The Burp Suite User Forum was discontinued on the 1st November 2024.

Burp Suite User Forum

For support requests, go to the Support Center. To discuss with other Burp users, head to our Discord page.

SUPPORT CENTER DISCORD

Return 500 during intruder attack with Lab: Exploiting NoSQL operator injection to extract unknown fields

Nicolas | Last updated: Sep 20, 2024 11:23AM UTC

Hello, When doing this lab : https://portswigger.net/web-security/nosql-injection/lab-nosql-injection-extract-unknown-fields The intruder attack return error 500 for each request with this payload : {"username":"carlos","password":{"$ne":""}, "$where":"function(){if(Object.keys(this)[3].length == §1§) return 1; else return 0; }"} (I can browse the lab with when using Burp's browser)

Ben, PortSwigger Agent | Last updated: Sep 23, 2024 12:05PM UTC