
Un servidor de recopilación de interacciones OOB y una biblioteca cliente
Características • Uso • Cliente Interactsh • Servidor Interactsh • Integración de Interactsh • Únete a Discord
Interactsh es una herramienta de código abierto para detectar interacciones fuera de banda. Es una herramienta diseñada para detectar vulnerabilidades que provocan interacciones externas.
interactsh-client -h
Esto mostrará la ayuda de la herramienta. Aquí están todos los modificadores que soporta.```yaml
Usage:
./interactsh-client [flags]
Flags:
INPUT:
-s, -server string interactsh server(s) to use (default "oast.pro,oast.live,oast.site,oast.online,oast.fun,oast.me")
-fl, -file string[] local file(s) to upload and host on the interactsh server
CONFIG:
-config string flag configuration file (default "$HOME/.config/interactsh-client/config.yaml")
-auth configure projectdiscovery cloud (pdcp) api key (default true)
-n, -number int number of interactsh payload to generate (default 1)
-t, -token string authentication token to connect protected interactsh server
-pi, -poll-interval int poll interval in seconds to pull interaction data (default 5)
-nf, -no-http-fallback disable http fallback registration
-cidl, -correlation-id-length int length of the correlation id preamble (min 3, default 20) (default 20)
-cidn, -correlation-id-nonce-length int length of the correlation id nonce (min 3, default 13) (default 13)
-sf, -session-file string store/read from session file
-kai, -keep-alive-interval value keep alive interval (default 1m0s)
FILTER:
-m, -match string[] match interaction based on the specified pattern
-f, -filter string[] filter interaction based on the specified pattern
-dns-only display only dns interaction in CLI output
-http-only display only http interaction in CLI output
-smtp-only display only smtp interactions in CLI output
-asn include asn information of remote ip in json output
UPDATE:
-up, -update update interactsh-client to latest version
-duc, -disable-update-check disable automatic interactsh-client update check
OUTPUT:
-o string output file to write interaction data
-json write output in JSON Lines format
-ps, -payload-store write generated interactsh payload to file
-psf, -payload-store-file string store generated interactsh payloads to given file (default "interactsh_payload.txt")
-fsf, -file-store-file string store hosted file URLs to given file (requires -file)
-v display verbose interaction
DEBUG:
-version show version of the project
-health-check, -hc run diagnostic check up
El cliente CLI de Interactsh requiere go1.20+ para instalarse correctamente. Ejecute el siguiente comando para obtener el repositorio -```sh go install -v github.com/projectdiscovery/interactsh/cmd/interactsh-client@latest
### Configurar PDCP_API_KEY con el cliente CLI de Interactsh
> Obtén tu clave API gratuita registrándote en https://cloud.projectdiscovery.io
Puedes configurar tu PDCP_API_KEY de dos maneras:
1. Para configurar la clave API de forma interactiva, ejecuta el siguiente comando: ```sh
./interactsh-client -auth
Esto generará un payload único que puede usarse para pruebas OOB con información de interacción mínima en la salida.```console $ interactsh-client
_ __ __ __
()__ / /____ _________ / // /_
/ / __ / / _ / / __ '/ / __/ __/ __
/ / / / / // __/ / / // / // /( ) / / /
/// //_/_// _,/___/_/__// // v0.0.5
projectdiscovery.io
[INF] Listing 1 payload for OOB Testing [INF] c23b2la0kl1krjcrdj10cndmnioyyyyyn.oast.pro
[c23b2la0kl1krjcrdj10cndmnioyyyyyn] Received DNS interaction (A) from 172.253.226.100 at 2021-26-26 12:26 [c23b2la0kl1krjcrdj10cndmnioyyyyyn] Received DNS interaction (AAAA) from 32.3.34.129 at 2021-26-26 12:26 [c23b2la0kl1krjcrdj10cndmnioyyyyyn] Received HTTP interaction from 43.22.22.50 at 2021-26-26 12:26 [c23b2la0kl1krjcrdj10cndmnioyyyyyn] Received HTTPS interaction from 43.22.22.50 at 2021-26-26 12:26 [c23b2la0kl1krjcrdj10cndmnioyyyyyn] Received DNS interaction (MX) from 43.3.192.3 at 2021-26-26 12:26 [c23b2la0kl1krjcrdj10cndmnioyyyyyn] Received DNS interaction (TXT) from 74.32.183.135 at 2021-26-26 12:26 [c23b2la0kl1krjcrdj10cndmnioyyyyyn] Received SMTP interaction from 32.85.166.50 at 2021-26-26 12:26
### Archivo de sesión
`interactsh-client` con el flag `-sf, -session-file` se puede usar para almacenar/leer la información de la sesión actual desde un archivo definido por el usuario, lo cual es útil para reanudar la misma sesión y consultar las interacciones incluso después de que el cliente se detenga o se cierre.```console
$ interactsh-client -sf interact.session
_ __ __ __
(_)___ / /____ _________ ______/ /______/ /_
/ / __ \/ __/ _ \/ ___/ __ '/ ___/ __/ ___/ __ \
/ / / / / /_/ __/ / / /_/ / /__/ /_(__ ) / / /
/_/_/ /_/\__/\___/_/ \__,_/\___/\__/____/_/ /_/ 1.0.3
projectdiscovery.io
[INF] Listing 1 payload for OOB Testing
[INF] c23b2la0kl1krjcrdj10cndmnioyyyyyn.oast.pro