Burp Suite User Forum

Create new post

how to generate different token or session id for every request that i made using intruder?

fajar | Last updated: Jul 02, 2018 11:52AM UTC

how to generate different token or session id for every request that i made using intruder? your support already give a suggest, i can change the token using random value using payload. But from my understanding, the website that i want to attack, always generate the token itself. so i think i cant give random value to token using payload.. i give you the video screenshot, showing the cookies value give the same result for same request. https://www.useloom.com/share/96f000bb18a8425d9dbdcad602491437

Liam, PortSwigger Agent | Last updated: Jul 02, 2018 01:43PM UTC

Burp should update the cookie jar automatically. Ensure you have this option selected in the Rule Actions editor. Then, ensure your session rule is working correctly, you should test this with the Repeater. To ensure your session handling rule is working with Intruder, tick the Intruder option at Project options > Sessions > Add / Edit > Scope > Tools Scope.

You must be an existing, logged-in customer to reply to a thread. Please email us for additional support.