Burp Suite User Forum

Create new post

Error regarding "Finding and exploiting an unused API endpoint" lab

Thomas | Last updated: Mar 12, 2024 08:19PM UTC

Hello, I wanted to bring to Portswigger's attention that there is an error with the "Finding and exploiting an unused API endpoint" lab. When using the OPTIONS method to discover what methods are allowed by the API, the application responds with a "405 Method Not Allowed" message. The walkthrough says that the OPTIONS request should receive a response stating that GET and PATCH are allowed. Please look into this. All the best.

Dominyque, PortSwigger Agent | Last updated: Mar 13, 2024 08:10AM UTC

Hi Thomas You would get a 405 response; however, there is a response header in that response called 'Allow,' which informs you of the methods that are allowed by the API I have attached a screenshot here showing this: https://snipboard.io/pdw7bU.jpg

You must be an existing, logged-in customer to reply to a thread. Please email us for additional support.