Burp Suite User Forum

Login to post

Base64 encode adds "%3d" at the end of the encoded string

Lanza, | Last updated: Aug 25, 2023 11:01AM UTC

Hi, I am using the Intruder for brute-force attack. I am also using the payload processing to encode the credentials with Base64. The problem is that a %3d is being added at the end of the encoded string, and this is causing the authentication test to fail for a valid credential. Why the algorithm is adding %3d at the end of the encoded string, and is there a way to prevent or remove it from the encoded string? Thanks, Fabio

Dominyque, PortSwigger Agent | Last updated: Aug 25, 2023 12:59PM UTC

Hi Fabio With base64 encoding, this will URL-encode the '=' character into %3d

Lanza, | Last updated: Aug 25, 2023 02:27PM UTC

Hi Dominyque, I was able to prevent that from happening by unflagging the URL-encoding option. Thanks.

You need to Log in to post a reply. Or register here, for free.