The Burp Suite User Forum was discontinued on the 1st November 2024.

Burp Suite User Forum

For support requests, go to the Support Center. To discuss with other Burp users, head to our Discord page.

SUPPORT CENTER DISCORD

HTTP request smuggling, confirming a TE.CL vulnerability via differential responses

thekalaiyom | Last updated: Mar 18, 2023 09:06AM UTC

i am on the lab trying to understand how this request happens to work and when i change anything from the payload it returns 'HTTP/1.1 400 Bad Request' even the length of the byte, from Content-length: 4 to Content-length: 5 and adding another e on the body its a bad request. i have changed settings for Content length update and still not getting it My second question is how does the smuggler extension add to this? i am doing everything by hand Any clarification would be appreciated. Thanks

Ben, PortSwigger Agent | Last updated: Mar 20, 2023 05:23PM UTC