The Burp Suite User Forum was discontinued on the 1st November 2024.

Burp Suite User Forum

For support requests, go to the Support Center. To discuss with other Burp users, head to our Discord page.

SUPPORT CENTER DISCORD

one web browser action but two request sending from client to server (session with tokens)

Pawel | Last updated: Feb 10, 2019 05:30PM UTC

Hello Friends I have two questions. First: I would like to do bruteforce for user's password. I know how to set burp suite for it but the website which I testing, after I add username and password the request to server is sending and I get back "token". Second request to server is sending with the token only. After that the server give me te reply. Do you know how to configure burb suite to use it for brute the password of username? Second: Similar situation if I download the file. After I click download by webbrowser, the reqest to server is sending with IDfiles in POST method, servr give me the token, after this the second request is sending in GET with token and than server give me reply (file is dowloaded). I would like to check other IDfiles if exist ;). Can you tell my how to configure burb suite to use it for test of it? Thanks in advance Pawel

PortSwigger Agent | Last updated: Feb 11, 2019 09:08AM UTC