The Burp Suite User Forum was discontinued on the 1st November 2024.

Burp Suite User Forum

For support requests, go to the Support Center. To discuss with other Burp users, head to our Discord page.

SUPPORT CENTER DISCORD

Problem with Cache Poisoning Lab

steve | Last updated: Dec 13, 2023 02:21PM UTC

Hello, I'm 90% sure that this lab is broken: https://portswigger.net/web-security/web-cache-poisoning/exploiting-design-flaws/lab-web-cache-poisoning-with-an-unkeyed-cookie I can get the alert to pop-up for myself, but it's as if the user on the other end never receives the xss payload. I followed the instruction to the T and still nothing. I even tried just sending it with intruder for a few minutes just in case it needs time, but still nothing. Also, a bit unrelated to the issue, but relevant to the lab. Why is there a "-" used in the payload? I've never seen this used and it confuses me

Dominyque, PortSwigger Agent | Last updated: Dec 14, 2023 08:42AM UTC