Turbo Intruder - Burp Extensions Series
data:image/s3,"s3://crabby-images/860b0/860b06b5fe084e94d3c8588004eb9fb3568f2e6d" alt="Image"
Example
To showcase the plugin we will be using the ACID Flag Bank
challenge from 247ctf will be used. Just a quick note, Spoilers are ahead so if you want to try the challenge before continuing now is the best time to do that!
Challenge explanation - Spoilers
dump
get parameter we can view all funds in the two accounts we control.data:image/s3,"s3://crabby-images/75f0c/75f0c7a041c10cab8d0023ceaababf1ff91cfb7a" alt="Image"
Specifying the from
, to
and amout
get parameters we can transfer points to and from accounts.
data:image/s3,"s3://crabby-images/da69c/da69ce197cef45e05bda945e7ef85962e405ca8f" alt="Image"
Using the flag
get parameter and by also specifying the account with the from
get parameter we can attempt to buy a flag unsuccessfully due to insufficient funds.
data:image/s3,"s3://crabby-images/357e0/357e0aaa7732243ab1faf9310dded40fe7961f63" alt="Image"
Turbo Intruder
data:image/s3,"s3://crabby-images/ad68c/ad68c8920e919b6ba373d3f30e9bd73f04a34388" alt="Image"
req.status
200.data:image/s3,"s3://crabby-images/cc36d/cc36dc0e845566aea67f269bf93b43e4d831dd7b" alt="Image"
Checking our challenge funds again we can see an extra 50 points have been added to one of our accounts! We now are able to buy the flag!
data:image/s3,"s3://crabby-images/082f4/082f4457456cfea5a364c546eb8ff62c1deaa222" alt="Image"
This only covered one small instance of Turbo Intruders usage, for more information please check https://portswigger.net/research/turbo-intruder-embracing-the-billion-request-attack