The Burp Suite User Forum was discontinued on the 1st November 2024.

Burp Suite User Forum

For support requests, go to the Support Center. To discuss with other Burp users, head to our Discord page.

SUPPORT CENTER DISCORD

How to integrate Google Authenticator Burp Extender with Session Macro

aej | Last updated: Sep 14, 2020 10:16AM UTC

My website have Two Factor Authentication. On successful User/Password combination, the site redirects to input Google Authenticator code from user. I am failing to create a successful macro, as the Google Authenticator code generates different code every time. I tried using Google Authenticator Extender but failed. This extender seems to be successful only if website use only Google Authenticator code for login and not Username/Password. Also, Macro --> Configure Item --> Parameter Handing --> has only 2 options to derive a value. One is from previous response and other preset value. If there was an option to derive the value from an extender, this would have worked. Is there any way to automate this scenario?

Uthman, PortSwigger Agent | Last updated: Sep 14, 2020 11:25AM UTC