The Burp Suite User Forum was discontinued on the 1st November 2024.

Burp Suite User Forum

For support requests, go to the Support Center. To discuss with other Burp users, head to our Discord page.

SUPPORT CENTER DISCORD

Incorrect Payload order in Sniper and Pitchfork Modes

Smail | Last updated: Oct 05, 2024 03:03AM UTC

I'm encountering a problem with Burp Suite's Intruder tool where payloads are being placed in the wrong fields during an attack. In both Sniper and Pitchfork attack modes, I've marked two different positions in my request: one for the password field (pwd) and another for the User-Agent header. However, Burp is incorrectly swapping the payloads, placing the value intended for the password field into the User-Agent header, and vice versa. This behavior persists even after clearing and re-marking the positions, reinstalling Burp Suite, and using simple payloads. The issue makes it difficult to correctly execute attacks where multiple payloads are needed in specific fields.

Ben, PortSwigger Agent | Last updated: Oct 08, 2024 08:42AM UTC