Burp Suite User Forum

Login to post

can create notifaction when intruder returns a matching result?

BurpsuiteVIPCustomer | Last updated: May 07, 2022 02:27AM UTC

hello everyone,I think burpsuite intruder module need a notification function, when I use intruder to brute force a http request and response match a regex result. for example: I am trying to brute force the website password. If it return a "Login success" (use grep to match) , I hope it can notify me through e -mail or webhook or instant messaging tools.I don't want to stare at the screen all the time.

Michelle, PortSwigger Agent | Last updated: May 09, 2022 10:30AM UTC

Thanks for your message. Within Burp you could set up your Intruder attack to use 'Grep - Extract' to find the responses you are looking for and set the attack to be saved to the project file, you could then return to the project file once the attack has finished to review the results. If you were looking to add further functionality you could look at writing your own extension, we have a few resources here to help you get started: https://portswigger.net/burp/extender https://portswigger.net/burp/extender/writing-your-first-burp-suite-extension https://portswigger.net/burp/extender/api/ I hope this helps.

You need to Log in to post a reply. Or register here, for free.