BULK SQL Injection Test on Burp Requests
BULK SQL Injection Test on Burp Requests
Automate bulk SQL injection testing against multiple HTTP requests (captured via Burp) to:
- 
Rapidly detect vulnerable parameters 
- 
Avoid manual repetition 
- 
Scale recon & fuzzing using Burp exports 
✅ Step-by-Step Guide: Bulk SQL Injection Testing on Burp Requests
🧱 Use Case Setup
You Have:
- 
A set of HTTP requests from Burp Suite: - 
Either from request history 
- 
Or exported .xml,.json,.txtfiles
 
- 
- 
Goal: Inject SQL payloads automatically into all parameters and check response anomalies. 
🔹 Step 1: Export Requests from Burp
Option 1: Manually save selected requests
- 
Right-click > Save item(s) → Choose “Individual requests” or "Burp Suite project file (.burp)" 
Option 2: Copy as cURL (easier for scripting)
- 
Right-click > Copy as curl 
- 
Paste into a .txtfile or batch for automation
🔹 Step 2: Choose Your SQL Payload List
Use any of these:
- 
PayloadsAllTheThings: https://github.com/swisskyrepo/PayloadsAllTheThings
- 
Custom: 
🔹 Step 3: Python Script to Automate Payload Injection
🔹 Step 4: (Alternative) Use Burp Extensions
📦 Extensions to try from BApp Store:
| Extension | Description | 
|---|---|
| Turbo Intruder | High-speed bulk fuzzing engine (best choice) | 
| Autorize | Can be adapted for authorization + injection | 
| Logger++ | Enhanced tracking, not injection but great for diff | 
| J2EEScan | SQLi-focused scanner for Java-based apps | 
✅ With Turbo Intruder, you can bulk load requests and define injection points via template + Python logic.
🔹 Step 5: Analyze Responses
Scan for:
- 
HTTP 500 / 403 / 404 status anomalies 
- 
Keywords like sql syntax,mysql,psql,unexpected token
- 
Response length changes 
You can add:
🔐 Caution
- 
Only test systems you are authorized to attack 
- 
Use rate-limiting and thread control if scanning large targets 
- 
Respect authentication/CSRF contexts if needed (pass cookies) 
✅ Optional Add-ons
Want More?
- 
✅ Script to parse .burpbinary files
- 
✅ GUI for loading requests and payloads 
- 
✅ Auto reporting with highlights 
- 
✅ Jupyter Notebook for testing & graphing response anomalies 
0 Response to "BULK SQL Injection Test on Burp Requests"
Post a Comment