The Burp Suite User Forum was discontinued on the 1st November 2024.

Burp Suite User Forum

For support requests, go to the Support Center. To discuss with other Burp users, head to our Discord page.

SUPPORT CENTER DISCORD

Academy Lab Feedback: Exploiting NoSQL operator injection to bypass authentication

R | Last updated: Jul 09, 2024 06:26AM UTC

Hi, I was working on this lab, and found the description mis-leading. It suggested that I needed to login as the user called "administrator" to solve the lab, whereas the actual user required was not called "administrator" (but another username that started with "admin...").

Ben, PortSwigger Agent | Last updated: Jul 09, 2024 07:46AM UTC