The Burp Suite User Forum was discontinued on the 1st November 2024.

Burp Suite User Forum

For support requests, go to the Support Center. To discuss with other Burp users, head to our Discord page.

SUPPORT CENTER DISCORD

Bug in lab Basic clickjacking with CSRF token protection?

Nadia | Last updated: Oct 22, 2022 09:58PM UTC

Hello, I have issues with the "Basic clickjacking with CSRF token protection" lab. Everything is correct on my part (or so I believe). I have tried with the burp browser and chrome, but neither of them displays I solved the lab. I uploaded a video to show its behavior. https://youtu.be/tPwdGvrMp0A Thanks!

Ben, PortSwigger Agent | Last updated: Oct 25, 2022 07:20AM UTC

Hi Nadia, Thank you for the video. That is interesting - I cannot see anything obviously wrong with the approach that you have taken. In addition, if I run through the lab, using the embedded browser, I can successfully solve it using a very similar solution to yours. Out of interest, do you still see this issue if you attempt the lab again today (I just want to rule out any strange transient quirks that might have been afflicting you)?

Carolina | Last updated: May 25, 2023 01:15PM UTC

Same issue despite using different machines and networks. It cannot be solved.

Ben, PortSwigger Agent | Last updated: May 25, 2023 04:45PM UTC