Operator tip · burp
Match and replace
Proxy → Match and replace: auto-fix a header or cookie across Repeater/Intruder. Stop hand-editing the same byte 40 times.
Guide
When a lab forces a sticky header, role cookie, or stripped security header, editing every Repeater request by hand is how you lose an hour and introduce typos.
Why it matters
Match and replace runs on proxied traffic automatically. You set the rule once — Cookie values, X-Original-URL, User-Agent quirks, or stripping If-None-Match — and Repeater/Intruder inherit it. That is how you stay fast without corrupting the experiment.
How-to
- Proxy → Options (or Settings) → Match and replace.
- Add a rule: match type Request header / Response header / Request body.
- Example: match
^Cookie:.*$, replace with your forged session cookie. - Toggle the rule off when you leave that lab so it does not poison the next engagement.
# Mental model Request header match: Cookie: SESSION=guest Replace: Cookie: SESSION=admin_lab_token
- Keep rules named by lab (
idor-desk cookie) so you know what to disable. - Pair with Logger so you can prove what the proxy actually sent.