Burp proxy and burp repeater confusion

Harvey | Last updated: Feb 05, 2020 02:18PM UTC

Hi what is the difference between burp proxy send and burp repeater send?Let's say I changed the id of a request.Does the result of the burp repeater send request gets showed on the website,or you have to change the id on the burp proxy to get the result,and burp repeater only shows the server response.But if want to prove that the website allows login with stolen id,I have to use burp proxy?

Ben, PortSwigger Agent | Last updated: Feb 06, 2020 08:29AM UTC

Hi, Any requests that are forwarded through the Burp Proxy will be sent to the target web application and the response ultimately displayed in your browser (the Proxy is in the chain of communication between your browser and the web application you are viewing). The Repeater is used to manually manipulate and reissue requests so that the web applications response can be analyzed. When you send a request through the Repeater it still gets sent to the web application but the response is shown in the Response panel within the Repeater section. In this view you can see the raw response, response headers, HTML view and, if applicable, render the response as a page. You would normally use Repeater when you wanted to make small changes to an existing request to test how the web application responds to the request. Please let us know if you require any further information.

