Burp Suite User Forum

Create new post

HTTP/2 Req Smuggler extension bug?

intrd | Last updated: Oct 27, 2021 12:24AM UTC

So i'm running the probe on "Lab: H2.CL request smuggling" and the issues identified are: HTTP/2 TE desync v10a h2method HTTP/2 TE desync v10a h2auth HTTP/2 TE desync v10a h2path Not "HTTP/2 CL", this is normal? thank u

Hannah, PortSwigger Agent | Last updated: Oct 28, 2021 12:07PM UTC

Hi We are not able to give out any hints or information about the newly released labs. Keep trying, and good luck solving them!

intrd | Last updated: Oct 28, 2021 02:30PM UTC

I'm already solved the lab, the problem is that the lab is marked as CL, but it is TE. but ok.. thank u!

intrd | Last updated: Oct 29, 2021 03:35PM UTC

Sorry Hanna, I just noticed that these new labs has multiple solutions, CL and TE, but the extension only identifies TE.. it may confuse some ppl, but its problem in ext, not the lab. I will open an issue on github, thanks. (i'ts not a spoiler)

Hannah, PortSwigger Agent | Last updated: Nov 01, 2021 08:52AM UTC

Hi I've double-checked with James, the extension author, and as H2.CL is quite rare, the extension does not scan to it. At this time, he doesn't have any further plans to add this functionality.

You must be an existing, logged-in customer to reply to a thread. Please email us for additional support.