The Burp Suite User Forum was discontinued on the 1st November 2024.

Burp Suite User Forum

For support requests, go to the Support Center. To discuss with other Burp users, head to our Discord page.

SUPPORT CENTER DISCORD

Lab: User ID controlled by request parameter with data leakage in redirect

PhenomAnon | Last updated: Sep 30, 2022 10:51PM UTC

When I log in my GET request does not have a username field like the community solution shows... I log in and then turn on the interceptor and refresh the page, the community solutions shows a GET request with the username=wiener. Mine only has a Cookie: session key. As far as I can tell only the POST /login request has the username provided. But this has the CSRF id included as well which makes editing it in the repeater invalid.

PhenomAnon | Last updated: Sep 30, 2022 11:32PM UTC