The Burp Suite User Forum was discontinued on the 1st November 2024.

Burp Suite User Forum

For support requests, go to the Support Center. To discuss with other Burp users, head to our Discord page.

SUPPORT CENTER DISCORD

NTLM Replay

Joel | Last updated: Jul 23, 2018 03:22PM UTC

Currently if I want to browse some website through Burp with an NTLM authentication I need to provide to Burp the credentials. Since by design NTLM is prone to re(p)lay attack, why can't Burp just replay the challenges and responses withoout needing the credentials? Thank you Joel

PortSwigger Agent | Last updated: Jul 24, 2018 07:29AM UTC