This lab is vulnerable to indirect prompt injection. The user carlos frequently uses the live chat to ask about the Lightweight "l33t" Leather Jacket product. To solve the lab, delete carlos. To solve ...
Go to the exploit server and add the following iframe to the body. Remember to add your own lab ID: <iframe src="https://YOUR-LAB-ID.web-security-academy.net/" onload ...
How do I access my account and download the latest software and license key? Please log in your account using the details provided in your order confirmation email ...
Burp Scanner is capable of detecting a wide range of vulnerabilities, which are flagged by the scanner as issues. This table lists all vulnerabilities that can be identified by Burp Scanner. It is ...
This lab's live chat feature is vulnerable to cross-site WebSocket hijacking (CSWSH). To solve the lab, log in to the victim's account. To do this, use the provided exploit server to perform a CSWSH ...
Burp Intruder is a powerful tool for performing highly customizable, automated attacks against websites. It enables you to configure attacks that send the same request over and over again, inserting ...
This documentation describes the functionality of all editions of Burp Suite and related components. Use the links below to get started: ...
You need to configure Firefox so that you can use it for testing with Burp Suite.
This lab uses a JWT-based mechanism for handling sessions. The server supports the jku parameter in the JWT header. However, it fails to check whether the provided URL belongs to a trusted domain ...
Burp Scanner is an automated dynamic application security testing (DAST) web vulnerability scanner. Designed to replicate the actions and methodologies of a skilled manual tester, Burp Scanner powers ...
BChecks - BChecks are custom scan checks that you can create and import. Burp Suite DAST runs these checks in addition to its built-in scanning routine, helping you to target your scans and make your ...
CI-driven scans enable you to run Burp Scanner from a Docker container in your CI/CD environment. This is an easy way to integrate Burp Suite DAST with your CI/CD platform. It requires you to set up a ...
Some results have been hidden because they may be inaccessible to you
Show inaccessible results