The Burp Suite User Forum was discontinued on the 1st November 2024.

Burp Suite User Forum

For support requests, go to the Support Center. To discuss with other Burp users, head to our Discord page.

SUPPORT CENTER DISCORD

explanation of logic re Lab: Exploiting HTTP request smuggling to capture other users' requests

Jakub | Last updated: Dec 08, 2022 12:47PM UTC

Hi, I have two questions re "Lab: Exploiting HTTP request smuggling to capture other users' requests": 1. Why does the simulated user's HTTP GET request get appended to the comment field, what's the logic behind this? 2. Why entering higher content length returned shorter session token? Only when I reduced CL did I receive the full session token. Any help understanding the concepts above greatly appreciated. Thanks, Jakub

Hannah, PortSwigger Agent | Last updated: Dec 12, 2022 09:02AM UTC