SSRFmap

Web exploitation tool

Automates exploiting vulnerabilities in web applications to execute arbitrary actions on their behalf

Automatic SSRF fuzzer and exploitation tool

GitHub

3k stars
55 watching
530 forks
Language: Python
last commit: over 2 years ago
Linked from 1 awesome list

ctfexploitationhacktoberfestpentestserver-side-request-forgeryssrfssrfmapvulnerability

Backlinks from these awesome lists:

Related projects:

RepositoryDescriptionStars
tarunkant/gopherusA tool for generating Gopher payloads to exploit SSRF vulnerabilities and gain RCE on various servers2,909
manisso/fsocietyA comprehensive collection of hacking tools and scripts for penetration testing and vulnerability assessment10,698
damian89/extended-ssrf-searchAn SSRF scanner written in Python to identify potential vulnerabilities by scanning predefined settings in URLs and request headers.276
xmendez/wfuzzA tool to automatically generate and test web application inputs for security vulnerabilities5,978
rsactftool/rsactftoolTools for decrypting data from weak RSA keys and recovering private keys using various integer factorization algorithms.5,800
0xinfection/xsrfprobeA toolkit designed to test and exploit Cross-Site Request Forgery vulnerabilities in websites.1,116
fuzzdb-project/fuzzdbA comprehensive toolset for identifying and exploiting application vulnerabilities through dynamic testing8,288
ksharinarayanan/ssrfireAn automated tool to discover potential Server-Side Request Forgery (SSRF) vulnerabilities in web applications by scanning the domain for open redirects and testing for cross-site scripting (XSS)953
randomrobbiebf/grafana-ssrfA tool to demonstrate and exploit authenticated SSRF vulnerabilities in Grafana78
incredibleindishell/ssrf_vulnerable_labA laboratory repository demonstrating vulnerable PHP code examples for Server-Side Request Forgery (SSRF) attacks679
secdev/scapyA Python-based tool for interactive packet manipulation and analysis10,870
threat9/routersploitAn exploitation framework designed to aid in the testing of embedded devices' vulnerabilities12,253
jiangsir404/xss-sql-fuzzAutomates fuzzing of XSS and SQL injection vulnerabilities in web applications using Burp Suite extensions.61
evyatarmeged/raccoonA high-performance tool for reconnaissance and vulnerability scanning of web applications and networks3,105
fatedier/frpAn open source tool that exposes local servers behind firewalls or NATs to the internet87,642