The Burp Suite User Forum was discontinued on the 1st November 2024.

Burp Suite User Forum

For support requests, go to the Support Center. To discuss with other Burp users, head to our Discord page.

SUPPORT CENTER DISCORD

Lab Solution : 2FA broken logic

Haridutt | Last updated: Oct 01, 2020 05:24AM UTC

I am trying to solve this lab. I followed all the steps accordingly and in the end I am also getting 302 response while fuzzing. But the problem is that, when I open the 302 response in browser it is not getting me logged in. So I manually tried to enter mfa-code (the one with 302 response while fuzzing) but it gives incorrect security code message.

Hannah, PortSwigger Agent | Last updated: Oct 01, 2020 08:15AM UTC

Have you tried following a video solution for this lab? You can find one here: https://youtu.be/btqm9-swsvU

Fabio | Last updated: Feb 17, 2021 06:15PM UTC

try everything watched different video but nothing just not found 4 digit number

Fabio | Last updated: Feb 17, 2021 07:44PM UTC