
A Burp extension to detect and exploit versions of Telerik Web UI vulnerable to CVE-2017-9248.
A Burp extension to detect and exploit versions of Telerik Web UI vulnerable to CVE-2017-9248. This extension is based on the original exploit tool written by Paul Taylor (@bao7uo) which is available at https://github.com/bao7uo/dp_crypto. Credits and big thanks to him.
A related blog post on how to exploit web applications via Telerik Web UI can also be found here.


sudo pip install requests.


pip install requests to install it.stoud and stderr outputs cannot be seen there. However, you can view them under the Output and Errors sections of the Extender tab.PS: This is my first time developing a tool so apologies for the poor coding style. Feel free to contribute and improve the development of this tool.
Disclaimer: This tool is created for educational purposes only.