The Burp Suite User Forum was discontinued on the 1st November 2024.

Burp Suite User Forum

For support requests, go to the Support Center. To discuss with other Burp users, head to our Discord page.

SUPPORT CENTER DISCORD

spider for http basic auth w/o TLS

Robert | Last updated: Aug 21, 2018 03:00PM UTC

Hello all, http basic auth used in the clear (without TLS) is considered a security violation in my organization. We have a large number of web servers some with very deep levels of pages, so looking for this by hand is tedious. I am looking for a tool to find such security violations. Does something already exist? Or do I need to write one myself? If the latter, any hints or suggestions on doing this with Burp Suite would be appreciated. Thank you, R. Keyes

PortSwigger Agent | Last updated: Aug 22, 2018 08:45AM UTC

This is detected by Burp Scanner; the issue raise is "Cleartext submission of password". There's some information about that here: - https://portswigger.net/kb/issues/00300100_cleartext-submission-of-password

PortSwigger Agent | Last updated: Aug 22, 2018 01:38PM UTC