awesome-repositories.com
المدونة
MCP
awesome-repositories.com

اكتشف أفضل مستودعات المصادر المفتوحة باستخدام بحث مدعوم بالذكاء الاصطناعي.

استكشفعمليات بحث منسقةبدائل مفتوحة المصدربرمجيات ذاتية الاستضافةالمدونةخريطة الموقع
المشروعخادم MCPحولكيفية ترتيب النتائجالصحافة
قانونيالخصوصيةالشروط
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
·

23 مستودعات

Awesome GitHub RepositoriesServer Side Request Forgery

Tools for detecting and exploiting SSRF and DNS rebinding.

Explore 23 awesome GitHub repositories matching part of an awesome list · Server Side Request Forgery. Refine with filters or upvote what's useful.

Awesome Server Side Request Forgery GitHub Repositories

اعثر على أفضل المستودعات باستخدام الذكاء الاصطناعي.سنبحث عن أفضل المستودعات المطابقة باستخدام الذكاء الاصطناعي.
  • daffainfo/allaboutbugbountyالصورة الرمزية لـ daffainfo

    daffainfo/AllAboutBugBounty

    6,644عرض على GitHub↗

    AllAboutBugBounty is a curated collection of bug bounty techniques and payloads for web application security testing. It serves as a reference resource covering common web vulnerabilities and exploitation methods for security researchers, providing a structured approach to identifying and exploiting web application security flaws in bug bounty programs. The repository covers a wide range of attack categories including authentication bypass, cross-site scripting injection, server-side request forgery, web cache poisoning, and business logic abuse. It includes techniques for bypassing access co

    Covers forging server-side requests to bypass firewalls and access internal services.

    bugbugbountybugbountytips
    عرض على GitHub↗6,644
  • zhuifengshaonianhanlu/pikachuالصورة الرمزية لـ zhuifengshaonianhanlu

    zhuifengshaonianhanlu/pikachu

    4,421عرض على GitHub↗

    Pikachu هي منصة تدريب على أمن الويب وصندوق رمل لتطبيقات الويب الضعيفة. توفر بيئة مختبر داخل حاويات مصممة لممارسة اختبار الاختراق وتحديد عيوب الأمان الشائعة. يعمل المشروع كمختبر ممارسة لـ OWASP Top 10، ويقدم مجموعة محاكاة للمخاطر الحرجة. يتضمن سيناريوهات محددة لممارسة استغلال حقن SQL، والبرمجة عبر المواقع (XSS)، وتنفيذ الكود عن بُعد، وكسر التحكم في الوصول. تغطي البيئة مجموعة واسعة من محاكيات اختبار الأمان، بما في ذلك اجتياز الأدلة، وتزوير الطلبات من جانب الخادم (SSRF)، وتحميل الملفات غير الآمن، وهجمات الكيانات الخارجية XML (XXE). كما تتميز بواجهة خلفية إدارية لإدارة محاكيات التصيد الاحتيالي ومراقبة حمولات الجلسات الملتقطة. يتم نشر المنصة بأكملها عبر صورة داخل حاوية تقوم تلقائياً بتهيئة مخطط قاعدة البيانات وملء البيئة ببيانات أولية.

    Implements a simulation to practice server-side request forgery attacks.

    PHPweb
    عرض على GitHub↗4,421
  • swisskyrepo/ssrfmapالصورة الرمزية لـ swisskyrepo

    swisskyrepo/SSRFmap

    3,571عرض على GitHub↗

    Automatic SSRF fuzzer and exploitation tool

    Automated fuzzer and exploitation tool for SSRF.

    Python
    عرض على GitHub↗3,571
  • tarunkant/gopherusالصورة الرمزية لـ tarunkant

    tarunkant/Gopherus

    3,386عرض على GitHub↗

    This tool generates gopher link for exploiting SSRF and gaining RCE in various servers

    Generates gopher links to exploit SSRF for RCE.

    Python
    عرض على GitHub↗3,386
  • voorivex/pentest-guideالصورة الرمزية لـ Voorivex

    Voorivex/pentest-guide

    2,761عرض على GitHub↗

    This project is a comprehensive web application penetration testing guide and vulnerability research framework. It provides a structured methodology for identifying and exploiting security flaws through a phased approach involving reconnaissance, analysis, and exploitation. The resource is distinguished by its use of a curated methodology framework that links theoretical vulnerability patterns to real-world bug bounty reports and historical exploit examples. It includes a payload-based testing library and a reference system that maps specific vulnerability categories to recommended third-part

    Features a curated reference system and payloads for identifying server-side request forgery.

    bugbountybypassowasp-tests
    عرض على GitHub↗2,761
  • nccgroup/singularityالصورة الرمزية لـ nccgroup

    nccgroup/singularity

    1,301عرض على GitHub↗

    A DNS rebinding attack framework.

    Framework for executing DNS rebinding attacks.

