The Burp Suite User Forum was discontinued on the 1st November 2024.

Burp Suite User Forum

For support requests, go to the Support Center. To discuss with other Burp users, head to our Discord page.

SUPPORT CENTER DISCORD

HTTP request smuggling, confirming a TE.CL vulnerability via differential responses

Sebastian | Last updated: Feb 02, 2023 03:17AM UTC

Could you guys explain to me why the Content-Length of the second request needs to be 15? I see that the values 12 and 13 work, but if I send 10 it does not. I thought that any greater value than the body of the request would work, as it would grab a few bytes of the next request (the one that is sent after and should trigger the 404). But I see that this is not exactly the case. Thank you so much.

Ben, PortSwigger Agent | Last updated: Feb 02, 2023 02:39PM UTC