// the find
projectdiscovery/interactsh
An OOB interaction gathering server and client library
A blind/out-of-band interaction server and client for detecting SSRF, blind XXE, blind command injection and similar vulnerabilities that don't return a response in-band. It's the OOB piece of ProjectDiscovery's toolchain (same org as nuclei/httpx), aimed at bug bounty hunters and pentesters who need a Burp Collaborator-style server they can either use hosted or run themselves.
Covers DNS, HTTP(S), SMTP(S), LDAP, FTP and SMB/NTLM callbacks from one client instead of the DNS-only coverage most OOB tools stop at, which catches vulns that only fire over non-DNS protocols. The second-stage file hosting feature (for XXE external DTDs, XSLT includes, JNDI staging) is well thought through: off by default, authenticated, serves everything as application/octet-stream so it can't be turned into an XSS vector on your own domain, and prunes uploads on session end or TTL. Good ecosystem reach — Burp, ZAP and Caido extensions are maintained by third parties, plus a hosted web client and `notify` integration for async monitoring. The self-hosted server has real test coverage (dns_server_test.go, smtp_server_interaction_test.go, storage_redis_integration_test.go) rather than being a thin wrapper with no verification.
Serious use basically requires self-hosting: the public oast.* servers are shared infrastructure, get rotated/blocklisted, and you have no guarantee your correlation ID isn't visible to other tenants' abuse. Self-hosting means owning a domain, delegating nameservers to your VPS, and opening ports 53/80/443/25/389/445 — cloud providers frequently block outbound/inbound 25, which silently breaks SMTP OOB detection with no obvious error. Some server features are genuinely dangerous if misconfigured on a domain you care about — `-dynamic-resp` explicitly lets anyone execute arbitrary redirects/response bodies off your server's hostname, and the README's own warning about `-upload` turning a public instance into anonymous malware-staging is worth taking seriously rather than skimming past. It's Go-only for the client library; if your stack isn't Go you're shelling out to the CLI rather than getting a native SDK.