    JavaScript
    عرض على GitHub↗1,301
  • micha3lb3n/ssrfireالصورة الرمزية لـ micha3lb3n

    micha3lb3n/SSRFire

    971عرض على GitHub↗

    An automated SSRF finder. Just give the domain name and your server and chill! ;) Also has options to find XSS and open redirects

    Automated SSRF finder with XSS and redirect support.

    Shell
    عرض على GitHub↗971
  • assetnote/surfالصورة الرمزية لـ assetnote

    assetnote/surf

    755عرض على GitHub↗

    Escalate your SSRF vulnerabilities on Modern Cloud Environments. surf allows you to filter a list of hosts, returning a list of viable SSRF candidates.

    Filters hosts to identify viable SSRF candidates in cloud environments.

    Go
    عرض على GitHub↗755
  • taviso/rbndrالصورة الرمزية لـ taviso

    taviso/rbndr

    750عرض على GitHub↗

    Simple DNS Rebinding Service

    Simple service for DNS rebinding.

    C
    عرض على GitHub↗750
  • brannondorsey/whonowالصورة الرمزية لـ brannondorsey

    brannondorsey/whonow

    661عرض على GitHub↗

    A "malicious" DNS server for executing DNS Rebinding attacks on the fly (public instance running on rebind.network:53)

    Malicious DNS server for executing DNS rebinding.

    JavaScript
    عرض على GitHub↗661
  • jobertabma/ground-controlالصورة الرمزية لـ jobertabma

    jobertabma/ground-control

    549عرض على GitHub↗

    A collection of scripts that run on my web server. Mainly for debugging SSRF, blind XSS, and XXE vulnerabilities.

    Scripts for debugging SSRF, blind XSS, and XXE.

    Ruby
    عرض على GitHub↗549
  • brannondorsey/dns-rebind-toolkitالصورة الرمزية لـ brannondorsey

    brannondorsey/dns-rebind-toolkit

    501عرض على GitHub↗

    A front-end JavaScript toolkit for creating DNS rebinding attacks.

    Frontend toolkit for creating DNS rebinding attacks.

    JavaScript
    عرض على GitHub↗501
  • fsecurelabs/drefالصورة الرمزية لـ FSecureLABS

    FSecureLABS/dref

    493عرض على GitHub↗

    DNS Rebinding Exploitation Framework

    Framework for DNS rebinding exploitation.

    JavaScript
    عرض على GitHub↗493
  • spidermate/b-xssrfالصورة الرمزية لـ SpiderMate

    SpiderMate/B-XSSRF

    343عرض على GitHub↗

    Toolkit to detect and keep track on Blind XSS, XXE & SSRF

    Toolkit for tracking blind XSS, XXE, and SSRF.

    PHP
    عرض على GitHub↗343
  • teknogeek/ssrf-sheriffالصورة الرمزية لـ teknogeek

    teknogeek/ssrf-sheriff

    338عرض على GitHub↗

    A simple SSRF-testing sheriff written in Go

    Go-based tool for testing SSRF vulnerabilities.

    Go
    عرض على GitHub↗338
  • daeken/httprebindالصورة الرمزية لـ daeken

    daeken/httprebind

    306عرض على GitHub↗

    Automatic tool for DNS rebinding-based SSRF attacks

    Automates DNS rebinding-based SSRF attacks.

    Python
    عرض على GitHub↗306
  • knassar702/lorsrfالصورة الرمزية لـ knassar702

    knassar702/lorsrf

    296عرض على GitHub↗

    Fast CLI tool to find the parameters that can be used to find SSRF or Out-of-band resource load :artificial_satellite: :crab:

    Brute-forces hidden parameters to find SSRF vulnerabilities.

    Rust
    عرض على GitHub↗296
  • damian89/extended-ssrf-searchالصورة الرمزية لـ Damian89

    Damian89/extended-ssrf-search

    277عرض على GitHub↗

    Smart ssrf scanner using different methods like parameter brute forcing in post and get...

    Smart SSRF scanner using parameter brute-forcing.

    Python
    عرض على GitHub↗277
  • makuga01/dnsfookupالصورة الرمزية لـ makuga01

    makuga01/dnsFookup

    255عرض على GitHub↗

    DNS rebinding toolkit

    Toolkit for DNS rebinding attacks.

    JavaScript
    عرض على GitHub↗255
  • kathanp19/gaussrfالصورة الرمزية لـ KathanP19

    KathanP19/gaussrf

    175عرض على GitHub↗

    Fetch known URLs from AlienVault's Open Threat Exchange, the Wayback Machine, and Common Crawl and Filter Urls With OpenRedirection or SSRF Parameters.

    Fetches and filters URLs for SSRF and open redirect testing.

    Shell
    عرض على GitHub↗175
السابق12التالي
  1. Home
  2. Part of an Awesome List
  3. Security & Privacy
  4. Server Side Request Forgery

استكشف الوسوم الفرعية

  • Vulnerability SimulationsIntentional security flaws integrated into software for training and testing purposes. **Distinct from Server Side Request Forgery:** Focuses on providing a vulnerable target for practice rather than a tool for detection.