Running this OAST server
A self-hosted, HTTP/HTTPS out-of-band interaction catcher with a live dashboard, deployable to Vercel. You plant a unique host; when a target resolves or requests it, the hit is recorded and shown on the dashboard.
What this captures — and what it can't
Vercel is serverless: it serves HTTP/HTTPS on 80/443 only. It cannot bind port 53 (DNS) or 25/465/587 (SMTP), and cannot hold the persistent listeners those channels need. So this deployment captures HTTP and HTTPS interactions. For DNS and SMTP — which many blind SSRF / SQLi / RCE payloads rely on — run interactsh-server on a small VPS that is authoritative for the zone. The two can share the same root domain (see the last section).
1 · Deploy to Vercel
# from the repo root vercel # link + deploy a preview vercel --prod # promote to production
Set these environment variables on the project:
OAST_DOMAIN = summarize.nikhilkanade.me # the host you delegate below OAST_TOKEN = <random-secret> # optional; gates the dashboard API OAST_MAX = 500 # optional; in-memory buffer size
2 · Point the domain at Vercel
By default this runs in path mode (OAST_MODE=path): payloads live under one domain as summarize.nikhilkanade.me/c/<id>, so a single domain and its normal TLS cert are all you need. Add just the root at your registrar and under Project → Domains:
summarize.nikhilkanade.me CNAME cname.vercel-dns.com.
Optional — host mode. To use subdomain payloads (<id>.summarize.nikhilkanade.me), set OAST_MODE=host and add the wildcard *.summarize.nikhilkanade.me. Vercel issues a wildcard TLS cert only when it controls the domain's DNS, so this requires putting the zone on Vercel nameservers — a plain external CNAME is not enough and the wildcard will return DEPLOYMENT_NOT_FOUND.
3 · Generate a payload & verify
On the dashboard, enter your OAST_TOKEN if the deployment sets one, click Generate payload, then trigger it from anywhere:
curl -s https://summarize.nikhilkanade.me/c/<id> curl -s https://summarize.nikhilkanade.me/c/<id>/ssrf-test # any sub-path is captured
The request appears in the feed within a couple of seconds — method, source IP, headers, and body. Drop the URL into a suspected blind SSRF / XXE / RCE sink and watch for the out-of-band hit.
4 · A note on storage
Interactions live in an in-memory ring buffer, held only within a warm serverless instance. They are lost on cold starts, redeploys, and are not shared across instances — perfect for a live session, not for retention. For durable, multi-instance history, swap lib/store.ts for a Vercel KV / Redis-backed implementation with the same interface; nothing else changes.
5 · Adding DNS & SMTP (optional VPS)
To capture DNS and SMTP too, delegate the zone to a VPS running interactsh-server instead of pointing it at Vercel:
ns1.nikhilkanade.me. A <VPS_IP> # glue summarize.nikhilkanade.me. NS ns1.nikhilkanade.me. # on the VPS interactsh-server -domain summarize.nikhilkanade.me -ip <VPS_IP> -auth
That server answers every protocol on the zone. You can then use this Vercel app purely as a dashboard by having it read the interactsh-server API, or keep them separate — HTTP on Vercel, DNS/SMTP on the VPS. Keep the server token secret and rotate it per engagement.
Use only against systems you are authorized to test.