The Burp Suite User Forum was discontinued on the 1st November 2024.

Burp Suite User Forum

For support requests, go to the Support Center. To discuss with other Burp users, head to our Discord page.

SUPPORT CENTER DISCORD

parameter enumeration in DOM Invader

a | Last updated: Jul 22, 2021 06:17PM UTC

Hello Can you add support for client-side parameter enumeration? An example extension takes a list of parameters from the user Then you modify it to be added in the url After that, an iframe is created inside the page, or a new Windows is opened before the page is loaded, or the parameters are added to the iframe

Michelle, PortSwigger Agent | Last updated: Jul 23, 2021 12:51PM UTC

Thanks for your message. Which version are you currently using? We have already been adding a few new features and have one that discovers client-side parameters automatically and you can also inject into those parameters too if you select "inject canary into all sources". Would that cover what you need? If there are further features that you'd like to see can you tell us a bit more about your use case and how you'd like to use it? You can either reply here or email us using support@portswigger.net.

a | Last updated: Jul 23, 2021 02:14PM UTC