Burp Suite User Forum

Create new post

Enterprise logging into a simple application

David | Last updated: Feb 13, 2020 04:07PM UTC

My application has a login form with 3 fields. Username Password and an ID. How do get enterprise to log in and scan past the login page? The application is simple, no fancy js doing the login, no https in my dev environment. Just has 3 fields instead of 2. My Version: 2020.2-3025, Java version: 9.0.4 I've created a login macro (that passes the validation test) with community, exported those project settings, and imported that into enterprise. Can't get past the log in page to crawl and scan the other URL's. Is their a tutorial for creating login macro's that WORK in enterprise? Maybe i missed something?

Hannah, PortSwigger Agent | Last updated: Feb 14, 2020 11:08AM UTC

Unfortunately, at present, this functionality is not available in Enterprise. As part of our roadmap for 2020 (https://portswigger.net/blog/burp-suite-roadmap-for-2020), we are working on improving our login sequences. This will provide improved coverage and accuracy over simple configured credentials, work with JavaScript-heavy login functions and single sign-on, and be much easier to configure than session handling rules.

You must be an existing, logged-in customer to reply to a thread. Please email us for additional support.