HTTP Request Smuggling is an advanced technique for attacking websites that have one or more front-end servers. An attack is launched by sending ambiguous HTTP requests that get interpreted as ...
Complete this form to purchase a Burp Suite certification exam. Please note that you will require access to Burp Suite Professional to complete the exam.
This lab is vulnerable to routing-based SSRF via the Host header. Although the front-end server may initially appear to perform robust validation of the Host header, it makes assumptions about all ...
This lab involves a front-end and back-end server, and the front-end server doesn't support chunked encoding. The front-end server rejects requests that aren't using the GET or POST method. To solve ...
This lab has a stock check feature which fetches data from an internal system. To solve the lab, change the stock check URL to access the admin interface at http ...
To solve the lab, you'll first need to exfiltrate the value of the password reset token for the user carlos. In Burp's browser, attempt to reset the password for the carlos account. When you submit ...
This lab has a stock check feature which fetches data from an internal system. To solve the lab, use the stock check functionality to scan the internal 192.168.0.X range for an admin interface on port ...
This lab uses a JWT-based mechanism for handling sessions. It uses an extremely weak secret key to both sign and verify tokens. This can be easily brute-forced using a wordlist of common secrets. To ...
This lab uses an OAuth service to allow users to log in with their social media account. Flawed validation by the OAuth service makes it possible for an attacker to leak access tokens to arbitrary ...
Log in and purchase a gift card so you can study the purchasing flow. Consider that the shopping cart mechanism and, in particular, the restrictions that determine ...
This lab uses a JWT-based mechanism for handling sessions. The server supports the jku parameter in the JWT header. However, it fails to check whether the provided URL belongs to a trusted domain ...
Go to the exploit server and add the following iframe to the body. Remember to add your own lab ID: <iframe src="https://YOUR-LAB-ID.web-security-academy.net/" onload ...