Burp Suite User Forum

Create new post

Lab issue?

Tron | Last updated: Aug 14, 2020 02:21AM UTC

Hi, Having a great time working the labs here. I seem to have run across a weird issue with the following lab: https://portswigger.net/web-security/cross-site-scripting/contexts/lab-onclick-event-angle-brackets-double-quotes-html-encoded-single-quotes-backslash-escaped I've been able to pop alerts using a couple of different methods, however have not received "Solved" for the lab. 1. Inputting in the comment "Website" field: '''https://ac341f571e435e6380c7029b002e00a7.web-security-academy.net/post?postId=3" onclick="javascript:alert('1')''' 2. Using the recommended solution method. Any idea what might be happening? Thanks again. Respectfully, Mark

Uthman, PortSwigger Agent | Last updated: Aug 14, 2020 08:52AM UTC

Hi Mark, I just tested the lab solution and it appears to work as expected. Have you considered taking a look at a YouTube video? - https://www.youtube.com/watch?v=jJQknnwGaRg If you continue to face issues and think there could be a bug in the lab, please email us on support@portswigger.net

Tron | Last updated: Aug 14, 2020 03:30PM UTC

Hi, Uthman. Thanks for the reply. Hmmm.. the recommended solution method seemed to work straightaway after a fresh login today. I guess you have to trigger the alert via onclick to get a "solve"? Anyway, thanks again!

You must be an existing, logged-in customer to reply to a thread. Please email us for additional support.