Burp Suite User Forum

Create new post

Use Set-Cookie received as Response during Cluster Bomb

newbee00 | Last updated: Apr 10, 2021 09:52AM UTC

I am running a simple Cluster Bomb. Every Request sent generates a "Set-Cookie:" with a new JSESSIONID to be changed. How do I include that with every new request using Burp Pro?? Suggestions? There is a regex option for "Match and Replace" for Set-Cookie but that is only for traffic proxied using Burp, not for running Repeater tests.

Uthman, PortSwigger Agent | Last updated: Apr 12, 2021 09:08AM UTC

Hi, Have you tried using the session handling rules under Project options > Sessions? - https://portswigger.net/burp/documentation/desktop/options/sessions/rule-editor - https://portswigger.net/support/configuring-burp-suites-session-handling-rules Alternatively, have you checked if any extensions on the BApp Store meet your requirements? Potentially 'Authentication Token Obtain and Replace'? - https://portswigger.net/bappstore/51327b097b354243b307b4ed87ba39eb

You must be an existing, logged-in customer to reply to a thread. Please email us for additional support.