The Burp Suite User Forum was discontinued on the 1st November 2024.

Burp Suite User Forum

For support requests, go to the Support Center. To discuss with other Burp users, head to our Discord page.

SUPPORT CENTER DISCORD

How Do I: Tell Intruder that a particular field must be unique for every request?

Felix | Last updated: May 25, 2017 01:09PM UTC

Hey, I have a web app that has an "Add User" feature. The form submission includes lots of details (about 150) and one of the fields submitted is the "Username" field. I have used the pitchfork attack type and this sort-of works. Unfortunately, it seems to mean that I have to test every single field other than the username individually. I also like using the Intruder to narrowly target my active scans as it can more easily pick things up like time-based injection issues. Whilst I have completed the work on this web app test, it would be nice to know how to make it more efficient in the future. Is there a way of doing this that I don't know about? Thanks!

PortSwigger Agent | Last updated: May 25, 2017 02:22PM UTC