logo

Using Simple Burp Macros to Automate Testing

ID: 21f41277-4453-5617-b0ed-55818f3c1107

STIX ID: report--21f41277-4453-5617-b0ed-55818f3c1107

Feed Name: Black Hills Infosec Blog

Date Published: 2015-12-23

Date Updated: 2026-04-27

Author: BHIS

...
...

This tutorial explains how to use Burp Suite’s Macros and Session Handling Rules with Intruder to chain a profile update request to a subsequent view request, enabling automated enumeration and extraction of derived values that can reveal sensitive user information. It details configuring a post-request macro, scoping rules, Intruder’s Cluster Bomb payloads, and Grep–Extract patterns to parse the final response, and notes how this workflow can support testing for data leakage and multi-step issues such as stored XSS.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.