The Burp Suite User Forum was discontinued on the 1st November 2024.

Burp Suite User Forum

For support requests, go to the Support Center. To discuss with other Burp users, head to our Discord page.

SUPPORT CENTER DISCORD

Issue with Grep - extract for error message in lab : Lab: Username enumeration via subtly different responses

Nicolas | Last updated: Sep 07, 2024 11:00AM UTC

Hello, On this lab : https://portswigger.net/web-security/authentication/password-based/lab-username-enumeration-via-subtly-different-responses I added "Invalid username or password." as matching string (greb extract) but after the attack, the error column is empty. In the setting of the "attack" under Grep - Extract I see : Start after expression : -warning> End at delimiter : </p>\n <form Why can't it extract the error message? I also tried with : Start after expression : -warning> End at delimiter : </p> But it is the same. Any clue? Thanks

Dominyque, PortSwigger Agent | Last updated: Sep 09, 2024 08:54AM UTC

Hi Nicolas, I have just attempted the lab using the written solution and can confirm that it solves. Can you please send us screenshots/ screen recordings of your attempt at the lab so we can better advise? You can send this to support@portswigger.net

Nicolas | Last updated: Sep 09, 2024 10:02AM UTC

It works. My bad, I think I have added search string on Grep Match instead of Grep Extract. You can close my post, thanks

Michelle, PortSwigger Agent | Last updated: Sep 09, 2024 03:16PM UTC