Burp Suite User Forum

Create new post

Dynamic URL cannot be spidered or scanned

Henry | Last updated: Nov 29, 2016 03:59AM UTC

Hi, We have an issue with a site that all the URL are generated on the fly with random URL string. They can only be clicked once. Any request sent to the same URL will invalidate the session. So spidering and scanning will always result in invalidation of session. Could you please suggest how we can scan the web site? Thanks. Best, Henry

PortSwigger Agent | Last updated: Nov 29, 2016 09:55AM UTC

There isn't currently an effective way to use Burp Scanner on an application like this, since the URLs are one-time only, and Burp works by sending multiple requests derived from the same base request. We are working on some long-term enhancements to Burp that will enable it to deal with this situation more effectively, and operate with applications where the entire URL is ephemeral and changes on each use.

You must be an existing, logged-in customer to reply to a thread. Please email us for additional support.