The Burp Suite User Forum was discontinued on the 1st November 2024.

Burp Suite User Forum

For support requests, go to the Support Center. To discuss with other Burp users, head to our Discord page.

SUPPORT CENTER DISCORD

Lab: SameSite Strict bypass via client-side redirect

MissigNo | Last updated: Jan 29, 2023 02:12PM UTC

Hello! I was studying about SameSite restrictions in the Academy. However, a question mark has formed in my mind when I was trying to solve the lab "SameSite Strict bypass via client-side redirect". In the step 5 of the solution, the attacker sends a script that redirects the victim to the target site. But it isn't a cross-site redirect? Why the browser sends the target site cookie? And, why I can't send directly to de victim a redirection to the change-email page with the email query string?

Hannah, PortSwigger Agent | Last updated: Feb 02, 2023 11:36AM UTC