The Burp Suite User Forum was discontinued on the 1st November 2024.

Burp Suite User Forum

For support requests, go to the Support Center. To discuss with other Burp users, head to our Discord page.

SUPPORT CENTER DISCORD

unclear lab instructions

tekko | Last updated: Jun 18, 2020 05:44PM UTC

IN the lab: Username enumeration via response timing, I find the instruction #2 difficult to understand. It says: #2. Identify that the X-Forwarded-For header is supported, which allows you to spoof your IP address and bypass the IP-based brute-force protection. How and where do I identify that the X-Forwarded-for header is supported?

Ben, PortSwigger Agent | Last updated: Jun 18, 2020 06:15PM UTC