The Burp Suite User Forum was discontinued on the 1st November 2024.

Burp Suite User Forum

For support requests, go to the Support Center. To discuss with other Burp users, head to our Discord page.

SUPPORT CENTER DISCORD

Can't solve Web cache poisoning to exploit a DOM vulnerability via a cache with strict cacheability criteria

Leonard | Last updated: Mar 13, 2020 10:11AM UTC

Dear Burp Suite support team, It seems that I can't solve this lab (Web cache poisoning to exploit a DOM vulnerability via a cache with strict cacheability criteria). I've done exactly what the solution says... The alert fires, but after replaying the request dozens of times, while also checking that the X-Cache: hit header and the URL of my exploit server were present in the response, it still won't work. Any idea what could be wrong? Thanks in advance :)

Hannah, PortSwigger Agent | Last updated: Mar 13, 2020 10:54AM UTC