Burp Suite User Forum

Create new post

Web shell upload via extension blacklist bypass

Jagathy | Last updated: Mar 19, 2022 06:34AM UTC

Burp suite did not catch GET request to /files/avatars/<YOUR-IMAGE>

Ben, PortSwigger Agent | Last updated: Mar 21, 2022 08:03AM UTC

Hi Jagathy, Have you altered the Filter settings in the HTTP history so that image MIME types are being displayed? If not, you can do this by clicking the Filter bar and the,n in the subsequent 'Filter settings' dialog, making sure the 'Images' option is enabled.

You must be an existing, logged-in customer to reply to a thread. Please email us for additional support.