• caglararli@hotmail.com
  • 05386281520

What are the steps necessary to configure Burp Suite Crawler/Scan for maintaining login sessions?

Çağlar Arlı      -    30 Views

What are the steps necessary to configure Burp Suite Crawler/Scan for maintaining login sessions?

I am running a Audit and Scan Deep Scan of a website using Burp Suite Professional v2023.10.3.7. I have entered the Settings for the scan and went to Application Login, entering credentials for the login screen.

While the scan is occurring, if I click the "Live Crawl View" tab, I see that the login succeeds, but after Burp tries to navigate to more than 1 other page, it has to login again, every single time... This also occurs when I use the Record Login Sequence feature with the Burp Suite Chrome Extension. I understand there are "Session Rules" that can be set in Burp, but I don't know what to look for and how to actually set them properly so that this doesn't occur. It doesn't seem like session rules that are defined in the Session settings actually apply to the Crawl & Audit module/functionality at all.