The Burp Suite User Forum was discontinued on the 1st November 2024.

Burp Suite User Forum

For support requests, go to the Support Center. To discuss with other Burp users, head to our Discord page.

SUPPORT CENTER DISCORD

2FA bypass using brute-force attack

Hyok | Last updated: Jul 04, 2023 09:35AM UTC

I'm not able to solve this lab using turbo intruder as I'm using burp suite community edition. I also try to check if this issue persist only with turbo intruder or normal intruder, but this issue also happens with normal intruder. I already configure the macro as described in the video as well as in the textual solution(below to the lab description). I also completely remove my burp suite and then install it again but still I get this issue.

Hyok | Last updated: Jul 04, 2023 09:37AM UTC

The issue I currently face is "invalid CSRF token" in the response with 400 status code

Ben, PortSwigger Agent | Last updated: Jul 04, 2023 09:59AM UTC