Professional

Reverse Shell Receiver

This extension provides penetration testers with an integrated tab combining an HTTP webhook listener for out-of-band testing (OAST), an interactive reverse shell terminal, and a multi-platform payload generator.

Features

  • HTTP webhook listener that starts a TCP socket server on a configurable port, captures inbound HTTP requests, and displays them in a sortable, filterable history table with full request and response detail in native editor panels.
  • Reconstructs target service details from the Host header so that captured requests support context menu actions such as sending to Repeater directly from the request/response editor.
  • Interactive reverse shell terminal that continuously listens for incoming connections, automatically re-enters the accept loop after a session ends, and probes the remote OS to display a live working directory prompt styled for Linux/UNIX, cmd.exe, or PowerShell.
  • Payload generator covering reverse and bind shells, web shells, and data exfiltration one-liners across Linux/macOS and Windows, with IP auto-detection from active network interfaces, and encoding options including None, Base64, and URL.
  • Listener status card showing an ONLINE/OFFLINE badge alongside clickable address chips that copy the listening address to the clipboard and transition visually on hover and copy.
  • Port management tool that scans for processes occupying a configured port using netstat and provides per-process kill controls on both Windows and Linux.
  • Content-Length clamped to 10 MB on inbound requests to prevent heap exhaustion from oversized request bodies.

Usage

  1. Open the extension tab and enter the desired port number for the HTTP webhook listener or reverse shell listener.
  2. Click the start button to bring the listener online; confirm the ONLINE badge appears in the status card.
  3. To capture out-of-band HTTP requests, direct target callbacks to your listening address and port. Incoming requests appear as rows in the history table; click a row to inspect the full request and response side-by-side.
  4. To use the reverse shell terminal, configure the target to connect back on the shell listener port. Once connected, the extension probes the remote OS and displays a prompt showing the current remote path. Type commands into the input field and press Enter to send.
  5. To generate a payload, select the Payload Generator panel, choose a category (Reverse/Bind Shell, Web Shell, or Data Exfiltration), select the target OS and template, pick your local IP from the interface dropdown, choose an encoding, and click generate. Use the copy button to place the payload on the clipboard.
  6. To send a captured request to another tool, right-click it in Proxy History or the message editor and select the appropriate context menu action (for example, Send to Repeater).
  7. If a port is already in use, click the Kill Used Ports button to scan for occupying processes and terminate them individually from the results dialog.

Author

Author

joelindra

Version

Version

1.0.0

Rating

Rating

Popularity

Popularity

Last updated

Last updated

13 August 2026

Estimated system impact

Estimated system impact

Overall impact: Empty

Memory
Empty
CPU
Empty
General
Empty
Scanner
Empty

You can install BApps directly within Burp, via the BApp Store feature in the Burp Extender tool. You can also download them from here, for offline installation into Burp.

You can view the source code for all BApp Store extensions on our GitHub page.

Follow @BApp_Store on Twitter to receive notifications of all BApp releases and updates.

Please note that extensions are written by third party users of Burp, and PortSwigger Web Security makes no warranty about their quality or usefulness for any particular purpose.

Go back to BappStore

Note:

Please note that extensions are written by third party users of Burp, and PortSwigger Web Security makes no warranty about their quality or usefulness for any particular purpose.