awesome-repositories.com
Blog
MCP
awesome-repositories.com

Découvrez les meilleurs dépôts open-source grâce à notre recherche par IA.

ExplorerRecherches sélectionnéesAlternatives open sourceLogiciels auto-hébergésBlogPlan du site
ProjetÀ proposNotre méthodologiePresseServeur MCP
Mentions légalesConfidentialitéConditions d'utilisation
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
·
Back to cujanovic/ssrf-testing

Open-source alternatives to SSRF Testing

29 open-source projects similar to cujanovic/ssrf-testing, ranked by how many features they have in common. Compare stars, activity and what each one does to find the best SSRF Testing alternative.

  • andresriancho/w3afAvatar de andresriancho

    andresriancho/w3af

    4,850Voir sur GitHub↗

    w3af is a web penetration testing suite and security audit framework designed to identify and exploit vulnerabilities in web applications. It functions as a vulnerability scanner that crawls targets to find injection points and a fuzzer used to discover hidden endpoints and test input validation. The project distinguishes itself by providing an intercepting HTTP proxy for capturing and modifying traffic, combined with a knowledge-base driven exploitation system. It enables the execution of security exploits to gain remote shell access and supports post-exploitation activities, such as routing

    Pythonappseccross-site-scriptingscanner
    Voir sur GitHub↗4,850
  • manisso/fsocietyAvatar de Manisso

    Manisso/fsociety

    12,136Voir sur GitHub↗

    fsociety is a penetration testing framework and security tool orchestrator designed to conduct full security audits. It functions as a wrapper that integrates external security binaries into a unified, menu-driven interface, providing a centralized system for command-line parameter mapping and execution. The project distinguishes itself by organizing specialized utilities into domain-specific collections for structured navigation. It automates the transition between different phases of an audit by chaining reconnaissance and exploitation tools through sequential workflow automation. The fram

    Pythonbrute-force-attacksdesktopexploitation
    Voir sur GitHub↗12,136
  • ambionics/phpggcAvatar de ambionics

    ambionics/phpggc

    3,832Voir sur GitHub↗

    phpggc is a security assessment utility and command-line tool designed for the automated generation, obfuscation, and wrapping of serialized object chains. It functions as a gadget chain framework used to identify and verify remote code execution vectors by testing for PHP object injection vulnerabilities. The project provides a modular system for constructing complex serialized object sequences and includes a dedicated payload obfuscator to transform byte streams for bypassing web application firewalls and security filters. It also features a generator for wrapping serialized data into archi

    PHP
    Voir sur GitHub↗3,832

Recherche par IA

Explorez plus de dépôts awesome

Décrivez vos besoins en langage naturel — l'IA classe des milliers de projets open source sélectionnés par pertinence.

Find more with AI search
  • enjoiz/xxeinjectorAvatar de enjoiz

    enjoiz/XXEinjector

    1,754Voir sur GitHub↗

    Tool for automatic exploitation of XXE vulnerability using direct and different out of band methods.

    Ruby
    Voir sur GitHub↗1,754
  • epinna/tplmapAvatar de epinna

    epinna/tplmap

    4,169Voir sur GitHub↗

    tplmap is a security tool designed for the detection and exploitation of server-side template injection vulnerabilities. It functions as an automated scanner to identify vulnerable template engine contexts and provides a framework for achieving remote code execution. The tool focuses on translating high-level requests into engine-specific syntax to execute operating system commands and bypass application sandboxes. It further enables remote file system access, allowing users to read, write, and transfer files between a local machine and a target server. Additional capabilities include the ab

    Python
    Voir sur GitHub↗4,169
  • espreto/wpsploitAvatar de espreto

    espreto/wpsploit

    233Voir sur GitHub↗

    WPSploit - Exploiting Wordpress With Metasploit

    Ruby
    Voir sur GitHub↗233
  • evyatarmeged/raccoonAvatar de evyatarmeged

    evyatarmeged/Raccoon

    3,571Voir sur GitHub↗

    A high performance offensive security tool for reconnaissance and vulnerability scanning

    Python
    Voir sur GitHub↗3,571
  • flipkart-incubator/astraAvatar de flipkart-incubator

    flipkart-incubator/Astra

    2,639Voir sur GitHub↗

    Astra is a security analysis system and scanner designed to identify vulnerabilities and security flaws in REST API endpoints. It functions as a security testing tool that automatically detects common API weaknesses during development and deployment cycles. The project provides a graphical interface for triggering and monitoring security scanning processes, removing the requirement for manual command line execution. This management UI allows for the oversight of scanning workflows and the retrieval of vulnerability reports. The system supports the import of collection files to map endpoints

    Pythonci-cdowasppenetration-testing
    Voir sur GitHub↗2,639
  • flozz/p0wny-shellAvatar de flozz

    flozz/p0wny-shell

    2,825Voir sur GitHub↗

    p0wny@shell:~# is a very basic, single-file, PHP shell. It can be used to quickly execute commands on a server when pentesting a PHP application. Use it with caution: this script represents a security risk for the server.

