The Burp Suite User Forum was discontinued on the 1st November 2024.

Burp Suite User Forum

For support requests, go to the Support Center. To discuss with other Burp users, head to our Discord page.

SUPPORT CENTER DISCORD

Lab: Routing-based SSRF - Published solution generates 403

Phil | Last updated: May 01, 2023 09:58PM UTC

When I have an entry in the Host: header other than the lab host, I receive a 403 error (every time) The published solution says to put collaborator hosts in there; and then to use 192.168.0.x... But both those scenarios get the same 403 response. GET / HTTP/1.1 Host: n0oao4yrlnilqv8l0rkbhs4v7mdd15pu.oastify.com Sec-Ch-Ua: "Not:A-Brand";v="99", "Chromium";v="112" Sec-Ch-Ua-Mobile: ?0 Sec-Ch-Ua-Platform: "macOS" Upgrade-Insecure-Requests: 1 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/112.0.5615.138 Safari/537.36 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7 Sec-Fetch-Site: none Sec-Fetch-Mode: navigate Sec-Fetch-User: ?1 Sec-Fetch-Dest: document Accept-Encoding: gzip, deflate Accept-Language: en-GB,en-US;q=0.9,en;q=0.8 Connection: close HTTP/1.1 403 Forbidden Content-Type: text/html; charset=utf-8 Connection: close Content-Length: 109 <html><head><title>Client Error: Forbidden</title></head><body><h1>Client Error: Forbidden</h1></body></html>

Ben, PortSwigger Agent | Last updated: May 02, 2023 11:16AM UTC