The Burp Suite User Forum was discontinued on the 1st November 2024.

Burp Suite User Forum

For support requests, go to the Support Center. To discuss with other Burp users, head to our Discord page.

SUPPORT CENTER DISCORD

Find pages that should be protected by a session cookie

Keith | Last updated: Apr 12, 2024 11:03AM UTC

I'm using burp suite pro and an authenticated scan generates the target map of my web app. I want to automate a check to find pages that generate a valid response (non 303) when a session cookie is not provided. I've used the repeater to manually find unprotected pages, is there a method to re-scan the target map with none or invalid cookies?, I want to find map pages that are not generating the 303 redirect to the login page.

Syed, PortSwigger Agent | Last updated: Apr 15, 2024 09:21AM UTC