Burp Suite User Forum

Login to post

HTTP Request Smuggle false positives

Pietro | Last updated: Dec 10, 2021 11:55PM UTC

Hello, I've learned a lot on this topic by resolving every lab, but now I have been trying to find them in the real world and when I use this extension many times it finds at possible CL.TE or TE.CL and it always says something like: "Burp issued a request, and got a response. Burp then issued the same request, but with a shorter Content-Length, and got a timeout." But when I go to see the actual responses, they are exactly the same and no response got a timeout. I use comparer just in case I'm missing something. And I remember that in the labs the extension triggered a timeout, but I haven't found them in the real world yet. Are these false positives something I should get used to or it can be solved? Maybe I'm missing something that would show me that I'm actually getting timeout. Hope somebody can help me to clarify. Thanks

You need to Log in to post a reply. Or register here, for free.