Burp Suite User Forum

Create new post

reset of Session ids

Fabrizio | Last updated: Apr 19, 2024 05:44PM UTC

Hi, I want to show to students that by changing a session id the request is refused from the server. However, when I send a request with a modified session id from the Proxy or the Repeater, the request is accepted and a new session id is sent to the client. How can I avoid this weird behavior? Thank you, Fabrizio

Hannah, PortSwigger Agent | Last updated: Apr 22, 2024 09:54AM UTC

Hi Fabrizio This will likely depend on your web server. Is your session ID used for authentication? We have a couple of labs available on our Web Security Academy that involve using session cookies to bypass logins - have you checked any of these out?

You must be an existing, logged-in customer to reply to a thread. Please email us for additional support.