The Burp Suite User Forum was discontinued on the 1st November 2024.

Burp Suite User Forum

For support requests, go to the Support Center. To discuss with other Burp users, head to our Discord page.

SUPPORT CENTER DISCORD

Web Security Academy lab not working

R | Last updated: Jan 08, 2023 09:47PM UTC

The lab "Exploiting HTTP request smuggling to perform web cache poisoning" is not working properly. I can't seem to poison the cache using the request provided at 4. I do get the 302 Found response but to effect. Also the Content-Length header must be set to 180 and not 193 otherwise the request will not go though. Since the cache is not poisonded by the smuggled request, requesting the /resources/js/tracking.js does not do anything and I'm at a standstill. I checked two different video writeups and followed the steps but nothing changes. Thank you.

R | Last updated: Jan 09, 2023 10:16AM UTC

Hello. I tried again today and the problem is still there. I'd be glad to help an agent willing to look into the issue. Thanks.

Michelle, PortSwigger Agent | Last updated: Jan 09, 2023 04:00PM UTC

Hi Thanks for getting in touch. We'll take a look at th lab and be in touch soon.

Michelle, PortSwigger Agent | Last updated: Jan 10, 2023 09:55AM UTC