surf

Host scanner

A tool that identifies and filters potential Server-Side Request Forgery (SSRF) vulnerabilities in cloud environments by probing external hosts.

Escalate your SSRF vulnerabilities on Modern Cloud Environments. surf allows you to filter a list of hosts, returning a list of viable SSRF candidates.

GitHub

599 stars
8 watching
42 forks
Language: Go
last commit: almost 3 years ago
Linked from 1 awesome list


Backlinks from these awesome lists:

Related projects:

RepositoryDescriptionStars
kathanp19/gaussrfA tool for identifying potential vulnerabilities in websites by fetching known URLs and filtering out ones with open redirects or SSRF parameters.168
emo-crab/observer_wardA tool for identifying vulnerabilities in web applications and services by analyzing patterns of web servers and services1,295
serain/mailspoofA tool to analyze and report on SPF and DMARC record issues for potential email spoofing vulnerabilities.128
ksharinarayanan/ssrfireAn automated tool to discover potential Server-Side Request Forgery (SSRF) vulnerabilities in web applications by scanning the domain for open redirects and testing for cross-site scripting (XSS)953
mindpatch/lorsrfA tool designed to identify parameters in web applications that can be exploited for SSRF or out-of-band resource load attacks.291
whwlsfb/log4j2scanA tool that scans websites for Log4j2 remote code execution vulnerabilities using multiple DNS log platforms and supports various scan types776
spidermate/b-xssrfA toolkit to detect and track vulnerabilities in web applications295
damian89/extended-ssrf-searchAn SSRF scanner written in Python to identify potential vulnerabilities by scanning predefined settings in URLs and request headers.276
moduscreateorg/beepAn account security scanner that detects vulnerabilities in online accounts by hashing credentials and checking against data breaches.157
codingo/vhostscanA tool for discovering and scanning virtual hosts to identify potential vulnerabilities1,208
maxcountryman/flask-seasurfAn extension that helps protect against cross-site request forgery attacks in web applications190
codingo/reconnoitreAutomates reconnaissance and service enumeration of network hosts to gather information and write recommendations for further testing.2,124
r0075h3ll/oralyzerA tool to identify vulnerabilities in web applications by probing for Open Redirections and other types of attacks.758
secdec/attack-surface-detector-burpIdentifies web app endpoints and parameters to help detect vulnerabilities98
osamahamad/cve-2020-9484-mass-scanA tool designed to scan a list of URLs against Apache Tomcat deserialization vulnerabilities that could lead to Remote Code Execution.32