used for making requests - Is this correct ? Question 3: If there are 5 requests recorded in the Macro, and for the first request, is it required to select 'Use cookies from the session handling cookie jar in requests' - Login macro will be executed when session is invalid and when we say session is invalid, the cookies in the session handling cookie.jar will be invalid. With that said, can you confirm for the first request, do we need to select 'Use cookies from the session handling cookie jar in requests' ??

PortSwigger Agent | Last updated: May 19, 2016 10:37AM UTC

1. No, you can use both options. 2. That is right. One option determines whether requests are updated based on the cookie jar, and the other option determines whether the cookie jar is updated based on responses. 3. This really depends on the behavior of the application. I would suggest trying one option, using the session tracer to confirm whether the macro successfully creates a valid session, and changing the option if you need to.

You must be an existing, logged-in customer to reply to a thread. Please email us for additional support.