Burp Suite User Forum

Create new post

Lab: SSRF via OpenID dynamic client registration missing /.well-known

Tom | Last updated: Dec 28, 2020 07:54AM UTC

Hi there, I am doing the OpenID labs and had a good idea where to look for the OAuth configuration files. Seeing them missing, I had a peek at the solution. The solution also suggested to look at the URL I had in mind for the configuration, but the server still serves a 404 Not Found. I am talking about the lab: https://portswigger.net/web-security/oauth/openid/lab-oauth-ssrf-via-openid-dynamic-client-registration. Can someone have a look or confirm that I am perhaps incorrect?

Ben, PortSwigger Agent | Last updated: Jan 05, 2021 01:58PM UTC

Hi Tom, Are you using the correct URL to try and access the configuration files? When you look at the HTTP history within Burp, after you have logged in, there should be entries that have two similar but slightly different host values - the second one is the lab OAuth server URL.

You must be an existing, logged-in customer to reply to a thread. Please email us for additional support.