Burp Suite User Forum

Create new post

Lab: Exploiting exact-match cache rules for web cache deception

totkogonet | Last updated: Aug 20, 2024 05:21AM UTC

Hi all! Tell me, only in my “Lab: Exploiting exact-match cache rules for web cache deception” when sending an exploit to a victim, she does not switch to it. That is, the logs do not show that he is accessing it, and accordingly does not send his page to the cache. I tried through a script with document.location and through a redirect using the Location header. I used Burp CE and the built-in browser. Help please.

totkogonet | Last updated: Aug 20, 2024 06:41AM UTC

As usually happens after writing a ticket, everything worked))

Dominyque, PortSwigger Agent | Last updated: Aug 20, 2024 09:32AM UTC

Hi totkogonet Glad you were able to solve the lab! :)

Genry | Last updated: Sep 04, 2024 08:07PM UTC

hi, I have the same problem, after press button "Deliver exploit to victim", nothing happen, in access log empty

Genry | Last updated: Sep 04, 2024 08:13PM UTC

After writing this message it begin works. I tried solve lab about 30-40 minutes with renew lab instance and access log were empty in both cases

Ben, PortSwigger Agent | Last updated: Sep 05, 2024 06:36AM UTC

Hi Genry, We are experiencing some intermittent performance issues with the labs at the moment - it is possible that these issues have impacted your ability to solve the lab. The team are currently looking into this to try and identify the root cause and improve things for users.

You must be an existing, logged-in customer to reply to a thread. Please email us for additional support.