Burp Suite Repeater enables us to *modify and resend intercepted requests* to a target of our choosing. It allows us to take requests captured in the Burp Proxy and *manipulate them, sending them repeatedly as needed*. Alternatively, we can manually create requests from scratch, similar to using a command-line tool like cURL
The ability to edit and resend requests multiple times makes Repeater invaluable for manual exploration and testing of endpoints. It provides a user-friendly graphical interface for crafting request payloads and offers various views of the response, including a rendering engine for a graphical representation.
The Repeater interface consists of six main sections, as depicted in the annotated diagram below:
![[Burp Repeater.png]]
1) *Request List*: Located at the top left of the tab, it displays the list of Repeater requests. Multiple requests can be managed simultaneously, and each new request sent to Repeater will appear here.
2) *Request Controls*: Positioned directly beneath the request list, these controls allow us to send a request, cancel a hanging request, and navigate through the request history.
3) *Request and Response View*: Occupying the majority of the interface, this section displays the Request and Response views. We can edit the request in the Request view and then forward it, while the corresponding response will be shown in the Response view.
4) *Layout Options*: Located at the top-right of the Request/Response view, these options enable us to customise the layout of the Request and Response views. The default setting is a side-by-side (horizontal) layout, but we can also choose a vertical layout or combine them in separate tabs.
5) *Inspector*: Positioned on the right-hand side, the Inspector allows us to analyse and modify requests in a more intuitive manner than using the raw editor.
6) *Target*: Situated above the Inspector, the Target field specifies the IP address or domain to which the requests are sent. When requests are sent to Repeater from other Burp Suite components, this field is automatically populated.
### Inspector
![[Burp Repeater Inspector.png|300]]
- *Request Attributes*: Displays elements related to the location, method, and protocol of the request. This includes modifying the desired resource to retrieve, changing the HTTP method from GET to another variant, or switching the protocol from HTTP/1 to HTTP/2.
- *Request Query Parameters*: These refer to data sent to the server via the URL. For example, in a GET request like `https://admin.tryhackme.com/?redirect=false`, the query parameter redirect has a value of `false`.
- *Request Body Parameters*: Similar to query parameters, but **specific to POST requests**. Any data sent as part of a POST request will be displayed in this section, allowing us to modify the parameters before resending.
- *Request Cookies*: This section contains a modifiable list of cookies sent with each request.
- *Request Headers*: It enables us to view, access, and modify (including adding or removing) any headers sent with our requests. Editing these headers can be valuable when examining how a web server responds to unexpected headers.
- *Response Headers*: This section displays the headers returned by the server in response to our request. It cannot be modified, as we have no control over the headers returned by the server. Note that this section becomes visible only after sending a request and receiving a response.