The Burp Suite User Forum was discontinued on the 1st November 2024.

Burp Suite User Forum

For support requests, go to the Support Center. To discuss with other Burp users, head to our Discord page.

SUPPORT CENTER DISCORD

HTTP Host Header Attacks - Routing-based SSRF

Samuel | Last updated: May 01, 2023 09:12PM UTC

Hi, I'm trying to get the Set-Cookie response for this lab, but only receive this HTTP/2 302 Found Location: / X-Frame-Options: SAMEORIGIN Content-Length: 0 The request I'm sending is attached. It is supposed to only send GET /admin/delete?csrf=token&username=carlos

Ben, PortSwigger Agent | Last updated: May 03, 2023 04:27PM UTC