How to do it...

  1. Navigate to OWASP 2013 | A10 – Unvalidated Redirects and Forwards | Credits:
  1. Click the ISSA Kentuckiana link available on the Credits page:
  1. Switch to the Burp Proxy HTTP history tab, and find your request to the Credits page. Note that there are two query string parameters: page and forwardurl. What would happen if we manipulated the URL where the user is sent?
  1. Switch to the Burp Proxy Intercept tab. Turn Interceptor on ...

Get Burp Suite Cookbook now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.