http_send_raw_bytes
Byte-level request for smuggling and CRLF injection
How to use it
http_send_raw_bytes is exposed by the BurpMCP Ultra MCP server. Add the server to your MCP client (Claude Desktop, Cursor, Windsurf and others), and the http_send_raw_bytes tool becomes available to the model automatically. See the full listing for setup details and every tool this server provides.
FULL BURPMCP ULTRA LISTINGOther tools in BurpMCP Ultra (39)
Batch broken-access-control / IDOR across multiple identities
Create a Collaborator client for OOB testing
Generate a payload on a shared default client (quick OOB)
Generate a Collaborator payload
Get the client secret key for session persistence
Poll for DNS / HTTP / SMTP interactions (decodes DNS qnames)
Restore a client from its secret key
Get the Collaborator server address
Detect CORS misconfigurations (reflected / null origin, credentialed)
GraphQL introspection + field-suggestion enumeration
Analyze a response for keyword occurrences
Detect response variations (blind injection)
Inline fuzzer — FUZZ keyword, §marker§, or byte-offset modes + payload libraries
Race-condition testing — fire N requests simultaneously
Send HTTP request (structured or raw, HTTP/1.1 or HTTP/2)
Multi-step request sequence with token extraction between steps
Send multiple requests in parallel (batch ops, races)
Guided SQLi / SSTI / LFI with confirmation oracles (SQL-error fingerprints, time-delay, template math-eval, file markers) — not blind fuzzing
Register a custom payload processor
JWT offense — alg:none, RS→HS key confusion, weak-secret cracking, structural analysis
Add highlight color and comment to a history item
One-command auth-header injection for all matching requests
Get HTTP proxy history with filtering (host, method, status, MIME, scope)
Regex search across proxy history (URL, headers, body)
Get WebSocket proxy history
Regex search WebSocket history
Technology + WAF fingerprinting
Send a request to a Repeater tab
Create a custom audit issue
Generate HTML/XML scan report
All issues with severity/confidence filter
Import a BCheck script for custom scanning
Start active/passive scan with optional auth config
Start a web crawl from seed URLs
Add a request to a running audit
Get issues from a specific task
Create a WebSocket connection
Get messages with a direction filter
Auto-intercept WebSocket messages