Burp Suite User Forum

Create new post

lab-web-cache-poisoning-with-an-unkeyed-header

Andre | Last updated: Aug 24, 2020 02:03PM UTC

Hello! I'm trying to complete the lab, but when I send the home page request adding the "X-Forwarded-Host: " header, the request is not completed....if I remove this header and just send the cache buster in the URL it works fine... I don't think I'm doing anything wrong, i even tried to follow the solution and still didn't get any response on the server..

Michelle, PortSwigger Agent | Last updated: Aug 24, 2020 03:03PM UTC

It's probably worth double-checking the format of the request you're sending and looking at how it differs from the ones that work, e.g. look at the number of lines after the header, displaying non-printing characters might help you compare the two requests. Let us know how you get on and good luck with solving the lab!

You must be an existing, logged-in customer to reply to a thread. Please email us for additional support.