The Burp Suite User Forum was discontinued on the 1st November 2024.

Burp Suite User Forum

For support requests, go to the Support Center. To discuss with other Burp users, head to our Discord page.

SUPPORT CENTER DISCORD

multiple request headers in burpsuite community edition v2023.7.2

ADITHYA | Last updated: Jul 27, 2023 08:37PM UTC

Whenever i try to use the burpsuite the request is including multiple headers with values, causing duplicate headers error. sample request: GET /web-security/mystery-lab-challenge HTTP/2 Host: portswigger.net User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:109.0) Gecko/20100101 Firefox/115.0 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8 Accept-Language: en-GB,en;q=0.5 Accept-Encoding: gzip, deflate Referer: https://portswigger.net/web-security/all-labs Upgrade-Insecure-Requests: 1 Sec-Fetch-Dest: document Sec-Fetch-Mode: navigate Sec-Fetch-Site: same-origin Sec-Fetch-User: ?1 Te: trailers Accept-Encoding: gzip, deflate Accept: */* Accept-Language: en-US;q=0.9,en;q=0.8 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/115.0.5790.110 Safari/537.36 Cache-Control: max-age=0 Accept-Encoding: gzip, deflate Accept: */* Accept-Language: en-US;q=0.9,en;q=0.8 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/115.0.5790.110 Safari/537.36 Cache-Control: max-age=0

Dominyque, PortSwigger Agent | Last updated: Jul 28, 2023 09:13AM UTC

Hi Can you please email support@portswigger.net with a screenshot of a full screen of Burp with the request, including multiple headers?

Bejan | Last updated: Mar 30, 2024 10:05PM UTC

Hi, the same issue with me On this https://portswigger.net/web-security/request-smuggling/browser/pause-based-desync/lab-server-side-pause-based-request-smuggling

Dominyque, PortSwigger Agent | Last updated: Apr 01, 2024 05:02AM UTC

Hi Bejan What version of Burp are you using? Can you please give us an example as to what one of the requests with multiple headers looks like?

Derek | Last updated: May 23, 2024 05:15AM UTC

Hi i am facing an error saying duplicate headers in request using turbo intruder for this lab. this is the sample request POST /resources HTTP/1.1 Host: 0a4f002903ba67b482dd754600e8000c.web-security-academy.net Cookie: session=8aVCM2qExzt0Y2t1AJ4WhRIKozqAYedJ Connection: keep-alive Content-Type: application/x-www-form-urlencoded Content-Length: 85 GET /admin/ HTTP/1.1 Host: 0a4f002903ba67b482dd754600e8000c.web-security-academy.net

Dominyque, PortSwigger Agent | Last updated: May 23, 2024 07:10AM UTC

Hi Derek, Can you please confirm which lab it is that you're attempting? Additionally, what version of Burp are you using?

Derek | Last updated: May 24, 2024 01:28AM UTC

Hello, the lab is Server-side pause-based request smuggling. The version of burp i am using is community edition v2024.3.1.4 Appreciate your help

Dominyque, PortSwigger Agent | Last updated: May 24, 2024 08:09AM UTC

Hi Derek, Can you please send us screenshots of the request within Burp (or a screen recording of you performing this lab) as well as the error message you are seeing? You can send this to support@portswigger.net. This will help me get a closer look at the exact steps you are taking as I have just tried this step of this lab and did not receive the duplicate header error message

Derek | Last updated: May 24, 2024 10:42AM UTC

Hi Dominyque, I have sent via email as suggested. Please have a look

Derek | Last updated: May 25, 2024 06:30AM UTC