The Burp Suite User Forum was discontinued on the 1st November 2024.

Burp Suite User Forum

For support requests, go to the Support Center. To discuss with other Burp users, head to our Discord page.

SUPPORT CENTER DISCORD

Match and Replace response content in Intruder

Rey | Last updated: May 13, 2019 05:22AM UTC

I am working on a web application that generates a random length HTML comment in each response e.g. <!-- This is a random-length HTML comment: oisgvibelyvgbvhoeivghjfsbvlksfhv --> I have a rule within Proxy / Options / Match and Replace that successfully replaces the random comment with a fixed length string. However, this rule does not seem to take effect during an Intruder attack. The HTML comment changes the content length of each response during the attack, interfering with content length analysis. Any idea on how a Match and Replace rule can take effect in Intruder?

Rose, PortSwigger Agent | Last updated: May 13, 2019 12:58PM UTC