Burp Suite User Forum

Create new post

Bug causes Request Smuggling False Positive

Andrew | Last updated: Sep 24, 2020 06:59PM UTC

I noted a bug in the request smuggling vulnerability claims. Two requests are quoted, one with a request and a response. The second is provided with a request and no response. The second lacks the two CRLF's required to complete a HTTP request, so it looks like it is just timing out. Therefore, Burp reports request smuggling with it sees the difference. Example: Good: Line 17: 35 Line 18: 5gugs=x&provinceCode=QC&activeDate=2020-09-22&2g65x=x Line 19: 0 Line 20: Line 21: Bad: Line 17: 35 Line 18: jc77y=x&provinceCode=QC&activeDate=2020-09-22&nqj6o=x Line 19: 0 Line 20: Line 21: X There's not CRLF line 22 nor 23 that would be required to complete the HTTP call. X

Michelle, PortSwigger Agent | Last updated: Sep 25, 2020 01:36PM UTC

Thanks for getting in touch. Could you send an email to support@portswigger.net with a few more details so we can take a closer look, please? Which version of Burp are you using? Are the examples you show above taken from the Issue Activity details?

You must be an existing, logged-in customer to reply to a thread. Please email us for additional support.