The Burp Suite User Forum was discontinued on the 1st November 2024.

Burp Suite User Forum

For support requests, go to the Support Center. To discuss with other Burp users, head to our Discord page.

SUPPORT CENTER DISCORD

CORS with Null origin challenge is broken

bus7d | Last updated: Aug 13, 2023 07:57PM UTC

Hey, It seems that this challenge is broken as the browser does overwrite the Origin header when fetching a request with JS. It does work in Burp but not in real. Another challenge seems to be broken DOM cookie manipulation. Bests,

Michelle, PortSwigger Agent | Last updated: Aug 14, 2023 11:09AM UTC