The Burp Suite User Forum was discontinued on the 1st November 2024.

Burp Suite User Forum

For support requests, go to the Support Center. To discuss with other Burp users, head to our Discord page.

SUPPORT CENTER DISCORD

Issue with platform authentication (NTLM)

Jonas | Last updated: Dec 12, 2020 11:43AM UTC

I have been using Burp with webapps using NTLMv2 auth several times without issue. However, in this particular case, I am unable to get it working properly. I have setup platform authentication under user options. I believe the settings is correct because I get a 401 “Invalid credentials” if those settings are not properly set. When logging in to the web app with Burp active, the app simply stucks in “loading”. Looking in http history, a series of three requests is simply looped until some timeout occurs. At that point the webbapp tells me that I already have a logged in session and have to login again. Logging in normally without using Burp, I cannot see the series of request being looped as when using Burp. My conclusion is that the webapp determines I have two parallel sessions (when proxying via BUrp) for some reason. Obviously I make sure to properly logout and clear browsing data between each attempt. Any ideas?

Hannah, PortSwigger Agent | Last updated: Dec 14, 2020 01:11PM UTC