docs

Hugin OOB

Hugin — out-of-band confirmation

Confirm blind bugs out-of-band. This is how you prove SSRF, XXE, blind SQLi, blind RCE, and Log4Shell when the response doesn't change.

Load the tools

Call tools/list with _meta.bundle = "oob". You get: oastify, vurl_oastify.

Load the skill fragment

Read MCP resource hugin://skill/oob for the full workflow + gotchas.

Workflow

  1. Plant a payload — call oastify to generate an OOB interaction URL (unique per test).
  2. Inject — place the URL in the parameter you're testing (SSRF target, XXE entity, SQLi payload).
  3. Wait — the target processes the payload and makes an outbound request to your OOB server.
  4. Check — call oastify to list interactions. Each callback names the exact test that fired it.
  5. Prove it — the callback IS the evidence. Capture the interaction record.

Rules

  • Authorised targets only. Stay in scope.
  • Each OOB payload gets a unique subdomain — match the callback to the exact test.
  • DNS callbacks are the most reliable (firewall-resistant). HTTP/HTTPS callbacks are more specific.
  • Wait long enough — some blind bugs take seconds or minutes (cron jobs, async processing).
  • No callback doesn't mean no bug — the target may have egress filtering. Try multiple protocols.
  • OOB confirms the bug fires — you still need to show impact.