The Burp Suite User Forum was discontinued on the 1st November 2024.

Burp Suite User Forum

For support requests, go to the Support Center. To discuss with other Burp users, head to our Discord page.

SUPPORT CENTER DISCORD

suspecting a small mistake in SSRF topic

Mouaz | Last updated: Dec 02, 2023 04:15PM UTC

To whom it may concern, while learning and completing SSRF academy labs, I came across the topic "SSRF with whitelist-based input filters" under "Circumventing common SSRF defenses", and I believe there might be a small mistake in the first method: "embed credentials in a URL before the hostname, using the @ character" the payload as in the example goes as follows: https://expected-host:fakepassword@evil-host but to my knowledge, embedding should be such as: http://username:password@URL and Hence, I believe the example has a small mistake and should rather be like this: https://evil-host:fakepassword@expected-host Moreover, solving its corresponding lab below shows that the payload confirms the issue: http://localhost:80%2523@stock.weliketoshop.net/admin/delete?username=carlos Could you please confirm whether it's indeed a mistake in the example or if maybe I understood the example wrong? Thanks in advance :)

Michelle, PortSwigger Agent | Last updated: Dec 04, 2023 11:24AM UTC