diff options
Diffstat (limited to 'PLAN.md')
| -rw-r--r-- | PLAN.md | 20 |
1 files changed, 13 insertions, 7 deletions
@@ -65,13 +65,19 @@ hudsucker) - same problem, worth studying even though this build is Go. form isn't possible yet - only rewriting/removing existing ones. The underlying engine (rules.ApplyHeaders) already supports arbitrary text-block edits; it's specifically the form UI that's constrained. -- Step 7 (Intruder-equivalent) shipped Sniper only: one payload set, - one §marked§ position fuzzed at a time, every other marked position - held at its base value - the mode that covers most real Intruder - usage. Battering ram / pitchfork / cluster bomb aren't implemented. - Sequential sending only (no concurrency), capped at 1000 generated - requests as a fixed safety limit against an accidental huge wordlist - combined with several positions. Reuses the Repeater send primitive +- Step 7 (Intruder-equivalent) now covers all four of Burp's attack + modes (proxy.AttackMode: Sniper, BatteringRam, Pitchfork, + ClusterBomb). Sniper and BatteringRam only ever need one shared + payload set; Pitchfork and ClusterBomb are inherently per-position, + so they need one set per §marked§ position - the request-generation + logic (intrudeValues) is pure and side-effect free specifically so + the request count (positions × payloads for Sniper, a product for + ClusterBomb) can be validated against the 1000-request cap before + anything is dispatched, and so it's unit-testable without a live + target. The TUI reuses the single Payloads pane for per-position sets + too, split by a `---` delimiter line, rather than adding a + multi-widget payload-set editor. Sequential sending only (no + concurrency). Reuses the Repeater send primitive (proxy.Server.sendRaw) directly - an attack is just that primitive run in a loop with generated bytes - and results land in the same history table tagged source="intruder", same as Repeater's |