The Burp Suite User Forum will be discontinued on the 1st November 2024.

Burp Suite User Forum

For support requests, go to the Support Centre. To discuss with other Burp users, head to our Discord page.

SUPPORT CENTRE DISCORD

Create new post

Lab: SameSite Strict bypass via sibling domain - why the get request to .js is not shown in history? Bug?

Jack | Last updated: Jul 12, 2024 08:38AM UTC

Browser network tab shows it, but burp not, even not with "show all" setting at the http history tab. Pls see image: https://ibb.co/7jVxDKn Bug in lab?

Ben, PortSwigger Agent | Last updated: Jul 12, 2024 12:37PM UTC

Hi Jack, Having just launched this lab and run through a quick test I can actually see the request to chat.js within Burp, using the default settings within the HTTP history. Is this consistently happening when you interact with this particular lab?

Jack | Last updated: Jul 12, 2024 01:10PM UTC

I dont see it for this lab, but saw js files in other lab. I could bypass this but it was strange

You must be an existing, logged-in customer to reply to a thread. Please email us for additional support.