This lab is vulnerable to indirect prompt injection. The user carlos frequently uses the live chat to ask about the Lightweight "l33t" Leather Jacket product. To solve the lab, delete carlos. To solve ...
Go to the exploit server and add the following iframe to the body. Remember to add your own lab ID: <iframe src="https://YOUR-LAB-ID.web-security-academy.net/" onload ...
How do I access my account and download the latest software and license key? Please log in your account using the details provided in your order confirmation email ...
This lab's live chat feature is vulnerable to cross-site WebSocket hijacking (CSWSH). To solve the lab, log in to the victim's account. To do this, use the provided exploit server to perform a CSWSH ...
You need to configure Firefox so that you can use it for testing with Burp Suite.
Burp Scanner is capable of detecting a wide range of vulnerabilities, which are flagged by the scanner as issues. This table lists all vulnerabilities that can be identified by Burp Scanner. It is ...
This documentation describes the functionality of all editions of Burp Suite and related components. Use the links below to get started: ...
Depending on your subscription, you have several different options for hosting your Burp Suite DAST instance.
Burp Scanner is an automated dynamic application security testing (DAST) web vulnerability scanner. Designed to replicate the actions and methodologies of a skilled manual tester, Burp Scanner powers ...
Burp Suite is a comprehensive suite of tools for web application security testing. This interactive tutorial is designed to get you started with the core features of Burp Suite as quickly as possible.
When you launch a Burp Intruder attack, the attack runs in a new results window. This contains the attack results, and a clone of the configuration side panel from which the current attack is based.
The traditional way to prove that you've found a cross-site scripting vulnerability is to create a popup using the alert() function. This isn't because XSS has anything to do with popups; it's simply ...
Results that may be inaccessible to you are currently showing.
Hide inaccessible results