awesome-repositories.com
博客
MCP
awesome-repositories.com

通过 AI 驱动的搜索,发现最优秀的开源仓库。

探索精选搜索开源替代品自托管软件博客网站地图
项目MCP 服务器关于排名机制媒体报道
法律隐私政策服务条款
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
·

23 个仓库

Awesome GitHub RepositoriesServer Side Request Forgery

Tools for detecting and exploiting SSRF and DNS rebinding.

Explore 23 awesome GitHub repositories matching part of an awesome list · Server Side Request Forgery. Refine with filters or upvote what's useful.

Awesome Server Side Request Forgery GitHub Repositories

用 AI 发现最棒的仓库。我们将通过 AI 为您搜索最匹配的仓库。
  • daffainfo/allaboutbugbountydaffainfo 的头像

    daffainfo/AllAboutBugBounty

    6,644在 GitHub 上查看↗

    AllAboutBugBounty is a curated collection of bug bounty techniques and payloads for web application security testing. It serves as a reference resource covering common web vulnerabilities and exploitation methods for security researchers, providing a structured approach to identifying and exploiting web application security flaws in bug bounty programs. The repository covers a wide range of attack categories including authentication bypass, cross-site scripting injection, server-side request forgery, web cache poisoning, and business logic abuse. It includes techniques for bypassing access co

    Covers forging server-side requests to bypass firewalls and access internal services.

    bugbugbountybugbountytips
    在 GitHub 上查看↗6,644
  • zhuifengshaonianhanlu/pikachuzhuifengshaonianhanlu 的头像

    zhuifengshaonianhanlu/pikachu

    4,421在 GitHub 上查看↗

    Pikachu 是一个 Web 安全培训平台和易受攻击的 Web 应用沙盒。它提供了一个容器化的实验环境,旨在练习渗透测试和识别常见的安全漏洞。 该项目作为 OWASP Top 10 练习实验室,提供了一套针对关键风险的模拟套件。它包括用于练习 SQL 注入、跨站脚本 (XSS)、远程代码执行和失效的访问控制等漏洞利用的具体场景。 该环境涵盖了广泛的安全测试模拟,包括目录遍历、服务端请求伪造 (SSRF)、不安全的文件上传和 XML 外部实体 (XXE) 攻击。它还具有一个管理后台,用于管理钓鱼模拟并监控捕获的会话负载。 整个平台通过容器化镜像部署,该镜像会自动初始化数据库模式并使用种子数据填充环境。

    Implements a simulation to practice server-side request forgery attacks.

    PHPweb
    在 GitHub 上查看↗4,421
  • swisskyrepo/ssrfmapswisskyrepo 的头像

    swisskyrepo/SSRFmap

    3,571在 GitHub 上查看↗

    Automatic SSRF fuzzer and exploitation tool

    Automated fuzzer and exploitation tool for SSRF.

    Python
    在 GitHub 上查看↗3,571
  • tarunkant/gopherustarunkant 的头像

    tarunkant/Gopherus

    3,386在 GitHub 上查看↗

    This tool generates gopher link for exploiting SSRF and gaining RCE in various servers

    Generates gopher links to exploit SSRF for RCE.

    Python
    在 GitHub 上查看↗3,386
  • voorivex/pentest-guideVoorivex 的头像

    Voorivex/pentest-guide

    2,761在 GitHub 上查看↗

    This project is a comprehensive web application penetration testing guide and vulnerability research framework. It provides a structured methodology for identifying and exploiting security flaws through a phased approach involving reconnaissance, analysis, and exploitation. The resource is distinguished by its use of a curated methodology framework that links theoretical vulnerability patterns to real-world bug bounty reports and historical exploit examples. It includes a payload-based testing library and a reference system that maps specific vulnerability categories to recommended third-part

    Features a curated reference system and payloads for identifying server-side request forgery.

    bugbountybypassowasp-tests
    在 GitHub 上查看↗2,761
  • nccgroup/singularitynccgroup 的头像

    nccgroup/singularity

    1,301在 GitHub 上查看↗

    A DNS rebinding attack framework.

    Framework for executing DNS rebinding attacks.

    JavaScript
    在 GitHub 上查看↗1,301
  • micha3lb3n/ssrfiremicha3lb3n 的头像

    micha3lb3n/SSRFire

    971在 GitHub 上查看↗

    An automated SSRF finder. Just give the domain name and your server and chill! ;) Also has options to find XSS and open redirects

    Automated SSRF finder with XSS and redirect support.

