Burp Suite User Forum

Create new post

Exploit Server

Muhammed | Last updated: Dec 29, 2020 04:51PM UTC

Hi! What is exploit server where portswigger in real senario? For example what can ı use for "redirect_uri"? (I use linux)

Liam, PortSwigger Agent | Last updated: Dec 30, 2020 10:04AM UTC

Are you referring to the exploit server used in a Web Academy Lab?

Muhammed | Last updated: Dec 30, 2020 09:11PM UTC

Actually I ask "Access Log". When I search vulnerability on www.example.com what should I use intead of "Portswigger>exploit-server>access-log"?

Ben, PortSwigger Agent | Last updated: Jan 05, 2021 08:32AM UTC

Hi, Both the exploit server and access log are components that we include so that our users have the ability to solve each lab without any requirement to use external tools. The exploit server mimics an external server and is used to host exploits (where applicable). The access logs provide, as the name suggests, logging details of the requests made to access the resources within the lab itself.

T0w0T | Last updated: Feb 09, 2021 10:41AM UTC

Hello Ben, I was also wondering about the Exploit Server. In a real case scenario, and specifically concerning the Oauth linking exploit, why it's not just possible to send the link to the victim ? What is the role of the exploit server here ? How the exploit server is sending the payload, where and how it's opened on the victim side ? thank you in advance for your time

Ben, PortSwigger Agent | Last updated: Feb 09, 2021 03:53PM UTC

Hi, Basically, we are simulating a user falling victim to whatever exploit is being delivered (depending on what lab is being used). We do all this behind the scenes, using the exploit server and some other mechanisms, so that you, as the student, do not have to worry about any of this. We do not believe that it would make for a great learning experience if you had to, potentially, use external resources to solve a particular lab. We have created the web academy this way so that, as long as you have a copy of Burp handy, everything is self contained. You can then concentrate on learning the particular topic at hand rather than getting to grips with setting up an appropriate environment.

T0w0T | Last updated: Feb 20, 2021 04:36PM UTC

Thank you very much for your reply Ben

You must be an existing, logged-in customer to reply to a thread. Please email us for additional support.