Elektrine lite

← Feed

@deepthoughts10@infosec.exchange

Post #642937

2026-03-11 02:07 UTC

What are Out-of-band Application Security Testing (OAST) domains? Out-of-band application security testing (OAST) is a method for finding exploitable vulnerabilities in a web application by forcing a target to call back to a piece of infrastructure controlled by the tester. OAST domains (sub-domains most often) are often free and hosted by OAST tool providers like interact.sh. What happens when something is free on the Internet? It gets abused. Let’s make tOAST of the most commonly abused OAST domains! @greynoise has an in-depth writeup on recent campaigns using OAST infrastructure. OAST Domains/Provider: All 33 campaigns use Interactsh 5,560 unique callback sub-domains observed Block these domains to stop these attacks: oast.pro, oast.live, oast.fun, oast.me, oast.site #cybersecurity https://www.labs.greynoise.io/grimoire/2026-02-20-weekly-oast-report/

Replies (0)

No replies.