Burp Suite User Forum

Create new post

Scan for blind OS command injection

Peter | Last updated: Nov 11, 2021 01:14PM UTC

Often when I am learning in the academy I wonder if that particular vulnerability would popup using the scanner. The lab https://portswigger.net/web-security/os-command-injection/lab-blind-time-delays contains such a vuln but the scanner did not recognize it. Is this a sign the scanner doesn't test for blind OS command injection? How can I get a better insight in what is scanned and what not?

Ben, PortSwigger Agent | Last updated: Nov 11, 2021 07:33PM UTC

Hi Peter, I have just tried scanning this particular lab, using the latest version of Burp, and it correctly identifies an OS Command Injection on the /feedback/submit path. In addition, simply performing an active scan on the /feedback/submit request (after I have performed some manual browsing of the lab) also identifies the presence of this vulnerability. How have you configured your scan?

You must be an existing, logged-in customer to reply to a thread. Please email us for additional support.