awesome-repositories.com
Blog
MCP
awesome-repositories.com

Discover the best open-source repositories with AI-powered search.

ExploreCurated searchesOpen-source alternativesSelf-hosted softwareBlogSitemap
ProjectAboutHow we rankPressMCP server
LegalPrivacyTerms
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
·
Back to assetnote/surf

Open-source alternatives to Surf

25 open-source projects similar to assetnote/surf, ranked by how many features they have in common. Compare stars, activity and what each one does to find the best Surf alternative.

  • brannondorsey/dns-rebind-toolkitbrannondorsey avatar

    brannondorsey/dns-rebind-toolkit

    501View on GitHub↗

    A front-end JavaScript toolkit for creating DNS rebinding attacks.

    JavaScript
    View on GitHub↗501
  • nccgroup/singularitynccgroup avatar

    nccgroup/singularity

    1,301View on GitHub↗

    A DNS rebinding attack framework.

    JavaScript
    View on GitHub↗1,301
  • daffainfo/allaboutbugbountydaffainfo avatar

    daffainfo/AllAboutBugBounty

    6,644View on GitHub↗

    AllAboutBugBounty is a curated collection of bug bounty techniques and payloads for web application security testing. It serves as a reference resource covering common web vulnerabilities and exploitation methods for security researchers, providing a structured approach to identifying and exploiting web application security flaws in bug bounty programs. The repository covers a wide range of attack categories including authentication bypass, cross-site scripting injection, server-side request forgery, web cache poisoning, and business logic abuse. It includes techniques for bypassing access co

    bugbugbountybugbountytips
    View on GitHub↗6,644
  • voorivex/pentest-guideVoorivex avatar

    Voorivex/pentest-guide

    2,761View on GitHub↗

    This project is a comprehensive web application penetration testing guide and vulnerability research framework. It provides a structured methodology for identifying and exploiting security flaws through a phased approach involving reconnaissance, analysis, and exploitation. The resource is distinguished by its use of a curated methodology framework that links theoretical vulnerability patterns to real-world bug bounty reports and historical exploit examples. It includes a payload-based testing library and a reference system that maps specific vulnerability categories to recommended third-part

    bugbountybypassowasp-tests
    View on GitHub↗2,761

AI search

Explore more awesome repositories

Describe what you need in plain English — the AI ranks thousands of curated open-source projects by relevance.

Find more with AI search
  • firefart/stunnerfirefart avatar

    firefart/stunner

    852View on GitHub↗

    Stunner is a tool to test and exploit STUN, TURN and TURN over TCP servers. TURN is a protocol mostly used in videoconferencing and audio chats (WebRTC).

    Go
    View on GitHub↗852
  • fsecurelabs/drefFSecureLABS avatar

    FSecureLABS/dref

    493View on GitHub↗

    DNS Rebinding Exploitation Framework

    JavaScript
    View on GitHub↗493
  • jacobreynolds/ssrfdetectorJacobReynolds avatar

    JacobReynolds/ssrfDetector

    165View on GitHub↗

    Server-side request forgery detector

    JavaScript
    View on GitHub↗165
  • jobertabma/ground-controljobertabma avatar

    jobertabma/ground-control

    549View on GitHub↗

    A collection of scripts that run on my web server. Mainly for debugging SSRF, blind XSS, and XXE vulnerabilities.

    Ruby
    View on GitHub↗549
  • kathanp19/gaussrfKathanP19 avatar

    KathanP19/gaussrf

    175View on GitHub↗

    Fetch known URLs from AlienVault's Open Threat Exchange, the Wayback Machine, and Common Crawl and Filter Urls With OpenRedirection or SSRF Parameters.

    Shell
    View on GitHub↗175
  • knassar702/lorsrfknassar702 avatar

    knassar702/lorsrf

    296View on GitHub↗

    Fast CLI tool to find the parameters that can be used to find SSRF or Out-of-band resource load :artificial_satellite: :crab:

    Rust
    View on GitHub↗296
  • makuga01/dnsfookupmakuga01 avatar

    makuga01/dnsFookup

    255View on GitHub↗

    DNS rebinding toolkit

    JavaScript
    View on GitHub↗255
  • micha3lb3n/ssrfiremicha3lb3n avatar

    micha3lb3n/SSRFire

    971View on GitHub↗

    An automated SSRF finder. Just give the domain name and your server and chill! ;) Also has options to find XSS and open redirects

    Shell
    View on GitHub↗971
  • nxenon/h3spacexN

    nxenon/h3spacex

    0View on GitHub↗
    View on GitHub↗0
  • randomrobbiebf/grafana-ssrfRandomRobbieBF avatar

    RandomRobbieBF/grafana-ssrf

    83View on GitHub↗

    Authenticated SSRF in Grafana

    Python
    View on GitHub↗83
  • spidermate/b-xssrfSpiderMate avatar

    SpiderMate/B-XSSRF

    343View on GitHub↗

    Toolkit to detect and keep track on Blind XSS, XXE & SSRF

    PHP
    View on GitHub↗343
  • stealthcopter/deepcestealthcopter avatar

    stealthcopter/deepce

    1,530View on GitHub↗

    Docker Enumeration, Escalation of Privileges and Container Escapes (DEEPCE)

    Shellcontainer-escapedeepcedocker-enumeration
    View on GitHub↗1,530
  • swisskyrepo/ssrfmapswisskyrepo avatar

    swisskyrepo/SSRFmap

    3,571View on GitHub↗

    Automatic SSRF fuzzer and exploitation tool

    Python
    View on GitHub↗3,571
  • tarunkant/gopherustarunkant avatar

    tarunkant/Gopherus

    3,386View on GitHub↗

    This tool generates gopher link for exploiting SSRF and gaining RCE in various servers

    Python
    View on GitHub↗3,386
  • taviso/rbndrtaviso avatar

    taviso/rbndr

    750View on GitHub↗

    Simple DNS Rebinding Service

    C
    View on GitHub↗750
  • teknogeek/ssrf-sheriffteknogeek avatar

    teknogeek/ssrf-sheriff

    338View on GitHub↗

    A simple SSRF-testing sheriff written in Go

    Go
    View on GitHub↗338
  • arthaud/git-dumperarthaud avatar

    arthaud/git-dumper

    2,553View on GitHub↗
    Pythongitsecurityweb
    View on GitHub↗2,553
  • xawdxawdx/sentryssrfxawdxawdx avatar

    xawdxawdx/sentrySSRF

    72View on GitHub↗

    Tool to searching sentry config on page or in javascript files and check blind SSRF

    Python
    View on GitHub↗72
  • brannondorsey/whonowbrannondorsey avatar

    brannondorsey/whonow

    661View on GitHub↗

    A "malicious" DNS server for executing DNS Rebinding attacks on the fly (public instance running on rebind.network:53)

    JavaScript
    View on GitHub↗661
  • daeken/httprebinddaeken avatar

    daeken/httprebind

    306View on GitHub↗

    Automatic tool for DNS rebinding-based SSRF attacks

    Python
    View on GitHub↗306
  • damian89/extended-ssrf-searchDamian89 avatar

    Damian89/extended-ssrf-search

    277View on GitHub↗

    Smart ssrf scanner using different methods like parameter brute forcing in post and get...

    Python
    View on GitHub↗277