Post

Beware Burp Suite AI Explore Feature Using Malicious Commands

I recently decided to try the explore with AI feature of Burp Suite after param miner discovered an issue I hadn’t seen before. It proceeded through the process, then eventually did this:

Obviously, using a DROP TABLE command could be an issue when testing. I wonder what other commands it will try - rm -rf /? I reported it to their bug bounty program, not expected to get a bounty (I did not get one). I was told to report it to their support who said it’s a known issue.

I would say to error on the side of caution and not use this feature.

This post is licensed under CC BY 4.0 by the author.