Burp Suite User Forum

Create new post

Custom Header Application

ZEN | Last updated: Feb 06, 2020 05:46AM UTC

I have an application: api microservices, application_login, use access_token so as not to use a username and password when using Burpsuite enterprise, how do I do that?

Hannah, PortSwigger Agent | Last updated: Feb 06, 2020 08:25AM UTC

Hi, do you have access to a copy of Burp Suite Professional? We're currently working on improving application logins (https://portswigger.net/blog/burp-suite-roadmap-for-2020). However, it sounds like this is functionality you could achieve by importing some session handling rules from Burp Suite Professional into Enterprise.

Zen | Last updated: Feb 26, 2020 07:06AM UTC

Yes.. I'm use brupsuite Pro... so what should I do..?

Hannah, PortSwigger Agent | Last updated: Feb 26, 2020 12:12PM UTC

In your Burp Suite Pro installation, you can go to "Project options > Sessions > Session handling rules". From there, you can add a session handling rule to "Set a specific cookie or parameter value" in order to use your access token. You should check that this session handling rule is working in Professional first. The JSON can then be exported using the cog icon, and then imported into Enterprise on the "Scan configurations" page.

You must be an existing, logged-in customer to reply to a thread. Please email us for additional support.