The Burp Suite User Forum was discontinued on the 1st November 2024.

Burp Suite User Forum

For support requests, go to the Support Center. To discuss with other Burp users, head to our Discord page.

SUPPORT CENTER DISCORD

“Manipulating Websocket messages to exploit vulnerabilities”.

Yan | Last updated: Jul 28, 2022 01:22PM UTC

Dear team, I am doing the lab of websocket and I can't see the messages on the intercept tab of burp. I receive the get request but not the websocket messages. I have ticked both boxes in the options. Thanks, Yan

Ben, PortSwigger Agent | Last updated: Jul 29, 2022 07:00AM UTC

Hi Yan, To confirm, what browser (and what version of the browser) are you currently using to proxy your traffic? Do you see any entries in the Proxy -> WebSockets history section of Burp when you are interacting with this lab? In addition to the above, with the settings that you have configured, do the chat messages you send within the lab appear to work i.e. you can successfully send a chat message in the browser and you successfully receive a response (it is just that you are not seeing the WebSocket messages in Burp)?

John | Last updated: Jul 14, 2023 05:44AM UTC

Hi, I am having the same issue. And the chat box always say "disconnected." Any ideas? Please advise. I am using the built-in Chromium browser in burp.

John | Last updated: Jul 14, 2023 05:44AM UTC

Hi, I am having the same issue. And the chat box always say "disconnected." Any ideas? Please advise. I am using the built-in Chromium browser in burp.

John | Last updated: Jul 14, 2023 05:46AM UTC

Live chat DISCONNECTED: -- Chat has ended -- Your message:

Ben, PortSwigger Agent | Last updated: Jul 14, 2023 07:18AM UTC

Hi John, Are you able to provide us with some details of what steps you are taking within this lab so that we can assist you further? Having just run this lab it appears to work as expected when using the embedded browser so it would be useful to know exactly what you are doing when you experience this behaviour.

John | Last updated: Jul 14, 2023 02:38PM UTC

I'm following the steps in https://portswigger.net/web-security/websockets/lab-manipulating-messages-to-exploit-vulnerabilities. I launched the embedded browser in burp, and clicked "ACCESS THE LAB" button to launch the lab. Click "Live chat" and send a chat message. Live chat DISCONNECTED: -- Chat has ended -- Your message:

Ben, PortSwigger Agent | Last updated: Jul 17, 2023 07:12AM UTC