The Burp Suite User Forum was discontinued on the 1st November 2024.

Burp Suite User Forum

For support requests, go to the Support Center. To discuss with other Burp users, head to our Discord page.

SUPPORT CENTER DISCORD

403 Forbidden in sollution in Academy Web cache poisoning via ambiguous requests

Andrey | Last updated: Jun 20, 2024 02:44AM UTC

Hello, according to the Sollution when i use 2 HOST headers such as GET /?cb=123 HTTP/1.1 Host: 0aa300a60483e49080313f3f008e0077.h1-web-security-academy.net Host: example.com I receive HTTP/1.1 403 Forbidden Content-Type: text/html; charset=utf-8 Connection: close Content-Length: 109 <html><head><title>Client Error: Forbidden</title></head><body><h1>Client Error: Forbidden</h1></body></html> When in your sollution and other video guides this error doesn't appear

Dominyque, PortSwigger Agent | Last updated: Jun 20, 2024 08:03AM UTC