    PHP
    Voir sur GitHub↗2,825
  • frohoff/ysoserialAvatar de frohoff

    frohoff/ysoserial

    8,750Voir sur GitHub↗

    ysoserial is a security research tool and payload generator designed to identify and exploit insecure Java deserialization. It functions as a framework for creating malicious serialized objects that can trigger remote code execution on Java virtual machines. The project provides a library of known gadget chains, which are sequences of vulnerable class calls that achieve arbitrary command execution during the deserialization process. It automates the generation of these payloads by leveraging common third-party libraries. The tool covers capabilities for security penetration testing, Java app

    Javadeserializationexploitgadget
    Voir sur GitHub↗8,750
  • fuzzdb-project/fuzzdbAvatar de fuzzdb-project

    fuzzdb-project/fuzzdb

    8,819Voir sur GitHub↗

    fuzzdb is a collection of datasets designed for web application penetration testing and dynamic fuzzing. It provides a fuzzing payload dictionary, a resource discovery wordlist, and a fault injection dataset containing corrupted Unicode, null bytes, and escape codes to trigger application crashes and logic errors. The project includes a security filter bypass list featuring polyglots and encoded strings to evade web application firewalls and input validation filters. It also provides a comprehensive web application penetration testing dataset specifically for identifying flaws such as cross-s

    PHP
    Voir sur GitHub↗8,819
  • illuminopi/rcevil.netI

    Illuminopi/RCEvil.NET

    0Voir sur GitHub↗
    Voir sur GitHub↗0
  • imperva/automatic-api-attack-toolAvatar de imperva

    imperva/automatic-api-attack-tool

    495Voir sur GitHub↗

    Imperva's customizable API attack tool takes an API specification as an input, generates and runs attacks that are based on it as an output.

    Java
    Voir sur GitHub↗495
  • internetwache/gittoolsAvatar de internetwache

    internetwache/GitTools

    4,151Voir sur GitHub↗

    GitTools is a collection of security utilities designed to identify, scan, and exploit exposed version control directories on web servers. The project provides tools to locate publicly accessible Git directories and extract their contents to identify information leaks. The suite includes capabilities for downloading files and folder structures from remote repositories even when directory listing is disabled. It also features a recovery system that iterates through commit objects to restore content from incomplete or corrupted version control data.

    Shell
    Voir sur GitHub↗4,151
  • irsdl/iis-shortname-scannerAvatar de irsdl

    irsdl/IIS-ShortName-Scanner

    1,679Voir sur GitHub↗

    IIS Short Name Scanner - 2012-2023 & Still Giving...

    Java
    Voir sur GitHub↗1,679
  • kpcyrd/authoscopeAvatar de kpcyrd

    kpcyrd/authoscope

    418Voir sur GitHub↗

    Scriptable network authentication cracker

    Rust
    Voir sur GitHub↗418
  • leonardonve/sslstrip2Avatar de LeonardoNve

    LeonardoNve/sslstrip2

    325Voir sur GitHub↗

    SSLStrip version to defeat HSTS

    Voir sur GitHub↗325
  • liamg/gitjackerAvatar de liamg

    liamg/gitjacker

    1,607Voir sur GitHub↗

    🔪 :octocat: Leak git repositories from misconfigured websites

    Gogithackingpenetration-testing
    Voir sur GitHub↗1,607
  • luemmelsec/saml2sprayL

    LuemmelSec/SAML2Spray

    0Voir sur GitHub↗
    Voir sur GitHub↗0
  • microsoft/restler-fuzzerAvatar de microsoft

    microsoft/restler-fuzzer

    2,915Voir sur GitHub↗

    RESTler is the first stateful REST API fuzzing tool for automatically testing cloud services through their REST APIs and finding security and reliability bugs in these services.

    Python
    Voir sur GitHub↗2,915
  • nccgroup/freddyN

    nccgroup/freddy

    0Voir sur GitHub↗
    Voir sur GitHub↗0
  • oj/gobusterAvatar de OJ

    OJ/gobuster

    13,429Voir sur GitHub↗

    Gobuster is a command-line security utility designed for brute-force discovery of hidden infrastructure and content. It operates by systematically testing wordlists against target network services to identify files, directories, subdomains, and cloud storage buckets. The tool utilizes a concurrent worker pool to execute these requests in parallel, ensuring efficient scanning across various network environments. The project distinguishes itself through a modular plugin architecture that supports multiple discovery modes, including HTTP, DNS, and TFTP. This design allows for protocol-agnostic r

    Godnsgopentesting
    Voir sur GitHub↗13,429
  • orf/xcatO

    orf/xcat

    0Voir sur GitHub↗
    Voir sur GitHub↗0
  • osandamalith/lfifreakO

    OsandaMalith/LFiFreak

    0Voir sur GitHub↗

    LFI Freak

    Voir sur GitHub↗0
  • pwntester/ysoserial.netAvatar de pwntester

    pwntester/ysoserial.net

    3,735Voir sur GitHub↗

    ysoserial.net is a payload generator for .NET deserialization, designed to create malicious serialized objects and structured gadget chains. It serves as a tool for generating command execution strings and security testing suites used to assess vulnerabilities in .NET formatters. The tool enables the creation of sequences of object calls that trigger remote code execution during the reconstruction of serialized data. It produces specialized payloads for executing system commands, loading remote libraries, and accessing local file systems. The project includes capabilities for optimizing payl

    C#
    Voir sur GitHub↗3,735
  • tennc/webshellAvatar de tennc

    tennc/webshell

    10,735Voir sur GitHub↗

    This is a webshell open source project

    PHP
    Voir sur GitHub↗10,735
  • 0xacb/viewgen0

    0xacb/viewgen

    0Voir sur GitHub↗
    Voir sur GitHub↗0
  • tijme/angularjs-csti-scannerAvatar de tijme

    tijme/angularjs-csti-scanner

    324Voir sur GitHub↗

    Automated client-side template injection (sandbox escape/bypass) detection for AngularJS v1.x.

    Python
    Voir sur GitHub↗324
  • almandin/fuxploiderA

    almandin/fuxploider

    0Voir sur GitHub↗

    fuxploider is an open source penetration testing tool that automates the process of detecting and exploiting file upload forms flaws. This tool is able to detect the file types allowed to be uploaded and is able to detect which technique will work best tu upload web shells or any malicious file…

    Voir sur GitHub↗0