Burp Suite User Forum

Create new post

NTLM EPA support

Jorik | Last updated: Jun 06, 2023 09:17AM UTC

For a client I'm testing an application with NTLM authentication. With Chrome I could login, but not with Burp or Firefox. After days of digging I came across the following article: https://www.synacktiv.com/en/publications/dissecting-ntlm-epa-with-love-building-a-mitm-proxy With the Proxy-Ez I can authenticate with Burp, but it still has it limitations. Somehow the Intruder doesn’t work, while the Repeater does. Native NTLM EPA support in Burp would be useful, are there any plans on doing this?

Dominyque, PortSwigger Agent | Last updated: Jun 06, 2023 10:19AM UTC

Hi Thank you for your question about NTLM. We have an ongoing feature request for this functionality, to which I have added your +1.

You must be an existing, logged-in customer to reply to a thread. Please email us for additional support.