
Exfiltrate blind Remote Code Execution and SQL injection output over DNS via Burp Collaborator.
Exfiltrate Blind Remote Code Execution and SQL injection output over DNS via Burp Collaborator.
Select a platform from the dropdown menu, enter the desired command, and press Execute. A payload will be generated for the chosen platform. Select Copy Payload to Clipboard, execute the generated payload on your target, and wait for results to appear in the output window.


Select a DBMS and extraction query type from the dropdown menu. Toggle between hex encoding output during DNS exfiltration (to preserve special characters, spaces, etc) or plaintext exfiltration, and press Dump. A payload will be generated for the chosen DBMS. Select Copy Payload to Clipboard, run the generated SQL query on your target, and wait for results to appear in the output window. Extracted "table" and "column" data will populate in subsequent "column" and "row" payloads.


If you liked this plugin, please consider donating:
BTC: 1GvMN6AAQ9WgGZpAX4SFVTi2xU7LgCXAh2
ETH: 0x847487DBcC6eC9b681a736BE763aca3cB8Debe49
Paypal: paypal.me/logueadam
4.0.1:
4.0:
3.0:
2.2:
2.1:
2.0:
1.0: