The Burp Suite User Forum was discontinued on the 1st November 2024.

Burp Suite User Forum

For support requests, go to the Support Center. To discuss with other Burp users, head to our Discord page.

SUPPORT CENTER DISCORD

Lab: Stealing OAuth access tokens via an open redirect

Russell | Last updated: Aug 28, 2024 09:15AM UTC

In this lab, there seems to be a problem with the victim accessing the link. No matter what payload is being sent, the logs don't show the victims's IP address, showing they never accessed it, so the lab can't be finished.

Russell | Last updated: Aug 28, 2024 09:31AM UTC