Burp Suite User Forum

Create new post

Plugin: Going from OS Command injection to shell with tab-completion in Burp

gnothi | Last updated: Sep 11, 2020 05:19PM UTC

I'm not sure if this is a good place to announce this, but: I wrote a Burp Suite plugin that offers a Shell-like environment right in burp: You can download the plugin here: https://github.com/gnothiseautonlw/burp-shell-fwd-lfi It offers tab-completion, command history and persistence... just by leveraging an OS Command injection vulnerability, without the need of uploading a web shell or creating a bind or reverse shell I wrote an article on how it can be used. That same article also describes the methods that the plugin uses to go from OS Command injection to a shell like environment with tab-completion. You can find it here: https://docs.google.com/document/d/1Vk-CPFgylO79IJaSRq930qDs7N-rQnVHpRp2I9ooqR8/edit?usp=sharing Anyone know how you can apply to make plugins available in the BApp Store?

You must be an existing, logged-in customer to reply to a thread. Please email us for additional support.