The Burp Suite User Forum was discontinued on the 1st November 2024.

Burp Suite User Forum

For support requests, go to the Support Center. To discuss with other Burp users, head to our Discord page.

SUPPORT CENTER DISCORD

Web Security Academy || Finding and learning to make scripts like the labs

Stephan | Last updated: Jan 18, 2022 11:53AM UTC

Hi All, During the learning path I notice that alot of good theory is explained about how and what a vulnerability is and how to recognize it. However, I find the practice of this very poorly explained. Just like the Videos it's a 1 on 1 follow video that doesn't explain how they get anywhere or how they did the recon to get there. With the following example in the following lab exercises. a script is placed in the solution here. I will always get stuck on this because my programming background is a bit less, but I would still like to know more about how you made the script here. 1) https://portswigger.net/web-security/oauth/lab-oauth-stealing-oauth-access-tokens-via-a-proxy-page 2) https://portswigger.net/web-security/oauth/lab-oauth-stealing-oauth-access-tokens-via-an-open-redirect The methodology is always very clear to me, but I would like a better explanation about how you create the script or where we can look to make a script. In addition, I still need help with the script even though I have already completed it. P.S is there a discord server where people communicate?

Michelle, PortSwigger Agent | Last updated: Jan 20, 2022 01:38PM UTC