How to do it...

  1. Log into the Mutillidae application as admin with the password admin.
  2. Now log out of the application by clicking the Logout button from the top menu.
  3. Verify you are logged out by noting the Not Logged In message.
  4. View these steps as messages in Burp's Proxy | History as well. Note the logout performs a 302 redirect in an effort to not cache cookies or credentials in the browser:
  1. From the Firefox browser, click the back button and notice that you are now logged in as admin even though you did not log in! This is possible because of cached credentials stored in the browser and the lack of any cache-control protections set ...

Get Burp Suite Cookbook now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.