The Burp Suite User Forum was discontinued on the 1st November 2024.

Burp Suite User Forum

For support requests, go to the Support Center. To discuss with other Burp users, head to our Discord page.

SUPPORT CENTER DISCORD

Scan for blind OS command injection

Peter | Last updated: Nov 11, 2021 01:14PM UTC

Often when I am learning in the academy I wonder if that particular vulnerability would popup using the scanner. The lab https://portswigger.net/web-security/os-command-injection/lab-blind-time-delays contains such a vuln but the scanner did not recognize it. Is this a sign the scanner doesn't test for blind OS command injection? How can I get a better insight in what is scanned and what not?

Ben, PortSwigger Agent | Last updated: Nov 11, 2021 07:33PM UTC