streaak / SSRF-TestingLinks
SSRF (Server Side Request Forgery) testing resources
☆12Updated 8 years ago
Alternatives and similar repositories for SSRF-Testing
Users that are interested in SSRF-Testing are comparing it to the libraries listed below
Sorting:
- Real world bug bounty wordlists☆117Updated 2 years ago
- Tool to find the real IP behind CDNs/WAFs like cloudflare using passive recon by retrieving the favicon hash. For the same hash value, al…☆183Updated 4 years ago
- Dump all available paths and/or endpoints on WADL file.☆96Updated 2 weeks ago
- Detects request smuggling via HTTP/2 downgrades.☆94Updated 3 years ago
- Pass list of urls with FUZZ in and it will check if it has found a potential SSRF.☆111Updated 3 years ago
- Just some public notes that can be useful and i want let the world knows.☆88Updated 5 years ago
- Find subdomains and takeovers.☆86Updated 3 years ago
- API Key/Token Exploitation Made easy.☆90Updated 4 years ago
- ☆30Updated 4 years ago
- Match and Replace script used to automatically generate JSON option file to BurpSuite☆214Updated 6 years ago
- 31 Tips for pentesters & security engineers☆86Updated 4 years ago
- A list of Awesome Bughunting oneliners , collected from the various sources☆69Updated 2 years ago
- GH Scanner Tool is written in Python3 and designed for penetration testers and bug bounty hunters to scan Organization/User repositories …☆34Updated 5 months ago
- Host Header Injection Checker☆83Updated 3 years ago
- Recon for Department of Defense HackerOne program☆46Updated 7 years ago
- It's an watcher for new scopes added to bounty-targets-data and send you alert to Slack.☆59Updated 3 years ago
- A Python based scanner to find potential SSRF parameters in a web application.☆70Updated 4 years ago
- Webapp to search tips on Twitter through #bugbountytips☆72Updated 3 years ago
- A repository of some useful grep patterns for tomnomnoms gf tool☆38Updated 5 years ago
- MNS is a security and reconnaissance tool for monitoring new subdomains☆70Updated this week
- You can find hardcoded Api-Key,Secret,Token Etc..☆77Updated 3 years ago
- ☆105Updated 5 years ago
- ☆22Updated 3 years ago
- ☆18Updated 4 years ago
- Some of my bug bounty tools☆52Updated 6 years ago
- A tool for append URLs, skipping duplicates/paths & combine parameters.☆125Updated 3 years ago
- A tool to find subdomains or domains from passive sources.☆112Updated 4 years ago
- A tool to perform permutations, mutations and alteration of subdomains in golang.☆156Updated 2 years ago
- A collection of simple tools and poc-builders☆39Updated 4 months ago
- A Burp extension adding a passive scan check to flag parameters whose name or value may indicate a possible insertion point for SSRF or L…☆132Updated 4 years ago