The Burp Suite User Forum was discontinued on the 1st November 2024.

Burp Suite User Forum

For support requests, go to the Support Center. To discuss with other Burp users, head to our Discord page.

SUPPORT CENTER DISCORD

Web Cache Poisoning - via an unknow header

xela3 | Last updated: Oct 27, 2023 04:10PM UTC

Hello, I want to know if it should not be possible to make requests to my burp-collaborator instance in Web cache poisoning topic section. I perform the poison, and then, when I inject some payload to fetch('my-burp-collaborator', ...) I can never get a request performed, only the alerts. Are these requests being blocked? Was trying to simulate an attack chain like stealing some cookies through web cache poisoning.

Michelle, PortSwigger Agent | Last updated: Oct 30, 2023 08:53AM UTC

Hi Are you working on the labs in the Web Security Academy and trying to use a private collaborator server? If so, when working on the labs, you will need to switch to using the public collaborator server, as the labs have been set to work with the public collaborator server.

xela3 | Last updated: Oct 30, 2023 09:12AM UTC

Hey, Is it set to "Use the Default collaborator server".

Michelle, PortSwigger Agent | Last updated: Oct 30, 2023 11:16AM UTC