23 مستودعات
Tools for detecting and exploiting SSRF and DNS rebinding.
Explore 23 awesome GitHub repositories matching part of an awesome list · Server Side Request Forgery. Refine with filters or upvote what's useful.
AllAboutBugBounty is a curated collection of bug bounty techniques and payloads for web application security testing. It serves as a reference resource covering common web vulnerabilities and exploitation methods for security researchers, providing a structured approach to identifying and exploiting web application security flaws in bug bounty programs. The repository covers a wide range of attack categories including authentication bypass, cross-site scripting injection, server-side request forgery, web cache poisoning, and business logic abuse. It includes techniques for bypassing access co
Covers forging server-side requests to bypass firewalls and access internal services.
Pikachu هي منصة تدريب على أمن الويب وصندوق رمل لتطبيقات الويب الضعيفة. توفر بيئة مختبر داخل حاويات مصممة لممارسة اختبار الاختراق وتحديد عيوب الأمان الشائعة. يعمل المشروع كمختبر ممارسة لـ OWASP Top 10، ويقدم مجموعة محاكاة للمخاطر الحرجة. يتضمن سيناريوهات محددة لممارسة استغلال حقن SQL، والبرمجة عبر المواقع (XSS)، وتنفيذ الكود عن بُعد، وكسر التحكم في الوصول. تغطي البيئة مجموعة واسعة من محاكيات اختبار الأمان، بما في ذلك اجتياز الأدلة، وتزوير الطلبات من جانب الخادم (SSRF)، وتحميل الملفات غير الآمن، وهجمات الكيانات الخارجية XML (XXE). كما تتميز بواجهة خلفية إدارية لإدارة محاكيات التصيد الاحتيالي ومراقبة حمولات الجلسات الملتقطة. يتم نشر المنصة بأكملها عبر صورة داخل حاوية تقوم تلقائياً بتهيئة مخطط قاعدة البيانات وملء البيئة ببيانات أولية.
Implements a simulation to practice server-side request forgery attacks.
Automatic SSRF fuzzer and exploitation tool
Automated fuzzer and exploitation tool for SSRF.
This tool generates gopher link for exploiting SSRF and gaining RCE in various servers
Generates gopher links to exploit SSRF for RCE.
This project is a comprehensive web application penetration testing guide and vulnerability research framework. It provides a structured methodology for identifying and exploiting security flaws through a phased approach involving reconnaissance, analysis, and exploitation. The resource is distinguished by its use of a curated methodology framework that links theoretical vulnerability patterns to real-world bug bounty reports and historical exploit examples. It includes a payload-based testing library and a reference system that maps specific vulnerability categories to recommended third-part
Features a curated reference system and payloads for identifying server-side request forgery.
A DNS rebinding attack framework.
Framework for executing DNS rebinding attacks.
An automated SSRF finder. Just give the domain name and your server and chill! ;) Also has options to find XSS and open redirects
Automated SSRF finder with XSS and redirect support.
Escalate your SSRF vulnerabilities on Modern Cloud Environments. surf allows you to filter a list of hosts, returning a list of viable SSRF candidates.
Filters hosts to identify viable SSRF candidates in cloud environments.
A "malicious" DNS server for executing DNS Rebinding attacks on the fly (public instance running on rebind.network:53)
Malicious DNS server for executing DNS rebinding.
A collection of scripts that run on my web server. Mainly for debugging SSRF, blind XSS, and XXE vulnerabilities.
Scripts for debugging SSRF, blind XSS, and XXE.
A front-end JavaScript toolkit for creating DNS rebinding attacks.
Frontend toolkit for creating DNS rebinding attacks.
DNS Rebinding Exploitation Framework
Framework for DNS rebinding exploitation.
Toolkit to detect and keep track on Blind XSS, XXE & SSRF
Toolkit for tracking blind XSS, XXE, and SSRF.
A simple SSRF-testing sheriff written in Go
Go-based tool for testing SSRF vulnerabilities.
Automatic tool for DNS rebinding-based SSRF attacks
Automates DNS rebinding-based SSRF attacks.
Fast CLI tool to find the parameters that can be used to find SSRF or Out-of-band resource load :artificial_satellite: :crab:
Brute-forces hidden parameters to find SSRF vulnerabilities.
Smart ssrf scanner using different methods like parameter brute forcing in post and get...
Smart SSRF scanner using parameter brute-forcing.
DNS rebinding toolkit
Toolkit for DNS rebinding attacks.
Fetch known URLs from AlienVault's Open Threat Exchange, the Wayback Machine, and Common Crawl and Filter Urls With OpenRedirection or SSRF Parameters.
Fetches and filters URLs for SSRF and open redirect testing.