The Burp Suite User Forum was discontinued on the 1st November 2024.

Burp Suite User Forum

For support requests, go to the Support Center. To discuss with other Burp users, head to our Discord page.

SUPPORT CENTER DISCORD

Lab - Routing-based SSRF - how was it possible that we sent request to local IP-s and still portswigger servers responded?

Jack | Last updated: Jul 30, 2024 08:13PM UTC

See the request - how it reaches burp local servers? since this is a local server, this could point to any inner IP of any machine on the internet. please help me if you can, I am confused thank you GET /admin HTTP/2 Host: 192.168.0.105 Cookie: session=gXaR4tVETmO46VZBQHumSmtLhykmscQv; _lab=47%7cMC0CFQCCkJWObnZxFsBHff%2fN%2f3dCMI6r1QIUfYaeg54ZcKD2WfSBEqCZm809bRffwnXiyMym5Bsqxe%2fTIbKgx%2bRY7kGrlEU0Mm0OSKxTo%2br0uYCB847M4IVbC05Ndsn9Iih5GA6%2baal2GNfWYIzrIJ3vthlB20W4cQJK4JOyru01Nv4I User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:128.0) Gecko/20100101 Firefox/128.0 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/png,image/svg+xml,*/*;q=0.8 Accept-Language: en-US,en;q=0.5 Accept-Encoding: gzip, deflate, br Referer: https://192.168.0.105/ Upgrade-Insecure-Requests: 1 Sec-Fetch-Dest: document Sec-Fetch-Mode: navigate Sec-Fetch-Site: cross-site Priority: u=0, i Te: trailers

Michelle, PortSwigger Agent | Last updated: Jul 31, 2024 01:14PM UTC