Repository navigation

#

ssrf

A list of resources for those interested in getting started in bug bounties

11466
1 年前

This tool generates gopher link for exploiting SSRF and gaining RCE in various servers

Python
3169
2 年前

Java web common vulnerabilities and security code which is base on springboot and spring security

Java
2578
9 个月前

SSRF (Server Side Request Forgery) testing resources

Python
2425
10 个月前

Getting started with java code auditing 代码审计入门的小项目

JavaScript
921
2 年前

This Lab contain the sample codes which are vulnerable to Server-Side Request Forgery attack

PHP
734
2 年前

一款功能强大的漏洞扫描器,子域名爆破使用aioDNS,asyncio异步快速扫描,覆盖目标全方位资产进行批量漏洞扫描,中间件信息收集,自动收集ip代理,探测Waf信息时自动使用来保护本机真实Ip,在本机Ip被Waf杀死后,自动切换代理Ip进行扫描,Waf信息收集(国内外100+款waf信息)包括安全狗,云锁,阿里云,云盾,腾讯云等,提供部分已知waf bypass 方案,中间件漏洞检测(Thinkphp,weblogic等 CVE-2018-5955,CVE-2018-12613,CVE-2018-11759等),支持SQL注入, XSS, 命令执行,文件包含, ssrf 漏洞扫描, 支持自定义漏洞邮箱推送功能

Python
651
6 年前
TypeScript
566
3 年前

RevSuit is a flexible and powerful reverse connection platform designed for receiving connection from target host in penetration.

Go
550
2 年前

An exquisite dns&http log server for verify SSRF/XXE/RFI/RCE vulnerability

Go
473
2 年前

SSRF Proxy facilitates tunneling HTTP communications through servers vulnerable to Server-Side Request Forgery.

Ruby
471
8 年前

国光的手把手带你用 SSRF 打穿内网靶场源码

PHP
393
4 年前

Smart context-based SSRF vulnerability scanner.

Python
355
3 年前

XRCross is a Reconstruction, Scanner, and a tool for penetration / BugBounty testing. This tool was built to test (XSS|SSRF|CORS|SSTI|IDOR|RCE|LFI|SQLI) vulnerabilities

Shell
339
2 年前

A simple SSRF-testing sheriff written in Go

Go
329
10 个月前

Find All Parameters - Tool to crawl pages, find potential parameters and generate a custom target parameter wordlist

Go
316
1 年前