grafana-ssrf

SSRF vulnerability tester

A tool to demonstrate and exploit authenticated SSRF vulnerabilities in Grafana

Authenticated SSRF in Grafana

GitHub

77 stars
3 watching
28 forks
Language: Python
last commit: 5 months ago
Linked from 1 awesome list


Backlinks from these awesome lists:

Related projects:

Repository Description Stars
damian89/extended-ssrf-search An SSRF scanner written in Python to identify potential vulnerabilities by scanning predefined settings in URLs and request headers. 274
ksharinarayanan/ssrfire An automated tool to discover potential Server-Side Request Forgery (SSRF) vulnerabilities in web applications by scanning the domain for open redirects and testing for cross-site scripting (XSS) 944
incredibleindishell/ssrf_vulnerable_lab A laboratory repository demonstrating vulnerable PHP code examples for Server-Side Request Forgery (SSRF) attacks 670
serain/mailspoof A tool to analyze and report on SPF and DMARC record issues for potential email spoofing vulnerabilities. 127
teknogeek/ssrf-sheriff A tool designed to test and simulate Server-Side Request Forgery (SSRF) vulnerabilities by generating responses with configurable secret tokens 315
mindpatch/lorsrf A tool designed to identify parameters in web applications that can be exploited for SSRF or out-of-band resource load attacks. 289
kathanp19/gaussrf A tool for identifying potential vulnerabilities in websites by fetching known URLs and filtering out ones with open redirects or SSRF parameters. 165
1ndianl33t/gf-patterns A toolset for identifying potential security vulnerabilities and patterns in web applications 1,216
0xinfection/xsrfprobe A toolkit designed to test and exploit Cross-Site Request Forgery vulnerabilities in websites. 1,108
jacobreynolds/ssrfdetector A web application that detects and warns users about potential Server-side Request Forgery (SSRF) vulnerabilities. 149
aliasrobotics/rsf A standardized methodology to assess and improve the security of robotics systems 87
0xjcn/damn-vulnerable-defi-v3-ctf A DeFi protocol with intentional vulnerabilities for testing and learning secure smart contract development 25
qtc-de/remote-method-guesser A tool used to identify and exploit security vulnerabilities in Java RMI endpoints 828
daeken/httprebind A tool to automatically test DNS rebinding vulnerability in web applications 293
carstein/rfuss2 A simple Rust-based tool for testing software vulnerabilities by generating random inputs 23