Skip to content

Intruder Payloads

Intruder and Payload Processing

Intruder is a core tool in Burp Suite for automating payload-based attacks against web applications. It enables testers to systematically test parameters, headers, or request bodies by injecting predefined payloads. Advanced configurations allow for handling complex scenarios like multi-part payloads, conditional logic, and dynamic request structures. This section focuses on mastering payload processing techniques to maximize the effectiveness of Intruder in penetration testing.


Payload Processing Fundamentals

Intruder processes payloads through attack types that define how payloads are applied to the request. The most common modes include:

  1. Positional: Injects a single payload into a specific position (e.g., a parameter).
  2. Bitwise: Injects payloads into each bit of a value (e.g., testing for SQL injection with 1' OR 1=1).
  3. Sniper: Injects payloads into a single position, but allows manual control over which payload to use.
  4. Cluster: Injects multiple payloads into different positions simultaneously.
  5. Battering Ram: Injects all payloads into a single position, testing all combinations.

Example: Testing a login form for SQL injection using the Battering Ram attack type:

POST /login HTTP/1.1
Host: target.com
Content-Type: application/x-www-form-urlencoded

username=admin&password=PAYLOAD
- Configure the password parameter with a payload set containing SQLi vectors (e.g., 1' OR 1=1--, 1' OR 1=1#, etc.).
- Select Battering Ram to test all payloads in parallel.


Advanced Payload Permutations

For complex scenarios, combine multiple payload sets and use masks to control how payloads are applied. For example:
- Combining payloads: Use two payload sets (e.g., usernames and passwords) with a mask to generate combinations.
- Conditional logic: Use masks to apply different payloads based on request structure (e.g., headers vs. bodies).

Example: Testing a JSON API with multiple fields:

POST /api/data HTTP/1.1
Host: target.com
Content-Type: application/json

{
  "username": "PAYLOAD1",
  "password": "PAYLOAD2"
}
- Assign PAYLOAD1 to a username payload set and PAYLOAD2 to a password payload set.
- Use Cluster mode to test all combinations simultaneously.


Handling Complex Request Structures

Intruder can handle nested or multi-part requests by targeting specific fields. For example:
- Headers: Inject payloads into HTTP headers (e.g., User-Agent, Cookie).
- JSON bodies: Target specific keys in a JSON payload.
- Form data: Handle multipart/form-data requests with multiple fields.

Example: Testing a CSRF token in a form submission:

POST /submit HTTP/1.1
Host: target.com
Content-Type: application/x-www-form-urlencoded

username=admin&token=PAYLOAD
- Use Positional mode to inject payloads into the token parameter.
- Monitor responses for changes in the server’s behavior (e.g., successful token validation).


Custom Payload Processing with Intruder

For advanced use cases, leverage payload processing rules to dynamically modify payloads based on request context. For example:
- Prefix/suffix injection: Add static text to payloads (e.g., 1' OR 1=1).
- Encoding: Apply URL encoding or base64 to payloads.

Example: Encoding payloads for a blind SQLi test:

GET /search?query=PAYLOAD HTTP/1.1
Host: target.com
- Use a payload set with encoded values (e.g., 1' OR 1=1-- encoded as 1%27%20OR%201%3D1--).
- Configure Intruder to apply the encoding automatically.


Key takeaways

  • Master attack types like Battering Ram and Cluster for efficient payload testing.
  • Use masks to handle multi-part payloads and conditional logic.
  • Target specific request components (headers, JSON bodies) to exploit complex structures.
  • Leverage payload processing rules for dynamic payload manipulation (e.g., encoding).
  • Always validate responses to identify successful payload injections.