Burp Suite User Forum

Create new post

Concealed Sequences

Gaurav | Last updated: Oct 30, 2020 06:55AM UTC

Hi - Need some help with Concealed Sequences mentioned in the 2nd ed of WAHH. The books shares an example- lwjVJA Ls3Ajg xpKr+A XleXYg 9hyCzA jeFuNg JaZZoA if we go to Burp Suite->Decoder Tab. Take the above strings, decode them as Base64. It should reveal the following --Õ$ .ÍÀŽ Æ’«ø ^W-b ö‚Ì ?án6 %¦Y However, on my machine - Appears to be quite similar, however some subtle differences - —ÕJA .ÍÀjg Æ’«+A ^W—Yg ö‚zA ánNg %¦YoA After this, I am unable to proceed with the next step as well "Rendering the decoded data as hexadecimal numbers " Please advice - What am I doing wrong?

Gaurav | Last updated: Oct 30, 2020 06:58AM UTC

Have uploaded a screenshot to dropbox https://www.dropbox.com/s/n68mx9hse2d85oa/Screenshot%202020-10-30%20at%2012.27.12%20PM.png?dl=0

Michelle, PortSwigger Agent | Last updated: Nov 02, 2020 12:41PM UTC

Can you confirm what version of Burp you are using and which OS it is installed on? It's possible that the decoder may be using a different character set to the example in the book.

Gaurav | Last updated: Nov 04, 2020 05:38PM UTC

Hi Michelle, I am using the latest version of Burp Suite Community Edition. V2020.9.2. Build 4265 I am running on Mac OS Catalina. Version 10.15.7 (19H2) Is there something you would suggest so that I may continue enjoying and learning from the WAHH book!!

Michelle, PortSwigger Agent | Last updated: Nov 05, 2020 03:54PM UTC

It looks like the Burp Decoder is using a different source character set, comparing the results for other character sets using other tools that are available online, it looks like the example in the book may be using Windows-1252 as the source character set. I hope that helps. If you're enjoying WAHH, have you taken a look at the Web Security Academy? https://portswigger.net/web-security

You must be an existing, logged-in customer to reply to a thread. Please email us for additional support.