Burp Suite User Forum

Create new post

Issue with simulated victim user in Lab: Internal cache poisoning

X0Rhyth | Last updated: May 05, 2024 12:32AM UTC

Hi. There seems to be an issue with the simulated victim user for this lab that the lab doesn't get solved even when the cache is poisoned. Thx

Ben, PortSwigger Agent | Last updated: May 06, 2024 07:52AM UTC

Hi, I have just run through this lab and been able to solve it using the solution provided so it does appear to be working as expected. Are you able to provide us with some precise details of what you have configured in the exploit server and what request you are sending to try and solve the lab?

X0Rhyth | Last updated: May 06, 2024 10:06PM UTC

Hello, Alright now i get where the problem is. I poisoned the cache with "www.exploit-server.net" which made it accessible to my browser just fine. And when i visit the home page myself the alert function is executed which means the cache is poisoned as intended. However since the simulated user and the exploit server are probably on the same network the "www" part made the exploit server unreachable to the simulated user and so the lab wasn't getting solved. Removing the "www" part did the trick. Thx for your concern.

You must be an existing, logged-in customer to reply to a thread. Please email us for additional support.