Burp Suite User Forum

Create new post

Intruder Column for Response Length Independent of Payload Size

Ryan | Last updated: Jul 28, 2017 04:39PM UTC

When looking for web application behavior in response to fuzzing, I'm often looking for changes in the response length. The problem is that reflected input could obscure minor variations in the response that is separate from the reflected input. A handy feature would be a column that subtracts the payload length from the overall response length to show a corrected length that is independent of payloads which are reflected. The ideal solution (when dealing with multiple payload positions) would be to select the payloads to subtract as well as a multiplier in the case that a single payload is reflected multiple times. Thanks!

Liam, PortSwigger Agent | Last updated: Jul 31, 2017 01:46PM UTC

We have a story logged in our development backlog which will allow users to use the Burp API to configure more details of Intruder attacks. Once developed, this should provide a solution to your issue. Unfortunately, we can't provide an ETA.

You must be an existing, logged-in customer to reply to a thread. Please email us for additional support.