The Burp Suite User Forum was discontinued on the 1st November 2024.

Burp Suite User Forum

For support requests, go to the Support Center. To discuss with other Burp users, head to our Discord page.

SUPPORT CENTER DISCORD

SameSite Strict bypass via sibling domain LAB seems to be broken

Joshua | Last updated: Jul 30, 2024 07:46PM UTC

The exploit server log seems to fail at grabbing the requests from the victim after exploit delivery. It seems that the victim never actually clicks on the exploit? As I see nothing in the log or any DNS interaction on the collab server.

Joshua | Last updated: Jul 30, 2024 07:49PM UTC

Adding tot he original report: I get an initial GET request from the victim, but no furhter chat logs. 10.0.3.138 2024-07-30 19:10:58 +0000 "GET /exploit/ HTTP/1.1" 200

Michelle, PortSwigger Agent | Last updated: Jul 31, 2024 12:32PM UTC