Burp Suite User Forum

Create new post

See the requests being made while active scanning

Robin | Last updated: May 17, 2018 11:31AM UTC

I'm trying to do active scanning on my current test but I've got a problem that the login session occasionally dies for no apparent reason and when it does this in the middle of a scan the results from that point on are redundant. It would be good to be able to watch the requests and responses to see if the session dies so I can pause it and reauthenticate. I can't use a macro to do the auth as it is 2FA via SMS. This would also be useful on sites where one of the tests triggers a crash in the site so I can figure out which one it was. I've got round it in the past by running the scanning Burp through a second Burp on another box but that isn't ideal.

Liam, PortSwigger Agent | Last updated: May 17, 2018 12:45PM UTC

You can install the Flow extension from the BApp store. This extension can be used to log the requests and responses of any of Burp's tools; including Burp Scanner: - https://portswigger.net/bappstore/ee1c45f4cc084304b2af4b7e92c0a49d Please let us know if you need any further assistance.

Burp User | Last updated: May 17, 2018 01:03PM UTC

I'll give that a try, thanks

Burp User | Last updated: Apr 09, 2019 12:00PM UTC

One technique that works for me to see any tool's requests (including Burp's) while scanning, is by having it go through another instance of Burp.

You must be an existing, logged-in customer to reply to a thread. Please email us for additional support.