Burp Suite User Forum

Create new post

Testing web apps that use AD authentication through the Burpsuite Proxy

Rudolph, | Last updated: Apr 28, 2022 08:09PM UTC

I am trying to run an active scan on an internal app that uses AD authentication. The app calls a different internal website to do the authentication. It works fine without the burp proxy being on. When I enable the proxy and try to do a live scan, the authentication info is not accepted. I just get a popup message/form from the authentication site with the UserID and Password fields that says the application requires authentication. Any suggestions?

Liam, PortSwigger Agent | Last updated: Apr 28, 2022 08:28PM UTC

Have you tried using Burp's Platform authentication settings? - https://portswigger.net/burp/documentation/desktop/options/connections#platform-authentication

You must be an existing, logged-in customer to reply to a thread. Please email us for additional support.