The Burp Suite User Forum was discontinued on the 1st November 2024.

Burp Suite User Forum

For support requests, go to the Support Center. To discuss with other Burp users, head to our Discord page.

SUPPORT CENTER DISCORD

Authentication bypass via encryption oracle

bruno | Last updated: Jul 02, 2022 12:40AM UTC

Hello! I'm trying to solve the lab, i'm following both solution from the website and the videos that I found. "In the decrypt request, copy your stay-logged-in cookie and paste it into the notification cookie. Send the request. Instead of the error message, the response now contains the decrypted stay-logged-in cookie, for example:" When I do this action the response doesn't show my decrypted cookie, the <header class="notification-header"> is empty

bruno | Last updated: Jul 02, 2022 02:36PM UTC