Burp Suite User Forum

Create new post

Macth And replace does not work

Aleksi | Last updated: Dec 15, 2021 04:52PM UTC

Hello, Burp Suite Professional and Comunity version has an issue when the match & replace rule does not work. I have Macbook Pro with M1 and thought that was the issue but while testing with windows and i9 Macbook, they have the same issue. Versions are in all of those cases latest. Is that a known issue? A few weeks ago I am pretty sure that feature was working, not 100% working but sometimes. now I can't use it.

Liam, PortSwigger Agent | Last updated: Dec 16, 2021 09:21AM UTC

Hi Aleksi Thanks for your message. To help us debug this issue, could you provide us with an example match and replace that you have tried to use? Cheers Liam Tai-Hogan PortSwigger Web Security

Pavlina | Last updated: Jan 04, 2022 01:55PM UTC

Hello, currently working with v2021.10.3 and it seems that 'Match and Replace' does not work even for the predefined rules. For example those: Type: Request header Match: ^User-Agent.*$ Replace: User-Agent: Mozilla/5.0 (iPhone; CPU iPhone OS 5_1 like Mac OS X) AppleWebKit/534.46 (KHTML, like Gecko) Version/5.1 Mobile/9B176 Safari/7534.48.3 Comment: Emulate iOS Regex match: true Type: Request header Match: [empty] Replace: Origin: foo.example.org Comment: Add spoofed CORS origin Regex match: false But in fact, anything I tried, did not work (no changes in the HTTP history). Same for the response header. Could you have a look at that? Many thanks.

Pavlina | Last updated: Jan 04, 2022 02:14PM UTC

I am sorry, I overlooked the "Auto-modified [request/response]" Seems that 'Match and Replace' works correctly.

Liam, PortSwigger Agent | Last updated: Jan 04, 2022 02:25PM UTC

Thanks for letting us know!

Agustin | Last updated: Jan 06, 2024 10:37PM UTC

Im having the same issue, how did you solve it? Match and replace works while intercept is on, but in HTTP History it doesn't.

Agustin | Last updated: Jan 06, 2024 10:54PM UTC

Never mind, went to Http history, look the request and over the Pretty | Raw | Hex will say Original Request, there is an arrow at the right, click it and it will show you the automodified request

Liam, PortSwigger Agent | Last updated: Jan 08, 2024 10:26AM UTC

Thanks for the update, Agustin.

Please let us know if you require any further assistance.

You must be an existing, logged-in customer to reply to a thread. Please email us for additional support.