Collaborator settings

Burp Collaborator is an external service that Burp can use to help discover many kinds of vulnerabilities, such as external service interaction and out-of-band XSS.

Note

For more details about how Burp Collaborator works, see Burp Collaborator.

The Burp Collaborator server settings enable you to choose which Collaborator server you want to use:

Note

We periodically add new domain names for the public Collaborator server to reduce the chance of WAF blacklisting, which results in false negatives. By default, Burp Collaborator uses the domain in use when your version of Burp Suite Professional was released.

Currently, the domains in use are *.burpcollaborator.net or *.oastify.com. Make sure that your machine and target application can access both these domains on ports 80 and 443.

If you choose to use a private Collaborator server then you need to configure its location. You can provide the following information:

Note

If you have configured your Collaborator Server to use non-standard ports, then you must specify those ports here.

For more information on configuring non-standard ports, see Setting up the ports and firewall.

The following options are also available:

By default, Burp Collaborator server settings are user settings, affecting all Burp installations on your machine.

To make settings specific to the current project, switch the Override options for this project only toggle to On. Existing project file settings won't be affected as they will automatically have this setting enabled by default.