srdusr
aboutsummaryrefslogtreecommitdiffstats
path: root/README.md
diff options
context:
space:
mode:
Diffstat (limited to 'README.md')
-rw-r--r--README.md33
1 files changed, 32 insertions, 1 deletions
diff --git a/README.md b/README.md
index c91e455..67536c7 100644
--- a/README.md
+++ b/README.md
@@ -43,7 +43,11 @@ list of what's deliberately not implemented (and why), see
- **Intruder** (Sniper only): mark positions in a request template
with `§markers§`, supply a payload list, fuzz one position at a time
against a shared payload set. Results land in the same history table
- as everything else, searchable the same way.
+ as everything else, searchable the same way. Payload processing
+ (optional case and encode rules, applied to every payload before it's
+ sent) and grep-match/grep-extract (flag or pull text out of each
+ result's response with a regexp) are both configurable before starting
+ an attack - see [Intruder](#intruder) below.
- **Match-and-replace**: header rewrite rules (add, remove, or modify)
for requests and/or responses, applied live as traffic passes
through. History still shows what was actually sent/received on each
@@ -218,6 +222,33 @@ closes the active one. All three only fire in normal mode, so they
don't interfere with typing (`[`/`]` show up in JSON bodies constantly,
and `ctrl+w` is the editor's own delete-word-backward while composing).
+### Intruder
+
+Beyond marking `§positions§` and supplying payloads, two more things are
+configurable before `ctrl+r` starts the attack - both normal-mode-only
+shortcuts, available from any pane:
+
+- `c` / `e` cycle **payload processing**: an optional case rule
+ (off/upper/lower) and an optional encode rule (off/URL/Base64/Hex/
+ HTML), shown in the status line above the results table. Applied to
+ every payload, case first then encode, right before it's substituted
+ into the request - case-folding an already-encoded value would
+ corrupt it (e.g. uppercasing Base64 padding), so case always runs on
+ the original text first.
+- `m` / `v` edit **grep-match** / **grep-extract**, each a Go regexp
+ evaluated against every result's actual response bytes (same `enter`
+ confirms / `esc` cancels pattern as the history list's `/` search - an
+ invalid regexp is rejected with an error rather than silently
+ accepted). Grep-match flags a result (a `Match` column) if the pattern
+ is found anywhere in the response; grep-extract captures the first
+ submatch - or the whole match, if the pattern has no capturing group -
+ into an `Extract` column. Both are optional and independent; leave
+ either blank to skip that check.
+
+Both settings apply for the attack you're about to start - changing
+them mid-run doesn't retroactively re-evaluate requests already sent,
+matching Burp's own behavior.
+
### Match-and-replace rules
Press `m` from the history view. Rules match request or response