Burp Suite User Forum

Create new post

Collaborator External Service Interaction (DNS) - Mismatch in attack vector

Federico | Last updated: Jun 26, 2015 09:28AM UTC

There is a mismatch in the Collaborator External Service Interaction (DNS) between the URL inserted in the attack vector and the DNS request that Burp collaborator display in scanner result. One example advisory: Advisory: External service interaction (DNS) POST parameter of the request: xxx=http%3a%2f%2fdhylxw3clwxogtvs1ngy14fan1tuzk7avz.collaborator.xxx.net Colllaborator event: The Collaborator server received a DNS lookup of type A for the domain name v403kequ8ek63biao53gom2sajgco20shh.collaborator.xxx.net.

PortSwigger Agent | Last updated: Jun 29, 2015 01:13PM UTC

Thanks for this report. We're looking into this issue and will get back to you if we need any further details.

PortSwigger Agent | Last updated: Jun 29, 2015 01:13PM UTC

We've fixed this issue in today's Burp release (v1.6.21). Thanks for the feedback, and please let us know if you identify any other problems.

You must be an existing, logged-in customer to reply to a thread. Please email us for additional support.