I've been using AutoRepeater for years & I know from collabs/experience that not all are using it. I find it works magic in automating access control or other types of tests if you know how to configure it, so let's make an epic thread for AutoRepeater! #infosec #bugbounty [1]
AutoRepeater (AR) allows you to replace stuff on requests, with creative you can test limitless scenarios. It has 2 tabs 1) Base Replacements, 2) Replacements. Replacements are applied on top of Base Replacements. For each Replacement, a new request is generated. [2]
When testing for access control flaws, it's vital you replace all relevant info properly to not break requests. "0" in "Resp. Len. Diff." column is likely to mean you found an issue as the response is the same, but it could be boring/resources. I sort requests in DESC mode. [4]
AutoRepeater allows you to perform ANY replacement ANY kind of testing if you practice it's replacement types and regular expressions. My favorite ones though are "Match Param/Cookie/Header Name, Replace Value" and "Remove by Name". [6]
I usually tend to start building AutoRepeater configuration/rules/conditions, and manually inspect the modified responses. When I learn how the application behaves/errors etc, I carry on improving the configuration so I can sweep it quicker, efficiently but also accurately. [11]
Finally, AutoRepeater is a #BurpSuite plugin and it exists thanks to Justin Moore from @NCCGroupInfosec, but also the rest of its contributors. If you are going to try it, download from GitHub repo and not BApp Store as the version there is outdated. Also check the repo's wiki :)
Loading suggestions...