This tab is used to configure one or more payload sets. The number of payload
sets depends on the attack type defined in the
Positions tab. For many common
tasks, such as fuzzing parameters, brute force guessing a user's password, or
cycling through page identifiers, only a single payload set is needed.
The configuration steps needed to configure a payload set are as follows:
- Select the payload set that you wish to configure from the drop-down
- Select the payload type to use from the drop-down
list. A large number of payload types are available, and these are
highly configurable, allowing you to quickly automate the generation of
payloads for virtually any situation:
- Configure the payload options
for the selected payload type.
- Configure any required
payload processing rules, to manipulate the
generated payloads in various ways.
- Configure the required payload
encoding, to ensure that the correct characters are
URL-encoded for safe transmission over HTTP.
Get help from other users, at the Burp Suite User Forum:
Visit the forum ›
Tuesday, August 19, 2014
This release fixes a UI bug affecting a small number of users who are running Burp on Java 1.6.
See all release notes ›