    Shell
    在 GitHub 上查看↗971
  • assetnote/surfassetnote 的头像

    assetnote/surf

    755在 GitHub 上查看↗

    Escalate your SSRF vulnerabilities on Modern Cloud Environments. surf allows you to filter a list of hosts, returning a list of viable SSRF candidates.

    Filters hosts to identify viable SSRF candidates in cloud environments.

    Go
    在 GitHub 上查看↗755
  • taviso/rbndrtaviso 的头像

    taviso/rbndr

    750在 GitHub 上查看↗

    Simple DNS Rebinding Service

    Simple service for DNS rebinding.

    C
    在 GitHub 上查看↗750
  • brannondorsey/whonowbrannondorsey 的头像

    brannondorsey/whonow

    661在 GitHub 上查看↗

    A "malicious" DNS server for executing DNS Rebinding attacks on the fly (public instance running on rebind.network:53)

    Malicious DNS server for executing DNS rebinding.

    JavaScript
    在 GitHub 上查看↗661
  • jobertabma/ground-controljobertabma 的头像

    jobertabma/ground-control

    549在 GitHub 上查看↗

    A collection of scripts that run on my web server. Mainly for debugging SSRF, blind XSS, and XXE vulnerabilities.

    Scripts for debugging SSRF, blind XSS, and XXE.

    Ruby
    在 GitHub 上查看↗549
  • brannondorsey/dns-rebind-toolkitbrannondorsey 的头像

    brannondorsey/dns-rebind-toolkit

    501在 GitHub 上查看↗

    A front-end JavaScript toolkit for creating DNS rebinding attacks.

    Frontend toolkit for creating DNS rebinding attacks.

    JavaScript
    在 GitHub 上查看↗501
  • fsecurelabs/drefFSecureLABS 的头像

    FSecureLABS/dref

    493在 GitHub 上查看↗

    DNS Rebinding Exploitation Framework

    Framework for DNS rebinding exploitation.

    JavaScript
    在 GitHub 上查看↗493
  • spidermate/b-xssrfSpiderMate 的头像

    SpiderMate/B-XSSRF

    343在 GitHub 上查看↗

    Toolkit to detect and keep track on Blind XSS, XXE & SSRF

    Toolkit for tracking blind XSS, XXE, and SSRF.

    PHP
    在 GitHub 上查看↗343
  • teknogeek/ssrf-sheriffteknogeek 的头像

    teknogeek/ssrf-sheriff

    338在 GitHub 上查看↗

    A simple SSRF-testing sheriff written in Go

    Go-based tool for testing SSRF vulnerabilities.

    Go
    在 GitHub 上查看↗338
  • daeken/httprebinddaeken 的头像

    daeken/httprebind

    306在 GitHub 上查看↗

    Automatic tool for DNS rebinding-based SSRF attacks

    Automates DNS rebinding-based SSRF attacks.

    Python
    在 GitHub 上查看↗306
  • knassar702/lorsrfknassar702 的头像

    knassar702/lorsrf

    296在 GitHub 上查看↗

    Fast CLI tool to find the parameters that can be used to find SSRF or Out-of-band resource load :artificial_satellite: :crab:

    Brute-forces hidden parameters to find SSRF vulnerabilities.

    Rust
    在 GitHub 上查看↗296
  • damian89/extended-ssrf-searchDamian89 的头像

    Damian89/extended-ssrf-search

    277在 GitHub 上查看↗

    Smart ssrf scanner using different methods like parameter brute forcing in post and get...

    Smart SSRF scanner using parameter brute-forcing.

    Python
    在 GitHub 上查看↗277
  • makuga01/dnsfookupmakuga01 的头像

    makuga01/dnsFookup

    255在 GitHub 上查看↗

    DNS rebinding toolkit

    Toolkit for DNS rebinding attacks.

    JavaScript
    在 GitHub 上查看↗255
  • kathanp19/gaussrfKathanP19 的头像

    KathanP19/gaussrf

    175在 GitHub 上查看↗

    Fetch known URLs from AlienVault's Open Threat Exchange, the Wayback Machine, and Common Crawl and Filter Urls With OpenRedirection or SSRF Parameters.

    Fetches and filters URLs for SSRF and open redirect testing.

    Shell
    在 GitHub 上查看↗175
上一个12下一个
  1. Home
  2. Part of an Awesome List
  3. Security & Privacy
  4. Server Side Request Forgery

探索子标签

  • Vulnerability SimulationsIntentional security flaws integrated into software for training and testing purposes. **Distinct from Server Side Request Forgery:** Focuses on providing a vulnerable target for practice rather than a tool for detection.