The Burp Suite User Forum was discontinued on the 1st November 2024.

Burp Suite User Forum

For support requests, go to the Support Center. To discuss with other Burp users, head to our Discord page.

SUPPORT CENTER DISCORD

Lab: Basic password reset poisoning seems to be broken

Steven | Last updated: Apr 12, 2023 04:36PM UTC

From the lab solution step 6: "Back in Burp Repeater, change the Host header to your exploit server's domain name (YOUR-EXPLOIT-SERVER-ID.exploit-server.net) and change the username parameter to carlos. Send the request." When I change the host header to my exploit server id I get the error: HTTP/2 421 Misdirected Request Content-Length: 12 Invalid host I did try changing it from HTTP/2 to HTTP/1 and HTTP/1.1 and still got the same error.

Ben, PortSwigger Agent | Last updated: Apr 13, 2023 08:12AM UTC