The Burp Suite User Forum will be discontinued on the 1st November 2024.

Burp Suite User Forum

For support requests, go to the Support Centre. To discuss with other Burp users, head to our Discord page.

SUPPORT CENTRE DISCORD

Create new post

Lab: Stealing OAuth access tokens via an open redirect

In this lab, there seems to be a problem with the victim accessing the link. No matter what payload is being sent, the logs don't show the victims's IP address, showing they never accessed it, so the lab can't be finished.

Last updated: Aug 28, 2024 09:31AM UTC | 0 Agent replies | 1 Community replies | Bug Reports

504 Gateway Timeout

Hello, I am using Burp Suite Professional and when completing the labs it randomly gives me an 504 Gateway Timeout. I have to close the lab completely and load it again, which consumes time because it does it quite a lot. Is...

Last updated: Aug 28, 2024 07:49AM UTC | 5 Agent replies | 7 Community replies | Bug Reports

HTTP Match And Replace Rules Bug

Hello, I am using Burp Suite Professional version 2024.7.4-31588. In this version, I am adding a custom header using the "Match and Replace" section under the proxy settings. For example, if the header I add is "TEST,"...

Last updated: Aug 28, 2024 06:43AM UTC | 1 Agent replies | 1 Community replies | Bug Reports

ClickJacking labs remain as not solved

Hi PortSwigger Team, Even after completing more times "Basic clickjacking with CSRF token protection" and "Clickjacking with form input data prefilled from a URL parameter" labs, they are showing as not solved. I just...

Last updated: Aug 27, 2024 01:48PM UTC | 17 Agent replies | 24 Community replies | Bug Reports

"Basic clickjacking with CSRF token protection" lab error

When i try embed the iframe of the page with the delete account button my session is not included in the iframe. Instead of showing the myaccount page it shows the login page.

Last updated: Aug 27, 2024 07:26AM UTC | 2 Agent replies | 1 Community replies | Bug Reports

Unable to start embedded browser on Burpsuite JAR executable

I am running Burpsuite community edition latest version (v2024.6.6) on Ubuntu 22.04 and when i try to open the browser from proxy tab it doesn't open without showing any errors in terminal and in GUI it simply says "Burp...

Last updated: Aug 26, 2024 03:49PM UTC | 1 Agent replies | 2 Community replies | Bug Reports

Repeater - WebSocket Message - Copy to file/Paste from file isn't working

Hello, The Copy to file/Paste from file options in the Burp Suite Repeater tab is not functioning as expected when sending a WebSocket request.

Last updated: Aug 26, 2024 10:44AM UTC | 2 Agent replies | 1 Community replies | Bug Reports

Labs not loading/ taking forever to load

I am currently trying to access the 2fa-bypass-using-a-brute-force-attack lab and it takes forever to load the webpage. 99% of the time the connection times out. I have tried chrome, firefox, edge, and a different computer....

Last updated: Aug 26, 2024 06:38AM UTC | 2 Agent replies | 1 Community replies | Bug Reports

BSCP exam

Hello! Please advise in following: I had an exam on your platform, May 29th, 2023, and failed it. Considering that the first lab was resolved in 30 minute, but the next one took me more than 3,5 hours without any...

Last updated: Aug 26, 2024 06:37AM UTC | 2 Agent replies | 1 Community replies | Bug Reports

Issue with burp suite browser

noticing an issue with the chromium browser opened by burp suite, essentially run into multiple sites with the same error, an unknown error has occurred. Request is still getting logged, with no response GET /...

Last updated: Aug 23, 2024 10:08AM UTC | 1 Agent replies | 0 Community replies | Bug Reports

Reflected XSS labs

the following labs don't trigger a "lab solved" when using the intended solutions: Reflected XSS with AngularJS sandbox escape and CSP Reflected XSS protected by very strict CSP, with dangling markup attack

Last updated: Aug 22, 2024 10:41AM UTC | 1 Agent replies | 0 Community replies | Bug Reports

Lab: Stored DOM XSS

The goal is to trigger a stored XSS via alert(). My alert() works, but the lab is not solved (I got the lab via Mystic Lab). I also tried it with the solution payload in case the lab can really only be solved with an...

Last updated: Aug 22, 2024 10:10AM UTC | 1 Agent replies | 0 Community replies | Bug Reports

Repeater - never get as response

I am just starting and going thru the tutorial I was able to intercept and modify a request and get responses. but when I select from HTTP history as the tutorial says, and send to repeater, when I click send on repeater...

Last updated: Aug 22, 2024 06:24AM UTC | 1 Agent replies | 0 Community replies | Bug Reports

CORS Origin null Lab not working in Firefox and Chromium anymore

Hi there, Context: https://portswigger.net/web-security/cors/lab-null-origin-whitelisted-attack Issue: Exploit does not trigger, when viewing the exploit on Firefox or Chromium. Still works on Google Chrome (unless you...

Last updated: Aug 21, 2024 08:50PM UTC | 2 Agent replies | 5 Community replies | Bug Reports

can't set intruder resource pool

java 21 ,when I use the intruder ,set the resource pool,it tells me "Resource pool - Invalid concurrent requests - min 1 max 999",no matter what number the Maximum concurrent requests is set。is this a bug ,or something wrong...

Last updated: Aug 20, 2024 12:44PM UTC | 1 Agent replies | 0 Community replies | Bug Reports

CORS vulnerability with trusted null origin sends site to victim but victim does not visit site

<iframe sandbox="allow-scripts allow-top-navigation allow-forms" srcdoc="<script> var req = new XMLHttpRequest(); req.onload = reqListener; ...

Last updated: Aug 20, 2024 07:18AM UTC | 1 Agent replies | 1 Community replies | Bug Reports

Lab: Web shell upload via path traversal | Correct answer is wrong?

Request: GET /files/cmd.php?cmd=cat+/home/carlos/secret HTTP/2 Host: 0a9600c004a6188d80a8bdb500860051.web-security-academy.net Cookie: session=MS2htmTGD9xkK2AK907aZFLSnR7mdeBV User-Agent: Mozilla/5.0 (Macintosh; Intel...

Last updated: Aug 19, 2024 12:53PM UTC | 1 Agent replies | 2 Community replies | Bug Reports

Exploiting path mapping for web cache deception

I've got a "X-Cache: miss" everytime I send my request within the 30 s...

Last updated: Aug 19, 2024 10:40AM UTC | 1 Agent replies | 0 Community replies | Bug Reports

504 Gateway Time-out The server didn't respond in time.

Hello, This issue keeps repeating on every lab I'm trying. I keep retrying until the lab loads, which could sometimes work after the 5-10 tries, and sometimes I can try over 50 times, when the page suddenly loads and works...

Last updated: Aug 16, 2024 12:38PM UTC | 1 Agent replies | 1 Community replies | Bug Reports

Possible bug in an exam app

I have done the exam and for one of the apps burpsuite did not find anything. From what I saw in the app it seemed that at least the first stage was through web cache. Could someone confirm if the app was wrong?...

Last updated: Aug 16, 2024 09:10AM UTC | 1 Agent replies | 0 Community replies | Bug Reports

Page 8 of 155

Burp Suite Support Center

Your source for help and advice on all things Burp-related.

Burp Suite Support Center image