The Burp Suite User Forum was discontinued on the 1st November 2024.

Burp Suite User Forum

For support requests, go to the Support Center. To discuss with other Burp users, head to our Discord page.

SUPPORT CENTER DISCORD

Duo/MFA Authentication

Chris | Last updated: Dec 10, 2021 12:45AM UTC

With Zap I can do manual authentication: simply launch the browser, do my sites' crazy MFA routine, and get a session. Then I can hit scan. Burp for scans and spiders seems to want to handle the authentication "for me" in simplistic user/password or the overly complicated recorded sequence method. Is there no way to manually authenticate to the application and then launch a spider/scan? Seems like an interesting design decision if so.

Alex, PortSwigger Agent | Last updated: Dec 14, 2021 01:55PM UTC