The Burp Suite User Forum was discontinued on the 1st November 2024.

Burp Suite User Forum

For support requests, go to the Support Center. To discuss with other Burp users, head to our Discord page.

SUPPORT CENTER DISCORD

typo in academy example for TE.CL vulnerability?

Peter | Last updated: Apr 26, 2022 05:57PM UTC

In this learning material page: https://portswigger.net/web-security/request-smuggling#te-cl-vulnerabilities is the next example shown: ---------------------------------------- POST / HTTP/1.1 Host: vulnerable-website.com Content-Length: 3 Transfer-Encoding: chunked 8 SMUGGLED 0 ------------------------------- Since 'SMUGGLED\r\n' is 10 characters long, it feels to me that the 8 should be 'a' In my repeater test, with an 'a' I get immeditely repsonse, with the 8 I get an timeout "error":"Read timeout after 10000ms" Am I correct?

Michelle, PortSwigger Agent | Last updated: Apr 27, 2022 11:01AM UTC