Burp Suite User Forum

Create new post

Repeat spidering with corrected authentication

AC | Last updated: Jul 30, 2018 12:17AM UTC

I spidered a site, and many of the pages returned 401s. I've since fixed the project authentication settings, and I want to re-spider the pages that returned 401s. If I select the target and send it to spider, nothing happens because Burp thinks everything's already been spidered. Also, I'd like to see the good (authenticated) reponses in the Site map. Currently I'm only seeing that uninformative 401 responses, even when subsequent more interesting responses have been generated for a URL path. Thanks for your help!

PortSwigger Agent | Last updated: Jul 30, 2018 12:30PM UTC

In this case your best option is to delete the 401 pages. If you haven't done any manual crawling I would just delete the whole host from the site map. If you want to keep manual crawling, select the host in the tree, and use the filter to only show 4xx responses. Then select everything in Contents and delete that.

You must be an existing, logged-in customer to reply to a thread. Please email us for additional support.