The Burp Suite User Forum was discontinued on the 1st November 2024.

Burp Suite User Forum

For support requests, go to the Support Center. To discuss with other Burp users, head to our Discord page.

SUPPORT CENTER DISCORD

Problems with challenges

a | Last updated: Apr 05, 2020 10:21PM UTC

hello team burp I face some problems in special challenges, in cache poisoning description When the cache is poisoned, the exploit works properly, but when the proxy is closed, the exploit does not work as a self Challenges with a problem LAB: Web cache poisoning with an unkeyed header LAB: Web cache poisoning with an unkeyed cookie LAB: Web cache poisoning with multiple headers LAB: Web cache poisoning to exploit a DOM vulnerability via a cache with strict cacheability criteria LAB: Combining web cache poisoning vulnerabilities Example: We have a challenge Web cache poisoning with an unkeyed header What is required in this challenge is to save harmful content in the temporary storage and return it to another user when requesting the page The problem is that when the malicious request is stored, the exploit only works when the proxy is running When the proxy is closed, the attack will not work Video: https://vimeo.com/404404606 All the challenges of poisoning the web poisoning have the same problem

Uthman, PortSwigger Agent | Last updated: Apr 06, 2020 07:25AM UTC