The Burp Suite User Forum was discontinued on the 1st November 2024.

Burp Suite User Forum

For support requests, go to the Support Center. To discuss with other Burp users, head to our Discord page.

SUPPORT CENTER DISCORD

Lab: Web shell upload via obfuscated file extension

jeeyawn | Last updated: Dec 13, 2021 02:38AM UTC

Hi team, When I followed the lab solution and changed the file parameter to "exploit.php%00.jpg", I get the 404 Bad Requests error. I was able to solve the lab by changing the filename parameter to "exploit.php\x00.jpg" instead. Still I wanted to bring it to your attention and check if it's just me or if I'm missing anything here.

Ben, PortSwigger Agent | Last updated: Dec 13, 2021 02:31PM UTC