The Burp Suite User Forum was discontinued on the 1st November 2024.

Burp Suite User Forum

For support requests, go to the Support Center. To discuss with other Burp users, head to our Discord page.

SUPPORT CENTER DISCORD

making repeater request with session handling rule changes request body

Jacek | Last updated: Dec 11, 2015 10:57AM UTC

I've set up a session handling rule to fetch csrf token and place valid value in request I wish to test. I've placed XSS code into one of the POST params. Unfortunatelly, after the request was issued and response received, entire XSS code was removed from the request, and only original request param value remained. It didn't happen when rule was disabled. Why did it happen? Cheers, Jacek

PortSwigger Agent | Last updated: Dec 11, 2015 12:23PM UTC