"Parameter values extractor"

DAU | Last updated: Dec 06, 2016 03:01PM UTC

Basically this is an advanced search feature which gives a list of all values assigned to a parameter. The parameter can appear either in GET, POST, etc. requests or responses, or JSON, XML, etc. messages. The parameter name should be flexible using regex, because some apps might use dynamic parameter name. This feature could help enumerate all valid and/or used values for a parameter, which might be useful to analyze a parameter. I believe this is not possible using the current search function.

PortSwigger Agent | Last updated: Dec 09, 2016 02:42PM UTC

Have you tried the "Analyze target" function on the "engagement tools" context menu, on the site map? This shows you all parameters and their observed values, and might do what you need.

Burp User | Last updated: Dec 14, 2016 06:06PM UTC

Very nice ! I didn't know about this. It doesn't do all I asked for, but very nice !

