The Burp Suite User Forum was discontinued on the 1st November 2024.

Burp Suite User Forum

For support requests, go to the Support Center. To discuss with other Burp users, head to our Discord page.

SUPPORT CENTER DISCORD

http request smuggle (http/2 smuggle probe)

paul | Last updated: Aug 25, 2022 01:53PM UTC

The h2.cl request smuggling lab is straight-forward when performing manually. However, want to make sure the extent to which i can rely on the extension and scanner for detection. When i run the http/2 smuggle probe it doesn't detect an h2.cl vuln. Am i misunderstanding, or are there settings i am likely misconfiguring?

Hannah, PortSwigger Agent | Last updated: Aug 26, 2022 10:55AM UTC

Hi. I've just checked with the extension's author, and currently finding and exploiting H2.CL vulnerabilities are unsupported in HTTP Request Smuggler.

paul | Last updated: Aug 26, 2022 01:29PM UTC

Ok, thank you ... then i'm confused as to the purpose of the http/2 probe extension option. Hoping that can be explained. vr, paul

Hannah, PortSwigger Agent | Last updated: Aug 30, 2022 03:51PM UTC