Hugin OOB
Hugin — out-of-band confirmation
Confirm blind bugs out-of-band. This is how you prove SSRF, XXE, blind SQLi, blind RCE, and Log4Shell when the response doesn't change.
Load the tools
Call tools/list with _meta.bundle = "oob". You get: oastify, vurl_oastify.
Load the skill fragment
Read MCP resource hugin://skill/oob for the full workflow + gotchas.
Workflow
- Plant a payload — call
oastifyto generate an OOB interaction URL (unique per test). - Inject — place the URL in the parameter you're testing (SSRF target, XXE entity, SQLi payload).
- Wait — the target processes the payload and makes an outbound request to your OOB server.
- Check — call
oastifyto list interactions. Each callback names the exact test that fired it. - Prove it — the callback IS the evidence. Capture the interaction record.
Rules
- Authorised targets only. Stay in scope.
- Each OOB payload gets a unique subdomain — match the callback to the exact test.
- DNS callbacks are the most reliable (firewall-resistant). HTTP/HTTPS callbacks are more specific.
- Wait long enough — some blind bugs take seconds or minutes (cron jobs, async processing).
- No callback doesn't mean no bug — the target may have egress filtering. Try multiple protocols.
- OOB confirms the bug fires — you still need to show impact.