Blind Command / Server-side OAST
Use controlled, callback-only discriminators to distinguish server-side processing from reflection and to establish a safe evidence trail for blind command or fetch hypotheses.
Tags: oast, blind, command-injection, ssrf, rce
Level: advanced
Method
Establish an authorized hypothesis
Start from a bounded feature that invokes a server-side parser, converter, integration, webhook, job runner, or diagnostic command. Record scope and the expected execution point; do not spray parameters or endpoints.
Use a unique callback marker
Generate one campaign and sink-specific callback URL. Submit it only through the suspect field with a benign payload appropriate to the parser. Watch for DNS/HTTP interaction and preserve event metadata without secrets.
Tools: interactsh
Differentiate the mechanism
Compare a control input, a URL-fetch marker, and a syntax-preserving command delimiter only where policy allows. Changes in callback protocol, timing, or source identify SSRF, template rendering, or command interpretation; one callback is not automatically RCE.
Tools: Burp Suite
Confirm minimal impact
Use an inert identifier or harmless delay only if necessary and allowed. Never read files, enumerate internal networks, retrieve credentials, or execute destructive commands. Stop when the discriminator establishes the primitive.
Capture reproducible evidence
Save sanitized request details, exact callback event, control comparison, timestamps, and rationale that rules out client-side execution. State residual uncertainty honestly.
Field notes
- Use a separate identifier for each field; callback correlation is your evidence.
- Prefer a canary-first proof over output exfiltration.