The Burp Suite User Forum was discontinued on the 1st November 2024.

Burp Suite User Forum

For support requests, go to the Support Center. To discuss with other Burp users, head to our Discord page.

SUPPORT CENTER DISCORD

LAB: No SQL Exploiting NoSQL operator injection to extract unknown fields

Preecha | Last updated: May 30, 2024 07:59AM UTC

I have a question about lab this, I have to rescan find attributes only array is 0 = id 1 = username 2 = password 3 = email I haven't find the token because I tried Sequent 0 - 10 not find a token Please help tell me this.

Ben, PortSwigger Agent | Last updated: May 30, 2024 10:03AM UTC

Hi, Have you carried out step 4 of the solution, which is to manually attempt a reset of the 'carlos' users password within a browser?

Dominyque, PortSwigger Agent | Last updated: May 30, 2024 10:05AM UTC