Burp Suite User Forum

Create new post

IDOR

D | Last updated: Aug 09, 2022 08:03AM UTC

I have been stuck on the IDOR lab. Somehow, finding the credentials is the easy part along with the CSFR. The issue is that each time I enter Carlos' credentials, I get the following error "Invalid CSRF token (session does not contain a CSRF token)". I have cleared cookies, tried incognito and still no joy. Please help.

Ben, PortSwigger Agent | Last updated: Aug 09, 2022 09:07AM UTC

Hi, Just to clarify are you referring to the 'Insecure direct object references' lab (here - https://portswigger.net/web-security/access-control/lab-insecure-direct-object-references) or a different lab? If so, how are you trying to enter Carlos' credentials - are you using the account login page in the browser or via some other method?

You must be an existing, logged-in customer to reply to a thread. Please email us for additional support.