the ability to reset a lab

alienhax | Last updated: Oct 24, 2019 07:26PM UTC

after mucking about with: https://portswigger.net/web-security/cross-site-scripting/exploiting/lab-stealing-cookies i ended up messing the pages with csrf reuests\blocking the comment form. even though i can send manually a comment post request with a XSS script to fix this on the victims session (in order to complete the lab), i think you need to have the ability to reset the lab in order to avoid such convoluted solutions that occur in case of a mess done. thank you.

Liam, PortSwigger Agent | Last updated: Oct 25, 2019 06:58AM UTC

The lab should reset after 15 minutes of inactivity. Please let us know if you need any further assistance.

Davidchen | Last updated: Apr 24, 2021 09:53AM UTC

Dear: Sorry, I delete all account without success Can you reset the data for me thanks a lot! https://portswigger.net/web-security/deserialization/exploiting/lab-deserialization-using-application-functionality-to-exploit-insecure-deserialization

Uthman, PortSwigger Agent | Last updated: Apr 26, 2021 07:40AM UTC

Hi Davidchen, The lab will reset in approximately 15 minutes so please wait for that to happen before making another attempt to complete it.

Eric | Last updated: Dec 12, 2022 03:58PM UTC

Hello, I encountered the same issue as the previous user, all the accounts we're deleted while attempting the lab, can this please be reset, thanks. https://portswigger.net/web-security/deserialization/exploiting/lab-deserialization-using-application-functionality-to-exploit-insecure-deserialization

Ben, PortSwigger Agent | Last updated: Dec 13, 2022 07:56AM UTC

Hi Eric, As noted previously, your lab instance will expire after around 15 minutes of inactivity. After that point, if you try and launch a new lab you will obtain a new instance that will have reverted to its original configuration allowing you to try again.

