Operator tip · burp
Logger++ / Logger tab
Keep a full history of proxied traffic. When a bug reproduces once, your scrollback is the writeup backbone.
Guide
Bugs love to reproduce once and then vanish behind a race, a cache, or a one-time token. If you were not logging, you are writing fiction.
Why it matters
Burp's Logger (or the Logger++ extension) keeps a chronological record of requests and responses. That trail becomes your PoC steps, timestamps, and evidence for a quality report — which is exactly what Lab Lounge trains in report-quality.
How-to
- Enable Logger / install Logger++ and leave it running while you proxy.
- Filter by host when the lab shares a browser with other tabs.
- When something weird happens: pause, export the interesting rows, annotate in your notes.
- For writeups, screenshot or copy the exact request that flipped the bug — not a cleaned-up rewrite from memory.
# Writeup skeleton from logger rows 1. Auth as lowpriv → GET /api/item/1 2. Change id → GET /api/item/2 (200 + other user data) 3. Attach raw request/response from Logger