PortSwigger / http-request-smuggler

https://portswigger.net/blog/http-desync-attacks
Other
952 stars 101 forks source link

strange issue the trying to run the plugin #24

Closed chrjoh closed 4 years ago

chrjoh commented 4 years ago

Burp community edition, v 2.1.04 Installed the extension and see no errors in extensions panel, the option to launch smuggle probe is shown in the menu then selecting an host in the proxy menu, attack config is shown and hen I click OK , no error, no output pane is shown.

Looking at output in the extension menu for this plugin I see: thread pool size: 8 timeout: 10 use key: true key method: true key status: true key content-type: true key server: true key header names: false skip vulnerable hosts: false skip obsolete permutations: false only report exploitable: false risky mode: false Loaded HTTP Request Smuggler v1.03 Queued 1 attacks Queued 1 attacks Completed 1 of 1 Completed 2 of 2

and for turbo Intruder: Loaded Turbo Intruder v1.0.14

Can not figure out if I miss something in the setup or if there is a issue, as by looking it looks like the attack is performed but the result is not showing

albinowax commented 4 years ago

There's no issue here. In the community edition, if it detects a vulnerability the details will appear in the extension output. In your case, it hasn't detected a vulnerability.