srdusr
aboutsummaryrefslogtreecommitdiffstats
path: root/PLAN.md
diff options
context:
space:
mode:
Diffstat (limited to 'PLAN.md')
-rw-r--r--PLAN.md11
1 files changed, 11 insertions, 0 deletions
diff --git a/PLAN.md b/PLAN.md
index 745511c..64d1a0d 100644
--- a/PLAN.md
+++ b/PLAN.md
@@ -63,3 +63,14 @@ hudsucker) - same problem, worth studying even though this build is Go.
form isn't possible yet - only rewriting/removing existing ones. The
underlying engine (rules.ApplyHeaders) already supports arbitrary
text-block edits; it's specifically the form UI that's constrained.
+- Step 7 (Intruder-equivalent) shipped Sniper only: one payload set,
+ one §marked§ position fuzzed at a time, every other marked position
+ held at its base value - the mode that covers most real Intruder
+ usage. Battering ram / pitchfork / cluster bomb aren't implemented.
+ Sequential sending only (no concurrency), capped at 1000 generated
+ requests as a fixed safety limit against an accidental huge wordlist
+ combined with several positions. Reuses the Repeater send primitive
+ (proxy.Server.sendRaw) directly - an attack is just that primitive
+ run in a loop with generated bytes - and results land in the same
+ history table tagged source="intruder", same as Repeater's
+ source="repeater", rather than a separate results store.