Burp Suite User Forum

Create new post

create payload rule to reject or bypass payloads with duplicate characters

MOHAMMED | Last updated: Sep 24, 2018 03:17PM UTC

for example: I don't want burpsuite to try passwords like these: egraaaaa hidbbbbb hfkkkkkka ewsaaaas any word with duplicate letters more than 4 characters should be skipped. please help .

PortSwigger Agent | Last updated: Sep 25, 2018 08:22AM UTC

Intruder is designed so that an extension payload processor could do this. I just tried creating one and realized there is a minor bug and Intruder does not let a payload processor skip a payload. We will investigate this bug in detail when we next work on Intruder. In the meantime, the only workaround is to pre-process the payload lists to remove payloads you don't want to use.

You must be an existing, logged-in customer to reply to a thread. Please email us for additional support.