How to check account type using Burp Suite?

Аватар автора
MySQL Управление ресурсами сервера баз данных
Let&say you run a penetration test of a website and you have a list of credentials. You want to check which of them belong to the administrators and which are the accounts of ordinary users. Unfortunately, the account type is displayed on a different subpage than the one returned by the server after logging in. Of course, you could write a script in Python, which would first log in using the given data, and then download the content of the "profile" page. But you can also do it directly from Burp - using macros. #bugbounty

0/0


0/0

0/0

0/0