The Burp Suite User Forum was discontinued on the 1st November 2024.

Burp Suite User Forum

For support requests, go to the Support Center. To discuss with other Burp users, head to our Discord page.

SUPPORT CENTER DISCORD

understanding different encoded character when typing in URL compared via burp suite repeater

Phillip | Last updated: Jul 27, 2022 01:10AM UTC

Hi All, First time poster and hoping to understand how webpage url changes certain character compared to typing it via Burp suite repeater and turning on 'URL-encode as you type'. I am currently doing the BurpSuite lab 'SQL injection attack, querying the database type and version on MySQL and Microsoft'. I am trying to wrap my head around understanding the difference in typing the following into the URL or via BurpSuite repeater with the option 'URL-encode as you type' on. For the lab, I type in: ' order by 1# The difference when typing in the URL directly and Burpsuite as following: URL: GET /filter?category=Accessories%27%20order%20by%201 HTTP/1.1 Via BurpSuite with 'URL-encoder as you type' on: GET /filter?category=Accessories'+order+by+1%23 HTTP/1.1 Why does typing into the URL act differently to typing via BurpSuite and the BurpSuite works (assuming it is using the correct asc). Really appreciate the explanation

Liam, PortSwigger Agent | Last updated: Jul 27, 2022 08:45PM UTC