Burp Suite User Forum

Create new post

Web cache poisoning with an unkeyed header LAB issue

Brian | Last updated: Jun 11, 2020 10:38PM UTC

Hi I couldn't get this lab to work for me, so I viewed the solution and followed it to the letter. It's what I had already been doing. However, the X-cache header is always 'miss', even after many many tries. There's always the possibility I'm being a silly boy. But I am after all following the official solution and still no cache. Thanks for reading.

Hannah, PortSwigger Agent | Last updated: Jun 12, 2020 06:29AM UTC

Hi, I don't suppose you have the Param Miner extension installed? If so, can you make sure that you do not have the "Add dynamic cachebuster" option checked? This will cause a different cachebuster to be added to your request each time it is sent, making sure you never get a hit. Another option to look out for is the "Add 'fcbz' cachebuster", as this will mean that you never poison the root of the site.

You must be an existing, logged-in customer to reply to a thread. Please email us for additional support.