Sheet Intruder is a Burp Suite extension designed to simplify the process of fuzzing for Excel file uploads. It works by representing the content of an Excel file as a tag, which can then be integrated into various locations. This tag then allows configuration such as replacements for fuzzing targets.

Features:

Workflow:

  1. Choose your Excel file (.xls and .xlsx supported)
  2. The selected file is loaded into the extension
  3. In Repeater, Proxy, Scanner or Intruder you are now able to include the tags
  4. Before sending the request the provided Excel file is read and the requested modifications made