03 Burp Match and Replace
03 Burp Match and Replace
03 Burp Match and Replace
Introduction
Burp suite's proxy options have an option called "Match and replace" available.
This option has many rich uses that can help us automate our testing process.
With some smart uses of this amazing option, we can automatically test for CSRF,
IDOR, command injection,.. by just clicking around in the application! Let's explore
this magical tool and it's many options.
Now, as long as this rule is active you can click around in the application. If you
can open any information that should not be public, we have an IDOR on our
hands.
To disable this rule, simple uncheck the checkbox in front of it.
The response
The request
And in either
The header
The body
These give us an infinte amount of possibilites so the sky is the limit... Think
outside the box!