Repository navigation

#

ssrf

A list of resources for those interested in getting started in bug bounties

11177
9 个月前

This tool generates gopher link for exploiting SSRF and gaining RCE in various servers

Python
3046
2 年前

Java web common vulnerabilities and security code which is base on springboot and spring security

Java
2498
5 个月前

SSRF (Server Side Request Forgery) testing resources

Python
2397
6 个月前

Getting started with java code auditing 代码审计入门的小项目

JavaScript
909
2 年前

This Lab contain the sample codes which are vulnerable to Server-Side Request Forgery attack

PHP
712
2 年前

一款功能强大的漏洞扫描器,子域名爆破使用aioDNS,asyncio异步快速扫描,覆盖目标全方位资产进行批量漏洞扫描,中间件信息收集,自动收集ip代理,探测Waf信息时自动使用来保护本机真实Ip,在本机Ip被Waf杀死后,自动切换代理Ip进行扫描,Waf信息收集(国内外100+款waf信息)包括安全狗,云锁,阿里云,云盾,腾讯云等,提供部分已知waf bypass 方案,中间件漏洞检测(Thinkphp,weblogic等 CVE-2018-5955,CVE-2018-12613,CVE-2018-11759等),支持SQL注入, XSS, 命令执行,文件包含, ssrf 漏洞扫描, 支持自定义漏洞邮箱推送功能

Python
650
5 年前
TypeScript
559
2 年前

RevSuit is a flexible and powerful reverse connection platform designed for receiving connection from target host in penetration.

Go
536
2 年前

An exquisite dns&http log server for verify SSRF/XXE/RFI/RCE vulnerability

Go
467
2 年前

SSRF Proxy facilitates tunneling HTTP communications through servers vulnerable to Server-Side Request Forgery.

Ruby
461
7 年前

国光的手把手带你用 SSRF 打穿内网靶场源码

PHP
381
4 年前

Smart context-based SSRF vulnerability scanner.

Python
349
3 年前

XRCross is a Reconstruction, Scanner, and a tool for penetration / BugBounty testing. This tool was built to test (XSS|SSRF|CORS|SSTI|IDOR|RCE|LFI|SQLI) vulnerabilities

Shell
336
2 年前

A simple SSRF-testing sheriff written in Go

Go
327
6 个月前

Fast CLI tool to find the parameters that can be used to find SSRF or Out-of-band resource load 🛰 🦀

Rust
293
7 个月前