Burp Suite User Forum

Create new post

Scanning Peoplesoft application thorugh burpsuite

Behera, | Last updated: Oct 06, 2020 10:50PM UTC

We are performing a DAST scan for PeopleSoft application with password locked logic applied after 4 unsuccessful attempt. But during our burp scan we added the macro if the session is invalid so there is no way it will send the wrong userid/pswd but still the application getting locked during DAST scan. Please let me know if we can perform any configuration changes so that we can avoid the password locked during our DAST scanning. No of thread used: 5 No of retries : 3 Let me know if any other details required. Waiting for a quick response.

Liam, PortSwigger Agent | Last updated: Oct 07, 2020 07:29AM UTC

As part of the crawl process, Burp will attempt to self-register a user and trigger login failures. You can turn these features off via New Scan > Scan Configurations > New > Crawling > Login Functions. Please let us know if you need any further assistance.

Behera, | Last updated: Oct 07, 2020 01:22PM UTC

We are using v1.7.27. Please let me know which configuration needs to be disabled.

Liam, PortSwigger Agent | Last updated: Oct 08, 2020 09:28AM UTC

We'd recommend updating to the latest version of Burp Suite. Is there a reason you are using v1.7.27?

You must be an existing, logged-in customer to reply to a thread. Please email us for additional support.