Standalone OAST client for the public Burp Collaborator infrastructure.
OAST-Community generates reusable out-of-band payloads and retrieves DNS and HTTP(S) interactions without requiring Burp Suite Professional.
The client uses a persistent Collaborator context, allowing multiple payloads to be generated and tracked from the same session. It also includes manual polling and a continuous listener for incoming interactions.
No third-party Python packages are required.
This is an unofficial project and is not affiliated with or endorsed by PortSwigger.
- Creates or restores a local Collaborator client context.
- Generates unique
*.oastify.comOAST payloads. - Tracks multiple payloads under the same context.
- Polls the public Collaborator infrastructure for new interactions.
- Groups DNS callbacks to reduce duplicate resolver noise.
- Displays complete HTTP and HTTPS requests received by the OAST server.
- Provides a continuous listener mode for real-time interaction monitoring.
- Persists the client context between executions.
- Supports ephemeral sessions when persistence is not desired.
- Uses only the Python standard library.
Python 3.10+No third-party Python packages are required.
Clone the repository:
git clone https://github.com/Groppoxx/OAST-Community.git
cd OAST-CommunityRun the client:
python3 oast_community.pyThe first execution creates a persistent client context automatically.
╭────────────────────────────────────────────────────────────╮
│ OAST Community v1.0.0 │
├────────────────────────────────────────────────────────────┤
│ Payloads 0 │
│ Latest none │
├────────────────────────────────────────────────────────────┤
│ [1] New payload │
│ [2] Poll now │
│ [3] Listen │
│ [0] Exit │
╰────────────────────────────────────────────────────────────╯
Select >
Select:
[1] New payload
Example:
[2026-09-27T21:20:34Z] [+] Payload #1 generated
4bgaemtqblaca8gt3a62xdaf96fw3l.oastify.com
The generated hostname can be used depending on the OAST sink being tested.
DNS:
4bgaemtqblaca8gt3a62xdaf96fw3l.oastify.com
HTTP:
http://4bgaemtqblaca8gt3a62xdaf96fw3l.oastify.com/
HTTPS:
https://4bgaemtqblaca8gt3a62xdaf96fw3l.oastify.com/
For example:
curl "http://4bgaemtqblaca8gt3a62xdaf96fw3l.oastify.com/http-test"or:
curl "https://4bgaemtqblaca8gt3a62xdaf96fw3l.oastify.com/https-test"Select:
[2] Poll now
Example output:
[2026-09-27T21:25:07Z] [*] Polling for interactions
[2026-09-27T21:25:09Z] [+] 3 interactions received · 2 DNS · 1 HTTPS
╭────────────────────────────────────────────────────────────────────────────╮
│ Payload #1 · 2 DNS · 1 HTTPS │
├────────────────────────────────────────────────────────────────────────────┤
│ DNS A │
│ Query 4bgaemtqblaca8gt3a62xdaf96fw3l.oastify.com │
│ Resolvers 3.251.104.252, 3.251.104.34 │
│ │
│ HTTPS │
│ Time 2026-09-27T21:25:04.333Z │
│ Source 34.251.122.40:38382 │
│ │
│ GET / HTTP/1.1 │
│ Host: 4bgaemtqblaca8gt3a62xdaf96fw3l.oastify.com │
│ Accept-Encoding: gzip │
╰────────────────────────────────────────────────────────────────────────────╯
Multiple DNS requests may be generated for a single OAST interaction because different DNS resolvers can query the same payload.
OAST-Community groups those callbacks together while preserving the individual resolver addresses.
Select:
[3] Listen
The client continuously polls for new interactions:
[2026-09-27T21:30:01Z] [*] Listening · polling every 5s
[2026-09-27T21:30:01Z] [*] Ctrl+C to return
New interactions are printed automatically when they arrive.
Press:
Ctrl+C
to stop listening and return to the main menu.
A single client context can generate multiple OAST payloads.
Example:
Payload #1
aaaaaaaaaaaaaaaaaaaaaaaaaaaaaa.oastify.com
Payload #2
bbbbbbbbbbbbbbbbbbbbbbbbbbbbbb.oastify.com
Both payloads remain associated with the same client context.
