Tool simulation
Repeater Lab
Repeater workflow
Resend the search request with a script-looking value in q, then submit the vulnerability class.
New to this workspace? Target maps every captured host and path. Proxy holds HTTP History. Repeater lets you edit a request and resend it in its own tab. Intruder automates a payload across a request and flags the outlier response. Decoder and Comparer transform and diff values.
Loading...
Site map
Exchanges under acmeforum.local
Select an exchange to open it in the Proxy tool.
| # | Method | Host | Path | Status | Length | Note | Actions |
|---|---|---|---|---|---|---|---|
| GET | acmeforum.local | /search?q=printer | 200 | 76 |
GET /search?q=printer drivers HTTP/1.1Host: acmeforum.localAccept: text/html
HTTP/1.1 200 OKContent-Type: text/html<p>Results for: printer drivers</p>
Intercept
Off - captured traffic flows straight to HTTP History.
Editing: Template request
HTTP/1.1 200 OKContent-Type: text/html<p>Results for: printer drivers</p>
4 of 4 candidate positions active. Click a highlighted value to toggle it.
GET /?q= drivers HTTP/1.1 Host: Accept:
Clearing every category still runs the full library; check at least one to narrow it down.
'Single quote used to probe for unescaped SQL string concatenation.' OR '1'='1Boolean tautology used to check whether a WHERE clause can be reshaped by input.
<secmissions-probe>reflected</secmissions-probe>Inert placeholder tag used to check whether input is reflected without output encoding.
../../../etc/passwdRelative traversal sequence used to check whether path input can escape an intended directory.
http://127.0.0.1/Loopback destination used to check whether a fetch-by-URL feature reaches internal addresses.http://169.254.169.254/latest/meta-data/Well-known link-local metadata address used to check for unrestricted server-side fetches.
6 payloads ready to run.
Reading the outlier is the point: the response with a different status or length is the one that proves the flaw, regardless of how ordinary or dramatic that payload's own syntax looks.
No attack has been run yet. Configure positions and payloads, then start the attack.
0 added · 3 removed · 0 changed · 1 unchanged
4 commands available in this tool
helpset <param> <value>sendsubmit