Tool simulation
Repeater Lab
Repeater workflow
Resend the invoice download request with a neighboring invoice_id, then submit the vulnerability class.
New to this workspace? Target maps every captured host and path. Proxy holds HTTP History. Repeater lets you edit a request and resend it in its own tab. Intruder automates a payload across a request and flags the outlier response. Decoder and Comparer transform and diff values.
Loading...
Site map
Exchanges under billing.acmeretail.local
Select an exchange to open it in the Proxy tool.
| # | Method | Host | Path | Status | Length | Note | Actions |
|---|---|---|---|---|---|---|---|
| GET | billing.acmeretail.local | /invoices/download?invoice_id=88231 | 200 | 108 |
GET /invoices/download?invoice_id=88231 HTTP/1.1Host: billing.acmeretail.localCookie: session=customer-4471Accept: application/pdf
HTTP/1.1 200 OKContent-Type: application/pdf%PDF-1.4 invoice_id=88231 customer=customer-4471 total=214.00
Intercept
Off - captured traffic flows straight to HTTP History.
Editing: Template request
HTTP/1.1 200 OKContent-Type: application/pdf%PDF-1.4 invoice_id=88231 customer=customer-4471 total=214.00
6 of 6 candidate positions active. Click a highlighted value to toggle it.
GET //?invoice_id= HTTP/1.1 Host: Cookie: Accept:
Clearing every category still runs the full library; check at least one to narrow it down.
'Single quote used to probe for unescaped SQL string concatenation.' OR '1'='1Boolean tautology used to check whether a WHERE clause can be reshaped by input.
<secmissions-probe>reflected</secmissions-probe>Inert placeholder tag used to check whether input is reflected without output encoding.
../../../etc/passwdRelative traversal sequence used to check whether path input can escape an intended directory.
http://127.0.0.1/Loopback destination used to check whether a fetch-by-URL feature reaches internal addresses.http://169.254.169.254/latest/meta-data/Well-known link-local metadata address used to check for unrestricted server-side fetches.
6 payloads ready to run.
Reading the outlier is the point: the response with a different status or length is the one that proves the flaw, regardless of how ordinary or dramatic that payload's own syntax looks.
No attack has been run yet. Configure positions and payloads, then start the attack.
0 added · 3 removed · 0 changed · 1 unchanged
4 commands available in this tool
helpset <param> <value>sendsubmit