The main menu shows the number of generated payloads and the most recently generated hostname:
╭────────────────────────────────────────────────────────────╮
│ OAST Community v1.0.0 │
├────────────────────────────────────────────────────────────┤
│ Payloads 2 │
│ Latest bbbbbbbbbbbbbbbbbbbbbbbbbbbbbb.oastify.com │
├────────────────────────────────────────────────────────────┤
│ [1] New payload │
│ [2] Poll now │
│ [3] Listen │
│ [0] Exit │
╰────────────────────────────────────────────────────────────╯
Interactions are automatically mapped back to the payload that generated them.
By default, OAST-Community saves the current client context under:
~/.oast-community/
The state file contains the information required to retrieve interactions for previously generated payloads.
On Unix-like systems, the directory and state files are created with restrictive permissions.
This allows the client to be closed and reopened without losing the current context.
For example:
python3 oast_community.pymay restore:
Payloads 2
Latest bbbbbbbbbbbbbbbbbbbbbbbbbbbbbb.oastify.com
To replace the current persistent context with a new one:
python3 oast_community.py --new-contextThe new context starts with:
Payloads 0
Latest none
To create a temporary context without reading or writing state:
python3 oast_community.py --no-stateThe context exists only for the lifetime of the process.
--domain <DOMAIN>
Payload domain.
Default: oastify.com
--poll-host <HOST>
Collaborator polling host.
Default: polling.oastify.com
--interval <SECONDS>
Continuous listener polling interval.
Default: 5
--timeout <SECONDS>
Maximum network request time.
Default: 15
--new-context
Replace the current persistent client context with a new one.
--no-state
Run with an ephemeral context and disable state persistence.
--no-color
Disable ANSI terminal colors.
--debug
Enable additional diagnostic information.
--version
Print the current OAST-Community version.
Example:
python3 oast_community.py --debugDisable colors:
python3 oast_community.py --no-colorCheck the installed version:
python3 oast_community.py --versionExample:
OAST Community 1.0.0
OAST testing is useful when a vulnerability cannot directly return its result to the tester.
Instead, the tested application is induced to interact with an external server controlled by the tester.
Typical interaction types include:
DNS
HTTP
HTTPS
SMTP
OAST-Community creates a client context and generates unique interaction identifiers associated with that context.
A generated payload may then be inserted into an authorized security test, for example where an application performs a server-side request.
When the target resolves or requests the generated hostname, the interaction is recorded by the Collaborator infrastructure.
OAST-Community retrieves those interactions through polling and maps them back to the corresponding locally generated payload.
OAST techniques are commonly useful when testing for vulnerabilities such as:
- Blind SSRF
- Blind command injection
- Blind XXE
- Server-side URL fetching
- Out-of-band data exfiltration in authorized environments
- DNS-based callback detection
- HTTP callback detection
The generated payload itself is intentionally displayed as a hostname:
example.oastify.com
This allows the same payload to be reused in different protocols and contexts.
- OAST-Community currently defaults to the public
oastify.comCollaborator infrastructure. - Public Collaborator infrastructure is operated by PortSwigger and may change independently of this project.
- Polling can consume interactions returned by the server, so retrieved events may not appear again on subsequent polls.
- DNS callbacks may involve multiple recursive resolvers for a single application action.
- HTTP and HTTPS callbacks are displayed separately when the Collaborator backend reports the protocol distinction.
- The local state should be treated as sensitive because it contains the client context required to retrieve interactions.
- Do not publish or commit files from
~/.oast-community/.
OAST-Community/
├── LICENSE
├── README.md
├── requirements.txt
└── oast_community.py
-
OAST-Community is intended for authorized security testing, educational environments, vulnerability research, and lab use.
-
Only use this software against systems you own or have explicit permission to test.
-
The authors and contributors are not responsible for misuse or damage caused by this software.
-
Burp Suite, Burp Collaborator, and PortSwigger are trademarks or products of their respective owners.
-
This project is unofficial and is not affiliated with, sponsored by, or endorsed by PortSwigger.