Burp Suite User Forum

Create new post

Failed Interception.

Othman | Last updated: Mar 17, 2022 10:29AM UTC

Hey guys, I am trying to proxy a certain web application through burp but it seems to deny any requests from an authenticated user. I can't access the login page with my proxy turned on. And if I login and turn on my proxy, I am immediately logged out of the application. Is this a common feature in most web applications or is there an insecure configuration in my burp that is detected by the application?

Uthman, PortSwigger Agent | Last updated: Mar 17, 2022 11:04AM UTC

Hi Othman,

Have you checked if the application has some logic to detect the use of a proxy > Automatically log you out (i.e. some type of proxy-blocking functionality)?

You mentioned that you can't access the login page with your proxy turned on. Can you clarify what this looks like? Are you using the embedded browser? Or an external browser? Are you seeing any errors in the Event log in Burp?

Please send screenshots or a screen recording of the issue replicated along with diagnostics (Help > Diagnostics) to support@portswigger.net

Othman | Last updated: Mar 17, 2022 12:31PM UTC

Hi Uthman. I was using an external browser (Firefox) I've switched to the embedded chromium browser but I still get the same error. The error states "<site> redirected too many times, try clearing your cookies" I cleared the cookies but I still got the same error. I checked the event logs and there wasn't much there, one communication error with the api and the rest were info about the site using HTTP/2 (I doubt that is an issue). I'm not conversant with how to detect if the application is using some proxy-blocking mechanism, any tips?

Uthman, PortSwigger Agent | Last updated: Mar 17, 2022 01:55PM UTC

Othman | Last updated: Mar 17, 2022 03:36PM UTC

Hi Uthman I started over with a new burp instance on another machine and it worked. I was using a scope config file given by the site, turns out it was badly set up (I'm not sure how) but it may have been causing the redirects prompting the automatic logging out issue. I good now, I don't think this was a burp issue but look it up for the sake of it incase someone raises the issue in future. Thanks for the help :) great response time. Oh and...great name too haha.

Uthman, PortSwigger Agent | Last updated: Mar 17, 2022 07:46PM UTC

Hi Othman,

No problem at all. Great to hear that it now works!

Your name isn't too bad either ;D

You must be an existing, logged-in customer to reply to a thread. Please email us for additional support.