oast·server

Running this OAST server

A self-hosted, HTTP/HTTPS out-of-band interaction catcher with a live dashboard, deployable to Vercel. You plant a unique host; when a target resolves or requests it, the hit is recorded and shown on the dashboard.

What this captures — and what it can't

Vercel is serverless: it serves HTTP/HTTPS on 80/443 only. It cannot bind port 53 (DNS) or 25/465/587 (SMTP), and cannot hold the persistent listeners those channels need. So this deployment captures HTTP and HTTPS interactions. For DNS and SMTP — which many blind SSRF / SQLi / RCE payloads rely on — run interactsh-server on a small VPS that is authoritative for the zone. The two can share the same root domain (see the last section).

1 · Deploy to Vercel

# from the repo root
vercel            # link + deploy a preview
vercel --prod     # promote to production

Set these environment variables on the project:

OAST_DOMAIN = summarize.nikhilkanade.me     # the host you delegate below
OAST_TOKEN  = <random-secret>          # optional; gates the dashboard API
OAST_MAX    = 500                      # optional; in-memory buffer size

2 · Point the domain at Vercel

By default this runs in path mode (OAST_MODE=path): payloads live under one domain as summarize.nikhilkanade.me/c/<id>, so a single domain and its normal TLS cert are all you need. Add just the root at your registrar and under Project → Domains:

summarize.nikhilkanade.me      CNAME   cname.vercel-dns.com.

Optional — host mode. To use subdomain payloads (<id>.summarize.nikhilkanade.me), set OAST_MODE=host and add the wildcard *.summarize.nikhilkanade.me. Vercel issues a wildcard TLS cert only when it controls the domain's DNS, so this requires putting the zone on Vercel nameservers — a plain external CNAME is not enough and the wildcard will return DEPLOYMENT_NOT_FOUND.

3 · Generate a payload & verify

On the dashboard, enter your OAST_TOKEN if the deployment sets one, click Generate payload, then trigger it from anywhere:

curl -s https://summarize.nikhilkanade.me/c/<id>
curl -s https://summarize.nikhilkanade.me/c/<id>/ssrf-test   # any sub-path is captured

The request appears in the feed within a couple of seconds — method, source IP, headers, and body. Drop the URL into a suspected blind SSRF / XXE / RCE sink and watch for the out-of-band hit.

4 · A note on storage

Interactions live in an in-memory ring buffer, held only within a warm serverless instance. They are lost on cold starts, redeploys, and are not shared across instances — perfect for a live session, not for retention. For durable, multi-instance history, swap lib/store.ts for a Vercel KV / Redis-backed implementation with the same interface; nothing else changes.

5 · Adding DNS & SMTP (optional VPS)

To capture DNS and SMTP too, delegate the zone to a VPS running interactsh-server instead of pointing it at Vercel:

ns1.nikhilkanade.me.        A     <VPS_IP>       # glue
summarize.nikhilkanade.me.       NS    ns1.nikhilkanade.me.

# on the VPS
interactsh-server -domain summarize.nikhilkanade.me -ip <VPS_IP> -auth

That server answers every protocol on the zone. You can then use this Vercel app purely as a dashboard by having it read the interactsh-server API, or keep them separate — HTTP on Vercel, DNS/SMTP on the VPS. Keep the server token secret and rotate it per engagement.

Use only against systems you are authorized to test.