Using Recursive Grep to Test Per-Request CSRF-Token Protected Pages
ID: 2f13a45a-ffcb-579b-a57d-7ebc0c2b843d
STIX ID: report--2f13a45a-ffcb-579b-a57d-7ebc0c2b843d
Feed Name: Black Hills Infosec Blog
This post is a practical guide showing how to use Burp Intruder’s Recursive Grep payload to extract and reuse server-generated anti-CSRF tokens that change on each response, allowing automated testing against forms that otherwise reload with new tokens. It explains necessary Intruder options (Pitchfork attack, Grep Extract), how to seed the initial token, and demonstrates successful exploitation and known limitations with multi-step token sequences.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
