Burp Suite User Forum

Create new post

Bad Request in Web Academy labs..!!!!

Harshil | Last updated: Aug 30, 2021 10:27AM UTC

Hi all, I'm totally new to web security want to learn web security and I've found out portswigger web labs. this is my first day starting to learn about websec. but, when I tried to access my first lab as suggested by path, (https://portswigger.net/web-security/sql-injection/union-attacks/lab-determine-number-of-columns) after clicking on "Access the lab" button, it gives/shows me 'Bad Request' on browser. (Note: I've tried to open other labs as well. but, It gives same 'Bad Request' error.) please help me.

Ben, PortSwigger Agent | Last updated: Aug 31, 2021 07:39AM UTC

Hi Harshil, Can you confirm which particular browser you are using? In addition, do you have any extensions or plug-ins installed in this browser? Finally, do you have the ability to use a different browser on your machine? If so, do you observe the same behaviour if you use separate browsers to access the labs?

Harshil | Last updated: Sep 02, 2021 04:55AM UTC

Hi Ben, Yes, I've tested this in chromium and firefox web browser and got same results. Don't know what happened..!!! :( please help me to solve this problem, I can't able to practice webapp security because of this.

Ben, PortSwigger Agent | Last updated: Sep 02, 2021 01:28PM UTC

Hi Harshil, Out of interest, what versions of Firefox and Chromium are you using when you attempt to access the labs? To confirm, you are not using any plug-ins or extensions in your browsers when you attempt access? Do you have also have JavaScript enabled on your browsers?

Harshil | Last updated: Sep 03, 2021 03:50AM UTC

Hi Ben, yes, I was using plugins and for testing purpose, I've disabled all the plugins and still got same result. :( Javascript is enabled. I'm using Chromium Version 93.0.4577.63 (Official Build)

Ben, PortSwigger Agent | Last updated: Sep 03, 2021 01:48PM UTC

Hi Harshil, Are you able to clear out your Chromium browser cache (whilst keeping those plug-ins and extensions disabled) and then try again to access a lab to see if this makes a difference. If this still results in the same behaviour, are you able to send us an email at support@portswigger.net and include some screenshots (or better still a video) of the process you are using to access a lab so that we can see exactly what is happening? On the face of it, it sounds like something is interfering with the request that is being sent and, effectively, breaking it but you would assume that this would also manifest itself when accessing other web pages (it sounds like the only issue you have is launching the labs?).

Harshil | Last updated: Sep 05, 2021 11:49AM UTC

Hi Ben, thanks for the help. I've created another account and labs are working. now my question is how can I delete this account..??? I didn't see any links or feature that allow me to delete my account in my account settings.

Ben, PortSwigger Agent | Last updated: Sep 06, 2021 08:19AM UTC

Hi Harshil, We can delete the account for your from our side. Just to categorically confirm this in writing - you want us to delete the account associated with the email address that you have been using to send these forum posts?

Sam | Last updated: Dec 20, 2021 04:59PM UTC

The issue is still there while I'm writing this to PortSwigger Forum. As I read the previous conversation on the same issue so I'm going clear on some things that The PortSwigger Agent asked Who's name is Ben. Browser Name & Version = Firefox (95.0) on LINUX Extension = Around 5 Including FoxyProxy Disabling any kind of Extension is not the Solution I suppose because I tried to teach my students with a lot of Firefox Extension Enabled and We don't have any issues. It Just Worked fine. JavaScript is already Enabled. I tried after clearing cache but it didn't work. so question like " How to Solve that Issue " raises and until the response. Thank You.

Ben, PortSwigger Agent | Last updated: Dec 21, 2021 09:25AM UTC

Hi Sam, Just to clarify, you are experiencing the same issue as the original poster and are receiving errors when you try and launch all of the Web Academy labs?

Sam | Last updated: Dec 21, 2021 12:54PM UTC

Yes

mdih16 | Last updated: Dec 21, 2021 03:53PM UTC

I had this problem just now. The culprit for me was "ClearURLs" addon on Firefox.

Sam | Last updated: Dec 22, 2021 08:52AM UTC

It works fine in Private Tab while all the extension running fine with it. No issue

Michelle, PortSwigger Agent | Last updated: Dec 23, 2021 08:48AM UTC

Thanks for the update. Can I double-check a few details with you please? So far, I've not been able to replicate this here. - Are you only seeing this issue when you use a normal browser window in Firefox? - Are you proxying the requests via Burp when this happens? - When you use a private tab in Firefox or use Burp's embedded browser are the labs loading successfully?

Sam | Last updated: Dec 23, 2021 07:15PM UTC

It works fine in a Private window on Firefox with a Large number of Extensions But It displays the "Bad Request" Error when I try to open it in Normal Window on Firefox with the Same Number of Extensions. Normally, I turned the Proxy on through FoxyProxy when the lab is successfully loaded & I can see the LAB-ID. The issue didn't resolve yet for those who are using Normal Window on Firefox with a Large number of Extensions. But it works totally fine with Private Windows. Thank You.

Sam | Last updated: Dec 23, 2021 07:16PM UTC

It works fine in a Private window on Firefox with a Large number of Extensions But It displays the "Bad Request" Error when I try to open it in Normal Window on Firefox with the Same Number of Extensions. Normally, I turned the Proxy on through FoxyProxy when the lab is successfully loaded & I can see the LAB-ID. The issue didn't resolve yet for those who are using Normal Window on Firefox with a Large number of Extensions. But it works totally fine with Private Windows. Thank You.

Michelle, PortSwigger Agent | Last updated: Dec 24, 2021 10:22AM UTC

Thanks for the update, that's good to know :)

You must be an existing, logged-in customer to reply to a thread. Please email us for additional support.