The Burp Suite User Forum was discontinued on the 1st November 2024.

Burp Suite User Forum

For support requests, go to the Support Center. To discuss with other Burp users, head to our Discord page.

SUPPORT CENTER DISCORD

Solution not functional: "Lab: HTTP request smuggling, confirming a TE.CL vulnerability via differential responses"

Derk | Last updated: Sep 16, 2024 02:13PM UTC

The solution provided in the following lab is not functioning correctly: "Lab: HTTP request smuggling, confirming a TE.CL vulnerability via differential responses" After setting the correct host header and ensuring that HTTP 1.1/is set the payload provided in the solution does not result in a solved lab. I encountered this after trying my own solution, which did not work either. I have waited for the lab to reset multiple times but the standard solution and my own soltution never worked. Could someone please confirm whether the lab is bugged or whether I've made a mistake

Ben, PortSwigger Agent | Last updated: Sep 17, 2024 07:19AM UTC

Hi Derk, I have just run through this lab and was able to solve it using the written solution provided so it does appear to be working as expected. Are you able to provide us with a screenshot of the request that you are sending to try and solve this particular lab so that we can see this more clearly?

Derk | Last updated: Sep 17, 2024 11:20AM UTC