The Burp Suite User Forum was discontinued on the 1st November 2024.

Burp Suite User Forum

For support requests, go to the Support Center. To discuss with other Burp users, head to our Discord page.

SUPPORT CENTER DISCORD

There is a problem in this challenge !!!

bus7d | Last updated: Jul 04, 2022 05:20PM UTC

hello, catchy subject line isn't it? so there is a problem with this lab : https://portswigger.net/web-security/sql-injection/examining-the-database/lab-querying-database-version-mysql-microsoft it is impossible (as I know)to enumerate available columns and when testing with allegedly known number of columns (2) it does not work either (500 server error). the payloads mentionned in the solution and the videos does not work at all. the only I was able to use was this one: Gifts'+or+true--' which demonstrate one can modify the original request but it is not exploitable : Gifts'+ORDER+BY+1000000--' ==> 200 OK thank you for reading q

Ben, PortSwigger Agent | Last updated: Jul 05, 2022 08:34AM UTC

Hi, The lab is working as expected. Are you entering the payloads via Burp (as the solution suggests) or are you simply entering the payloads into the address bar of your browser? If it is the latter then you need to consider whether any special characters should be encoded.

bus7d | Last updated: Jul 05, 2022 11:47AM UTC