The Burp Suite User Forum was discontinued on the 1st November 2024.

Burp Suite User Forum

For support requests, go to the Support Center. To discuss with other Burp users, head to our Discord page.

SUPPORT CENTER DISCORD

Lab: HTTP/2 request smuggling via CRLF injection

Georg | Last updated: Apr 24, 2023 10:14AM UTC

Hello, I am doing the 'Lab: HTTP/2 request smuggling via CRLF injection', but for some reason, the GET request always contains a session cookie that is truncated (consists only of four characters); the full session cookie never shows, so I cannot resolve the lab. Has anyone run into this ? I have tried several content length values, no difference.

Ben, PortSwigger Agent | Last updated: Apr 24, 2023 12:53PM UTC