An issue was discovered in PortSwigger Burp Suite before 2021.2. During viewing of a malicious request, it can be manipulated into issuing a request that does not respect its upstream proxy configuration. This could leak NetNTLM hashes on Windows systems that fail to block outbound SMB.
Link | Tags |
---|---|
https://hackerone.com/reports/1054382 | issue tracking exploit third party advisory |
https://portswigger.net/burp/releases/professional-community-2020-12?requestededition=professional | release notes vendor advisory |