Collaborator settings

Burp Collaborator is an external service that Burp can use to help discover many kinds of vulnerabilities, such as external service interaction and out-of-band XSS.

Note

For more details about how Burp Collaborator works, see Burp Collaborator.

The Burp Collaborator server settings enable you to choose which Collaborator server you want to use:

Note

We periodically add new domain names for the public Collaborator server to reduce the chance of WAF blacklisting, which results in false negatives. By default, Burp Collaborator uses the domain in use when your version of Burp Suite Professional was released.

Currently, the domains in use are *.burpcollaborator.net or *.oastify.com. Make sure that your machine and target application can access both these domains on ports 80 and 443.

If you choose to use a private Collaborator server then you need to configure its location. You can provide the following information:

Note

If you have configured your Collaborator Server to use non-standard ports, then you must specify those ports here.

For more information on configuring non-standard ports, see Setting up the ports and firewall.

The following options are also available:

The Burp Collaborator server settings are project settings. They apply to the current project only.