Burp Suite User Forum

Create new post

LABs file upload not working

Velmar | Last updated: Jan 06, 2022 01:18PM UTC

Hi Recently I have noticed, that on 2 LABs avatar upload does not work. Can You confirm? 1. Server-side template injection with a custom exploit 2. Using PHAR deserialization to deploy a custom gadget chain On both cases, uploading a valid non malicious jpg, but the response is: HTTP/1.1 302 Found Location: ./ Connection: close Content-Length: 0 Can You confirm?

Ben, PortSwigger Agent | Last updated: Jan 07, 2022 03:26PM UTC

Hi Velmar, On first glance it does look like this is not behaving quite as expected (for the second lab, the request mentioned in the solution does not appear to be being generated when an upload is carried out) - let us have a chat with the Academy team and see if we can confirm what the issue is.

You must be an existing, logged-in customer to reply to a thread. Please email us for additional support.