Burp Suite User Forum

Create new post

How can I be sure about "External service interaction (DNS)" issue

Marc | Last updated: Apr 16, 2021 03:50PM UTC

Hello, After a scan, burp triggered a High issue : External service interaction (DNS). I tried to repeat manually the issue using Burp Collaborator but collaborator didn't intercept anything. Having a closer look at the high issue triggered by Burp, I saw that the lookup intercepted by the collaborator was coming from IP address 172.217.40.76. It's look like a Google's IP. Is it a false positive ? Thanks for you answer. Regards

Michelle, PortSwigger Agent | Last updated: Apr 19, 2021 09:14AM UTC

Thanks for your message. Depending on how DNS requests are forwarded they can originate from other DNS servers, so this in itself would not necessarily confirm that the issue was a false positive. For example, if you weren't trying to replicate this particular issue, but used the Burp Collaborator client to generate a payload and then browse to it, you can then take a look at the source IPs for the DNS and HTTP interactions to help show this.

You must be an existing, logged-in customer to reply to a thread. Please email us for additional support.