awesome-repositories.com
Blog
MCP
awesome-repositories.com

Discover the best open-source repositories with AI-powered search.

ExploreCurated searchesOpen-source alternativesSelf-hosted softwareBlogSitemap
ProjectAboutHow we rankPressMCP server
LegalPrivacyTerms
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
·
assetnote avatar

assetnote/surf

0
View on GitHub↗
755 stars·56 forks·Go·2 views

Surf

Escalate your SSRF vulnerabilities on Modern Cloud Environments. surf allows you to filter a list of hosts, returning a list of viable SSRF candidates.

Features

  • Server Side Request Forgery - Filters hosts to identify viable SSRF candidates in cloud environments.
  • Specialized Web Attacks - Filtering hosts to identify viable SSRF candidates.

Star history

Star history chart for assetnote/surfStar history chart for assetnote/surf

AI search

Explore more awesome repositories

Describe what you need in plain English — the AI ranks thousands of curated open-source projects by relevance.

Start searching with AI

Open-source alternatives to Surf

Similar open-source projects, ranked by how many features they share with Surf.
  • brannondorsey/dns-rebind-toolkitbrannondorsey avatar

    brannondorsey/dns-rebind-toolkit

    501View on GitHub↗

    A front-end JavaScript toolkit for creating DNS rebinding attacks.

    JavaScript
    View on GitHub↗501
  • nccgroup/singularitynccgroup avatar

    nccgroup/singularity

    1,301View on GitHub↗

    A DNS rebinding attack framework.

    JavaScript
    View on GitHub↗1,301
  • daffainfo/allaboutbugbountydaffainfo avatar

    daffainfo/AllAboutBugBounty

    6,644View on GitHub↗

    AllAboutBugBounty is a curated collection of bug bounty techniques and payloads for web application security testing. It serves as a reference resource covering common web vulnerabilities and exploitation methods for security researchers, providing a structured approach to identifying and exploiting web application security flaws in bug bounty programs. The repository covers a wide range of attack categories including authentication bypass, cross-site scripting injection, server-side request forgery, web cache poisoning, and business logic abuse. It includes techniques for bypassing access co

    bugbugbountybugbountytips
    View on GitHub↗6,644
  • voorivex/pentest-guideVoorivex avatar

    Voorivex/pentest-guide

    2,761View on GitHub↗

    This project is a comprehensive web application penetration testing guide and vulnerability research framework. It provides a structured methodology for identifying and exploiting security flaws through a phased approach involving reconnaissance, analysis, and exploitation. The resource is distinguished by its use of a curated methodology framework that links theoretical vulnerability patterns to real-world bug bounty reports and historical exploit examples. It includes a payload-based testing library and a reference system that maps specific vulnerability categories to recommended third-part

    bugbountybypassowasp-tests
    View on GitHub↗2,761
See all 25 alternatives to Surf→

Frequently asked questions

What does assetnote/surf do?

Escalate your SSRF vulnerabilities on Modern Cloud Environments. surf allows you to filter a list of hosts, returning a list of viable SSRF candidates.

What are the main features of assetnote/surf?

The main features of assetnote/surf are: Server Side Request Forgery, Specialized Web Attacks.

What are some open-source alternatives to assetnote/surf?

Open-source alternatives to assetnote/surf include: nccgroup/singularity — A DNS rebinding attack framework. brannondorsey/dns-rebind-toolkit — A front-end JavaScript toolkit for creating DNS rebinding attacks. voorivex/pentest-guide — This project is a comprehensive web application penetration testing guide and vulnerability research framework. It… daffainfo/allaboutbugbounty — AllAboutBugBounty is a curated collection of bug bounty techniques and payloads for web application security testing.… damian89/extended-ssrf-search — Smart ssrf scanner using different methods like parameter brute forcing in post and get... brannondorsey/whonow — A "malicious" DNS server for executing DNS Rebinding attacks on the fly (public instance running on rebind.network:53).