Burp Suite User Forum

Create new post

Lab: SameSite Strict bypass via sibling domain

Anuj | Last updated: Jun 26, 2023 04:58AM UTC

Please check if any update was done on your part for the mentioned lab. In proxy history there are no requests for resources like script and image files containing an Access-Control-Allow-Origin header, which reveals a sibling domain at cms-YOUR-LAB-ID.web-security-academy.net

Ben, PortSwigger Agent | Last updated: Jun 26, 2023 08:03AM UTC

Hi Anuj, The lab appears to be working as expected: https://snipboard.io/RVfmxs.jpg Are you filtering out image and script requests from being shown in the proxy history or are you simply not finding the relevant header in any of the your requests?

You must be an existing, logged-in customer to reply to a thread. Please email us for additional support.