Burp Suite User Forum

Create new post

Lab: SSRF via OIDC dynamic registration - no well-known

sunny | Last updated: Feb 14, 2021 08:52AM UTC

Hi, I believe the current image of the lab is having some issue: it does not seem to have the /.well-known folder Can you pls check? thank you so much!

Uthman, PortSwigger Agent | Last updated: Feb 15, 2021 09:37AM UTC

Hi Sunny, The lab appears to be functioning as expected. Are you replacing 'YOUR-LAB-OAUTH-SERVER' with the ID of your labs OAUTH server? This would be the string before '.web-security-academy.net' in the URL when you select 'Login with social media'. You should notice that this is different from the main lab ID (i.e. that of the homepage).

sunny | Last updated: Feb 18, 2021 02:20PM UTC

oops, you are absolutely correct, my bad! thank you so much! :)

sunny | Last updated: Feb 18, 2021 02:20PM UTC

oops, you are absolutely correct, my bad! thank you so much! :)

Uthman, PortSwigger Agent | Last updated: Feb 18, 2021 02:23PM UTC

You are welcome. Enjoy the rest of the labs! :)

You must be an existing, logged-in customer to reply to a thread. Please email us for additional support.