The Burp Suite User Forum was discontinued on the 1st November 2024.

Burp Suite User Forum

For support requests, go to the Support Center. To discuss with other Burp users, head to our Discord page.

SUPPORT CENTER DISCORD

Burp misses open redirect

Patrick | Last updated: May 18, 2017 06:39PM UTC

Hey, I was testing an application which is listening on HTTP and does a redirect to HTTP/S, without a trailing /. Example HTTP Request: http://[victim]/XYZ Example HTTP Response: HTTP 301 Location: https://[victim]XYZ As the / is missing from the document request, we control the domain name string. There are likely ample of ways to do this, but the most simple would be: http://[victim]/@[attacker]. Thought it would be simple to include if you wished. -Patrick

PortSwigger Agent | Last updated: May 22, 2017 08:01AM UTC