The Burp Suite User Forum was discontinued on the 1st November 2024.

Burp Suite User Forum

For support requests, go to the Support Center. To discuss with other Burp users, head to our Discord page.

SUPPORT CENTER DISCORD

Password reset poisoning on via my own server

Loan | Last updated: Aug 20, 2022 05:37PM UTC

Hi all, I solved the password reset poisoning lab without any issue. However, I have one question. I would like to be able to reproduce such vulnerabilities in real life penetration testing, that's why I did set up a basic webserver to use like the exploit server delivered by portswigger in the labs. So I tried to have the reset token sent to my webserver in order to view it in the access logs, however, it doesn't work. My webserver doesn't have a domain name so I am providing its ip address as the host header, I wonder if that is the issue (does host header works with ip addresses too in real life?) or maybe this kind of actions are blocked by portswigger. Thanks in advance.

Hannah, PortSwigger Agent | Last updated: Aug 22, 2022 11:03AM UTC