Skip to content

Out-of-band resource load (HTTP) (Burp Active Scanner) #10

@0xdevalias

Description

@0xdevalias

So I was running a burp active scan while I still had this proxy enabled, and it reported the following:

GET / HTTP/1.1
Host: 0312i1bkk8obx8ks6zjcxn4uvl1kpcr0hn7bw.burpcollaborator.net
Pragma: no-cache
Cache-Control: no-cache, no-transform
Connection: close
HTTP/1.1 200 OK
server: Burp Collaborator https://burpcollaborator.net/
x-collaborator-version: 4
content-type: text/html
content-length: 60
Date: Mon, 13 Nov 2017 21:18:58 GMT
Connection: close

<html><body>u7rlb1gwv1pfcez5563zzjzjrgkugifigz</body></html>

Knowing it'll happen means I can account for it, but might pose a potential (rather small) risk when proxying through this server.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions