Burp Suite User Forum

Create new post

Cookie Disappears

Jota | Last updated: Jan 01, 2022 11:51PM UTC

Hi PortSwigger, When I'm sending a request with a Notification Cookie (Lab: Authentication bypass via encryption oracle) it responds with an 200 OK, but the Notification Cookie disappears and the response doesn't show the Notification decrypted, I don't know why it is not applying the Notification Cookie, please help, I made all the Solution steps but it isn't showing the Decrypted cookie, and it is deleting the Cookie every time I send a request. Best regards, Jota

Hannah, PortSwigger Agent | Last updated: Jan 04, 2022 12:28PM UTC

Hi Jota Have you tried following along with a video solution of the lab, rather than following the written steps? - https://youtu.be/IVCCwTEjJvk - https://youtu.be/62spVp-GVPI

Jota | Last updated: Jan 04, 2022 08:13PM UTC

I followed the tutorial and everything went fine until the part of ("In Decoder, URL-decode and Base64-decode the cookie. Select the "Hex" view, then right-click on the first byte in the data. Select "Delete bytes " and delete 23 bytes.") I couldn't select the "Delete bytes" option because the only option to delete is the following: "Delete selected byte". The version of Burp is: v2021.10.3, how can I delete 23 bytes if I don't see this option?

Michelle, PortSwigger Agent | Last updated: Jan 06, 2022 03:30PM UTC

The menu options have changed in recent versions so we have made the team aware of the change that is needed in the instructions, thank you for bringing this to our attention. You can still select multiple bytes in the Decode tab by using click and drag with the mouse or selecting the first byte and using Shift and the arrow keys to highlight multiple bytes. I hope this helps.

Jota | Last updated: Jan 06, 2022 05:46PM UTC

I'm grateful that I helped, but I used your method of "selecting the first byte and using Shift and arrow keys to highlight multiple bytes." but it didn't work, after encoding as Base64 and as URL the string doesn't work, probably because I didn't delete exactly 23 bytes, if the option existed on it would probably work (I'm not sure). I've tried several ways. I deleted 22, 24 bytes but it doesn't work, I couldn't solve the lab and I'm sure that I did everything right until this part, but no problem, I think that is not possible without the option, on the comments section in the youtube video, some people couldn't solve the lab too. Thanks for the help. Jota

Jota | Last updated: Jan 06, 2022 06:07PM UTC

By the way, I don't know why but when I install an extension on Burp and restart Burp or the Virtual machine, the extension disappears and all settings go back to default. Any idea of why this is happening?

Jota | Last updated: Jan 06, 2022 06:07PM UTC

By the way, I don't know why but when I install an extension on Burp and restart Burp or the Virtual machine, the extension disappears and all settings go back to default. Any idea of why this is happening?

Jota | Last updated: Jan 06, 2022 06:08PM UTC

I spammed the submit button twice, sorry.

Michelle, PortSwigger Agent | Last updated: Jan 07, 2022 01:10PM UTC

Thanks for the update. I have been able to replicate the behavior you are describing in the lab, I don't think this is related to how you are deleting the bytes so I will discuss this further with the Academy team and let you know what we find. For the issue with the extensions can you email some more details to support@portswigger.net so we can take a closer look, please? Which extension(s) are you installing when this happens? Does it happen after installing a particular extension? Can you also send us the Help -> Diagnostics output, both just after installing the extensions and then again after restarting Burp when they are no longer there, please?

Jota | Last updated: Jan 07, 2022 07:36PM UTC

Sure, i will send an email.

Jota | Last updated: Jan 07, 2022 08:27PM UTC

Surprisingly everything is working fine now, the extension continues even after I restart Burp. This bug was happening in my old virtual machine, I had to create another one today because the old one got corrupted and when I went to see if Burp was kepping the extension and it was, so it is everything ok. Thank you for your assistance with this matter. Best regards, Jota

Michelle, PortSwigger Agent | Last updated: Jan 10, 2022 03:07PM UTC

Thanks for letting me know things are working with your extensions now. I've replicated the issue you are seeing with the lab and am discussing my results with the Academy team. We'll be in touch soon.

Michelle, PortSwigger Agent | Last updated: Jan 28, 2022 11:43AM UTC

Thanks for your patience. We have now resolved the issues with the lab so if you use the method of selecting the first byte and using Shift and arrow keys to highlight multiple bytes when you then re-encode the data and use it you should see the error message mentioned in step 9 of the solution.

Jota | Last updated: Feb 02, 2022 02:33PM UTC

Thanks for the reply and for solving the problem. Best regards, Jota

Prasad | Last updated: Apr 13, 2023 11:24AM UTC

Hello, I am seeing the same error mentioned at the beginning of this page. When I am sending the GET request with the notification cookie in Repeater, the response seems 200 ok, but the notification cookie disappears from the request header and the response does not show the notification decrypted either. Just shows an empty '<header class="notification-header"></header>'. The lab did work fine about 2 months ago, but it is not working now. I have tried clearing cache but no luck. I have tried multiple times using both firefox and burp's browser. Could you please take a look? Thanks, Prasad

Prasad | Last updated: Apr 13, 2023 11:24AM UTC

Hello, I am seeing the same error mentioned at the beginning of this page. When I am sending the GET request with the notification cookie in Repeater, the response seems 200 ok, but the notification cookie disappears from the request header and the response does not show the notification decrypted either. Just shows an empty '<header class="notification-header"></header>'. The lab did work fine about 2 months ago, but it is not working now. I have tried clearing cache but no luck. I have tried multiple times using both firefox and burp's browser. Could you please take a look? Thanks, Prasad

Prasad | Last updated: Apr 13, 2023 11:25AM UTC

Hello, I am seeing the same error mentioned at the beginning of this page. When I am sending the GET request with the notification cookie in Repeater, the response seems 200 ok, but the notification cookie disappears from the request header and the response does not show the notification decrypted either. Just shows an empty '<header class="notification-header"></header>'. The lab did work fine about 2 months ago, but it is not working now. I have tried clearing cache but no luck. I have tried multiple times using both firefox and burp's browser. Could you please take a look? Thanks, Prasad

Michelle, PortSwigger Agent | Last updated: Apr 13, 2023 04:24PM UTC

Can you please send some screenshots or a screen recording to support@portswigger.net showing the steps you're taking when this issue occurs?

You must be an existing, logged-in customer to reply to a thread. Please email us for additional support.