Burp Suite User Forum

Create new post

Confirm IP address is rotating regularly when using TOR SOCKS5 proxy?

Pete | Last updated: Jul 26, 2016 07:49AM UTC

I have Burp set up to the TOR SOCKS5 proxy. As I understand it, TOR switches to a new exit node every 10 minutes or so, which is true is ideal, as this means when I am running intruder, it will look like it is coming from a new IP address regularly. But is this how it really works? If I start an intruder attack on a website with a payload of 1000 iterations, will it really appear to come from more than one IP address? thx

PortSwigger Agent | Last updated: Jul 26, 2016 07:57AM UTC

You could use a simple Intruder task to verify whether your public IP address changes. Find a request that reveals your public IP address (e.g. a google search for "what's my ip"). Make an Intruder attack that issues this request periodically - e.g. once per minute in a single thread. Configure the extract grep settings of the attack to extract the answer in the response. You can then run this attack, and monitor the attack results to see whether your public IP address is changing.

You must be an existing, logged-in customer to reply to a thread. Please email us for additional support.