Burp Suite User Forum

Create new post

A flag to Prevent polling collaborator through socks 5 proxy

Breno | Last updated: May 16, 2023 10:28PM UTC

Sometimes, there is a need to set up a SOCKS proxy to an internal host. However, in certain network proxy settings, Oastify and custom collaborator servers may be blocked. In such cases, it would be ideal to have a flag that allows for using the proxy for all HTTP connections while still being able to poll the collaborator using my own network. This flag would address this particular issue and cater to this specific use case.

Michelle, PortSwigger Agent | Last updated: May 17, 2023 01:45PM UTC

Thanks for your message. Can you tell us more about your setup in this use case? Can the application you are testing see the public Collaborator server, but the machine where you have Burp installed (when using the SOCKS proxy) cannot see the public Collaborator server? How often do you come across this scenario?

Breno | Last updated: May 17, 2023 10:49PM UTC

> Can the application you are testing see the public Collaborator server, but the machine where you have Burp installed (when using the SOCKS proxy) cannot see the public Collaborator server? > but the machine where you have Burp installed can see the public or my custom collaborator socks5 can't see public or my custom collaborator My target can see public collaborator server to address this issue i'm using interactsh cli to test my targets ( outside burp and without socks5 ofcourse haha) but would be better if we had a option to poll results inside burp suite bypassing socks5 configuration. > How often do you come across this scenario? i do internal penetration tests so everyweek? hahaha

Michelle, PortSwigger Agent | Last updated: May 18, 2023 03:55PM UTC

Hi Can you email support@portswigger.net with a few more details of your workflow? I'm not sure if I'm picturing the right thing at the moment (sorry!). Are you only sending requests to test the system from outside of Burp and just using the Collaborator client within Burp to poll the Collaborator server?

You must be an existing, logged-in customer to reply to a thread. Please email us for additional support.