Burp Suite User Forum

Create new post

Combining web cache poisoning vulnerabilities

Afonso | Last updated: Mar 20, 2024 12:12PM UTC

Hello I am following the solution steps provided and followed the video solution as well but the lab is not solved. When I put "X-Original-Url: /setlang\es" in the GET / . it doesn't redirect me to the localised=1. it just keeps sending me to the regular homepage without the localised=1 parameter. Also I tried using the "X-Original-Url: /setlang\es" in the GET /setlang/es request and it just keeps redirecting me to /setlang/es instead of /?localised=1. What is the issue here?

Dominyque, PortSwigger Agent | Last updated: Mar 21, 2024 12:25PM UTC

Hi Afonso We have just tested the lab and can confirm that it works with the given solution. If you are still struggling with solving the lab, please email us at support@portswigger.net with screenshots/ screen recordings of your attempt at the lab. This will give us an insight into the exact steps you are taking so that we may better advise you.

You must be an existing, logged-in customer to reply to a thread. Please email us for additional support.