The Burp Suite User Forum was discontinued on the 1st November 2024.

Burp Suite User Forum

For support requests, go to the Support Center. To discuss with other Burp users, head to our Discord page.

SUPPORT CENTER DISCORD

Bug causes Request Smuggling False Positive

Andrew | Last updated: Sep 24, 2020 06:59PM UTC

I noted a bug in the request smuggling vulnerability claims. Two requests are quoted, one with a request and a response. The second is provided with a request and no response. The second lacks the two CRLF's required to complete a HTTP request, so it looks like it is just timing out. Therefore, Burp reports request smuggling with it sees the difference. Example: Good: Line 17: 35 Line 18: 5gugs=x&provinceCode=QC&activeDate=2020-09-22&2g65x=x Line 19: 0 Line 20: Line 21: Bad: Line 17: 35 Line 18: jc77y=x&provinceCode=QC&activeDate=2020-09-22&nqj6o=x Line 19: 0 Line 20: Line 21: X There's not CRLF line 22 nor 23 that would be required to complete the HTTP call. X

Michelle, PortSwigger Agent | Last updated: Sep 25, 2020 01:36PM UTC