The Burp Suite User Forum was discontinued on the 1st November 2024.

Burp Suite User Forum

For support requests, go to the Support Center. To discuss with other Burp users, head to our Discord page.

SUPPORT CENTER DISCORD

If there a way of authenticating to a site that used multifactor authentication in Burp Suite Enterprise?

Glenn | Last updated: Oct 05, 2020 02:25PM UTC

We have many websites and are required to use multifactor authentication such as a user name and password and a text message to a phone or email. This is commonly called 2nd factor authentication. Is there are way Burp Suite Enterprise handles this two step authentication? Thanks, Glenn

Uthman, PortSwigger Agent | Last updated: Oct 05, 2020 03:38PM UTC

Hi Glenn, Unfortunately, this is not currently supported. We have released a recorded login feature but 2FA is out of scope for this. Does the text message or email contain a one-time token/password? (e.g. a 6-digit code) Does the token/password change on each login? Is it realistic for you to temporarily disable the 2FA?

Glenn | Last updated: Oct 05, 2020 04:03PM UTC

The text or email contains a one-time token and it changes on each login. The problem really is that we have scheduled scans once a month as well as ad hoc scans so disabling the 2FA is not really an action.

Uthman, PortSwigger Agent | Last updated: Oct 05, 2020 04:25PM UTC