diff options
Diffstat (limited to 'README.md')
| -rw-r--r-- | README.md | 33 |
1 files changed, 32 insertions, 1 deletions
@@ -43,7 +43,11 @@ list of what's deliberately not implemented (and why), see - **Intruder** (Sniper only): mark positions in a request template with `§markers§`, supply a payload list, fuzz one position at a time against a shared payload set. Results land in the same history table - as everything else, searchable the same way. + as everything else, searchable the same way. Payload processing + (optional case and encode rules, applied to every payload before it's + sent) and grep-match/grep-extract (flag or pull text out of each + result's response with a regexp) are both configurable before starting + an attack - see [Intruder](#intruder) below. - **Match-and-replace**: header rewrite rules (add, remove, or modify) for requests and/or responses, applied live as traffic passes through. History still shows what was actually sent/received on each @@ -218,6 +222,33 @@ closes the active one. All three only fire in normal mode, so they don't interfere with typing (`[`/`]` show up in JSON bodies constantly, and `ctrl+w` is the editor's own delete-word-backward while composing). +### Intruder + +Beyond marking `§positions§` and supplying payloads, two more things are +configurable before `ctrl+r` starts the attack - both normal-mode-only +shortcuts, available from any pane: + +- `c` / `e` cycle **payload processing**: an optional case rule + (off/upper/lower) and an optional encode rule (off/URL/Base64/Hex/ + HTML), shown in the status line above the results table. Applied to + every payload, case first then encode, right before it's substituted + into the request - case-folding an already-encoded value would + corrupt it (e.g. uppercasing Base64 padding), so case always runs on + the original text first. +- `m` / `v` edit **grep-match** / **grep-extract**, each a Go regexp + evaluated against every result's actual response bytes (same `enter` + confirms / `esc` cancels pattern as the history list's `/` search - an + invalid regexp is rejected with an error rather than silently + accepted). Grep-match flags a result (a `Match` column) if the pattern + is found anywhere in the response; grep-extract captures the first + submatch - or the whole match, if the pattern has no capturing group - + into an `Extract` column. Both are optional and independent; leave + either blank to skip that check. + +Both settings apply for the attack you're about to start - changing +them mid-run doesn't retroactively re-evaluate requests already sent, +matching Burp's own behavior. + ### Match-and-replace rules Press `m` from the history view. Rules match request or response |