The Burp Suite User Forum was discontinued on the 1st November 2024.

Burp Suite User Forum

For support requests, go to the Support Center. To discuss with other Burp users, head to our Discord page.

SUPPORT CENTER DISCORD

Dashes in the payload for the "Lab: Web cache poisoning with an unkeyed cookie"

Jakub | Last updated: Dec 08, 2022 03:40PM UTC

Hi, I have a quick question regarding the "Lab: Web cache poisoning with an unkeyed cookie": Sending this cookie worked: Cookie: fehost=test"-alert(1)-"test While sending same payload, but without dashes, didn't: Cookie: fehost=test"alert(1)"test As far as I know dashes simply mean subtraction in JavaScript, any ideas why payload without them wouldn't trigger the alert? Thanks, Jakub

Michelle, PortSwigger Agent | Last updated: Dec 09, 2022 12:23PM UTC