Burp Suite User Forum

Create new post

Cannot reproduce certain finding on Burp Collaborator

Nikolaos | Last updated: Feb 01, 2021 04:57PM UTC

Hello. I was doing a Burp Scan the other day and the report gave me an "External Service Interaction (DNS)" finding. The collaborator payload was submitted in the SSL SNI and the HTTP Host header. I checked with Logger++ and located the packet that caused the interaction with the Burp Collaborator. I tried to reproduce that behaviour in the Repeater but I wasn't able to achieve that. The response came from an AkamaiGhost proxy and it was a 400 Bad request. Nevertheless during the test the Burp Collaborator received a DNS lookup of Type A for the following domain name proxy-host.hpawb6p8xxichueswh9mtdp6sxyqmga99xzkp8e.burpcollaborator.net What strikes me first is the proxy-host in front of it and I was wondering if anyone has an idea how I could manually reproduce that. Thanks.

Uthman, PortSwigger Agent | Last updated: Feb 02, 2021 10:15AM UTC

Hi Nikolas, Have you tried using the collaborator client to replicate the issue? - https://portswigger.net/burp/documentation/desktop/tools/collaborator-client

You must be an existing, logged-in customer to reply to a thread. Please email us for additional support.