xl7dev / BurpSuite

BurpSuite using the document and some extensions
964 stars 423 forks source link

burp suite scan web file and path #2

Open Any3ite opened 7 years ago

Any3ite commented 7 years ago

use burp suite intruder options, and add §/§ in root path ,then select a wordlist

check (start attrack) , so "/" in payload encoded , %2f ,I want to do to let him not to code

使用burp的 intruder功能,并在根目录的/ 上添加标记,然后选择字典,并点击开始攻击按钮,但是payload中的/都被url编码成了%2f,我要怎么做才能让它不自动编码

xl7dev commented 7 years ago

Intruder>>Payloads>>Payload Encoding>>Cancel check