finds.dev← search

// the find

projectdiscovery/interactsh

★ 4,561 · Go · MIT · updated Sep 2026

An OOB interaction gathering server and client library

A blind/out-of-band interaction server and client for detecting SSRF, blind XXE, blind command injection and similar vulnerabilities that don't return a response in-band. It's the OOB piece of ProjectDiscovery's toolchain (same org as nuclei/httpx), aimed at bug bounty hunters and pentesters who need a Burp Collaborator-style server they can either use hosted or run themselves.

Covers DNS, HTTP(S), SMTP(S), LDAP, FTP and SMB/NTLM callbacks from one client instead of the DNS-only coverage most OOB tools stop at, which catches vulns that only fire over non-DNS protocols. The second-stage file hosting feature (for XXE external DTDs, XSLT includes, JNDI staging) is well thought through: off by default, authenticated, serves everything as application/octet-stream so it can't be turned into an XSS vector on your own domain, and prunes uploads on session end or TTL. Good ecosystem reach — Burp, ZAP and Caido extensions are maintained by third parties, plus a hosted web client and `notify` integration for async monitoring. The self-hosted server has real test coverage (dns_server_test.go, smtp_server_interaction_test.go, storage_redis_integration_test.go) rather than being a thin wrapper with no verification.

Serious use basically requires self-hosting: the public oast.* servers are shared infrastructure, get rotated/blocklisted, and you have no guarantee your correlation ID isn't visible to other tenants' abuse. Self-hosting means owning a domain, delegating nameservers to your VPS, and opening ports 53/80/443/25/389/445 — cloud providers frequently block outbound/inbound 25, which silently breaks SMTP OOB detection with no obvious error. Some server features are genuinely dangerous if misconfigured on a domain you care about — `-dynamic-resp` explicitly lets anyone execute arbitrary redirects/response bodies off your server's hostname, and the README's own warning about `-upload` turning a public instance into anonymous malware-staging is worth taking seriously rather than skimming past. It's Go-only for the client library; if your stack isn't Go you're shelling out to the CLI rather than getting a native SDK.

View on GitHub → Homepage ↗

// want more like this?

We dig through GitHub every week and send a few repos picked for what you actually care about — each with an honest take like this one.

Get finds in your inbox → Search again →