Burp Suite User Forum

Create new post

Resolve the url's in the training?

Dave | Last updated: Apr 08, 2019 06:35PM UTC

Hello, After finding a post about the web security training, I have started it. I finished the first lab and completed it. Sadly, the 2nd lab is broken: Firstly, the URL given in the training, https://insecure-website.com/products?category=Gifts is not the one used in the link lower down when you access the lab: https://ac1420c23ef63f8280baebcf.web-security-academy.net/ So onto the 2nd lesson about login bypass. When I use the name administrator'-- and not use a password based on the writeup, I get an error that the password field is empty and needs a value. So it looks like either the write is incorrect. Or someone fixed the vulnerability, which in my mind is ironic!! Please confirm that the login bypass is expected to use the prescribed method laid out. Or do I need to research more deeply? Sincerely, Dave

PortSwigger Agent | Last updated: Apr 09, 2019 09:28AM UTC

Hi Dave, thanks for letting us know about this. The mismatching URLs are intentional. Each user gets their own lab URL, while the tutorial is static content. The vulnerability is still present in that lab, you just need to include a non-empty password. The text is a little misleading, so we may revise that.

You must be an existing, logged-in customer to reply to a thread. Please email us for additional support.