SSRFire

SSRF scanner

An automated tool to discover potential Server-Side Request Forgery (SSRF) vulnerabilities in web applications by scanning the domain for open redirects and testing for cross-site scripting (XSS)

An automated SSRF finder. Just give the domain name and your server and chill! ;) Also has options to find XSS and open redirects

GitHub

953 stars
25 watching
161 forks
Language: Shell
last commit: almost 5 years ago
Linked from 1 awesome list


Backlinks from these awesome lists:

Related projects:

RepositoryDescriptionStars
damian89/extended-ssrf-searchAn SSRF scanner written in Python to identify potential vulnerabilities by scanning predefined settings in URLs and request headers.276
jacobreynolds/ssrfdetectorA web application that detects and warns users about potential Server-side Request Forgery (SSRF) vulnerabilities.150
kathanp19/gaussrfA tool for identifying potential vulnerabilities in websites by fetching known URLs and filtering out ones with open redirects or SSRF parameters.168
mindpatch/lorsrfA tool designed to identify parameters in web applications that can be exploited for SSRF or out-of-band resource load attacks.291
teknogeek/ssrf-sheriffA tool designed to test and simulate Server-Side Request Forgery (SSRF) vulnerabilities by generating responses with configurable secret tokens320
incredibleindishell/ssrf_vulnerable_labA laboratory repository demonstrating vulnerable PHP code examples for Server-Side Request Forgery (SSRF) attacks679
assetnote/surfA tool that identifies and filters potential Server-Side Request Forgery (SSRF) vulnerabilities in cloud environments by probing external hosts.599
randomrobbiebf/grafana-ssrfA tool to demonstrate and exploit authenticated SSRF vulnerabilities in Grafana78
spidermate/b-xssrfA toolkit to detect and track vulnerabilities in web applications295
serain/mailspoofA tool to analyze and report on SPF and DMARC record issues for potential email spoofing vulnerabilities.128
r0075h3ll/oralyzerA tool to identify vulnerabilities in web applications by probing for Open Redirections and other types of attacks.758
asaiken/dom-based-xss-finderTools for identifying and exploiting vulnerabilities in DOM-based cross-site scripting attacks.71
xawdxawdx/sentryssrfA tool to search for and exploit Sentry configuration vulnerabilities in web applications68
mandatoryprogrammer/xsshunter_clientAn instrument used to hunt and identify cross-site scripting (XSS) vulnerabilities by tracking correlated requests and payloads.250
hahwul/xspearAutomated testing tool for identifying vulnerabilities in web applications via cross-site scripting (XSS) attacks1,215