Professional

Collabfiltrator

This Burp Extension assists in exfiltration of blind Remote Code Execution output and SQL injection output over DNS via Burp Collaborator.

RCE Exfiltration

Usage

  1. Select a platform from the dropdown menu.
  2. Enter the desired command.
  3. Press "Execute". This will generate a payload for your chosen platform.
  4. Select "Copy payload to clipboard".
  5. Execute the generated payload on your target.
  6. Wait for results to appear in the output window.

Supported RCE targets

  • Windows (Powershell)
  • Linux (sh + ping)
  • Linux (sh + nslookup)
  • Linux (bash + ping)
  • Linux (bash + nslookup)

SQLi Exfiltration

Usage

  1. Select a DBMS and extraction query type from the dropdown menu.
  2. Toggle between hex encoding output during DNS exfiltration (to preserve special characters, spaces, etc) or plaintext exfiltration.
  3. Press "Dump". This will generate a payload for the chosen DBMS.
  4. Select "Copy payload to clipboard".
  5. Run the generated SQL query on your target.
  6. Wait for results to appear in the output window.
    Extracted "table" and "column" data will populate in subsequent "column" and "row" payloads.

Supported SQLi targets

  • Microsoft SQL Server (Stacked Queries)
  • MySQL (Windows)
  • PostgreSQL (Elevated Privileges)
  • Oracle (Elevated Privileges)
  • Oracle (XML External Entities)

Author

Author

Adam Logue, Frank Scarpella, Jared McLaren, Ryan Griffin

Version

Version

4.0.1

Rating

Rating

Popularity

Popularity

Last updated

Last updated

31 January 2025

Estimated system impact

Estimated system impact

Overall impact: Low

Memory
Low
CPU
Low
General
Low
Scanner
Low

You can install BApps directly within Burp, via the BApp Store feature in the Burp Extender tool. You can also download them from here, for offline installation into Burp.

You can view the source code for all BApp Store extensions on our GitHub page.

Follow @BApp_Store on Twitter to receive notifications of all BApp releases and updates.

Please note that extensions are written by third party users of Burp, and PortSwigger Web Security makes no warranty about their quality or usefulness for any particular purpose.

Go back to BappStore

Note:

Please note that extensions are written by third party users of Burp, and PortSwigger Web Security makes no warranty about their quality or usefulness for any particular purpose.