The Burp Suite User Forum was discontinued on the 1st November 2024.

Burp Suite User Forum

For support requests, go to the Support Center. To discuss with other Burp users, head to our Discord page.

SUPPORT CENTER DISCORD

PRACTITIONER Authentication bypass via encryption oracle

Hyper10sion | Last updated: Jun 15, 2022 03:31PM UTC

on the solution box: 8.In Decoder, URL-decode and Base64-decode the cookie. Select the "Hex" view, then right-click on the first byte in the data. Select "Delete bytes" and delete 23 bytes. why url-decode and base64 decode before deleting 23 bytes? how do we know that this is the right way to find and delete the hex charecters?

Ben, PortSwigger Agent | Last updated: Jun 17, 2022 09:44AM UTC