vulns.co
/
GKData.io MCP

Back to Playbooks

Blind Command / Server-side OAST

Use controlled, callback-only discriminators to distinguish server-side processing from reflection and to establish a safe evidence trail for blind command or fetch hypotheses.

Tags: oast, blind, command-injection, ssrf, rce

Level: advanced

Method

  1. Establish an authorized hypothesis

    Start from a bounded feature that invokes a server-side parser, converter, integration, webhook, job runner, or diagnostic command. Record scope and the expected execution point; do not spray parameters or endpoints.

  2. Use a unique callback marker

    Generate one campaign and sink-specific callback URL. Submit it only through the suspect field with a benign payload appropriate to the parser. Watch for DNS/HTTP interaction and preserve event metadata without secrets.

    Tools: interactsh

  3. Differentiate the mechanism

    Compare a control input, a URL-fetch marker, and a syntax-preserving command delimiter only where policy allows. Changes in callback protocol, timing, or source identify SSRF, template rendering, or command interpretation; one callback is not automatically RCE.

    Tools: Burp Suite

  4. Confirm minimal impact

    Use an inert identifier or harmless delay only if necessary and allowed. Never read files, enumerate internal networks, retrieve credentials, or execute destructive commands. Stop when the discriminator establishes the primitive.

  5. Capture reproducible evidence

    Save sanitized request details, exact callback event, control comparison, timestamps, and rationale that rules out client-side execution. State residual uncertainty honestly.

Field notes

  • Use a separate identifier for each field; callback correlation is your evidence.
  • Prefer a canary-first proof over output exfiltration.

References