streaak / SSRF-TestingLinks
SSRF (Server Side Request Forgery) testing resources
☆12Updated 8 years ago
Alternatives and similar repositories for SSRF-Testing
Users that are interested in SSRF-Testing are comparing it to the libraries listed below
Sorting:
- Just some public notes that can be useful and i want let the world knows.☆88Updated 5 years ago
- Utility to pull disclosed vulnerabilities from HackerOne private programs - for personal use only☆13Updated 4 years ago
- Match and Replace script used to automatically generate JSON option file to BurpSuite☆214Updated 6 years ago
- Detects request smuggling via HTTP/2 downgrades.☆94Updated 3 years ago
- Real world bug bounty wordlists☆116Updated 2 years ago
- ☆44Updated 4 years ago
- Dump all available paths and/or endpoints on WADL file.☆96Updated last week
- Unpack a JavaScript Source Map back into filesystem structure☆185Updated 5 years ago
- A repository of some useful grep patterns for tomnomnoms gf tool☆38Updated 5 years ago
- A list of Awesome Bughunting oneliners , collected from the various sources☆69Updated 2 years ago
- Extract relative urls from a heap snapshot☆87Updated 4 years ago
- WILSON Cloud Respwnder is a Web Interaction Logger Sending Out Notifications with the ability to serve custom content in order to appropr…☆50Updated last year
- Get the scope of your bugcrowd programs☆67Updated 4 years ago
- Tool to find the real IP behind CDNs/WAFs like cloudflare using passive recon by retrieving the favicon hash. For the same hash value, al…☆183Updated 4 years ago
- Find subdomains and takeovers.☆86Updated 2 years ago
- ☆18Updated 4 years ago
- List HackerOne private program assets☆154Updated 4 years ago
- A Burp extension adding a passive scan check to flag parameters whose name or value may indicate a possible insertion point for SSRF or L…☆133Updated 4 years ago
- Pass list of urls with FUZZ in and it will check if it has found a potential SSRF.☆110Updated 3 years ago
- Bug Bounty Dork☆73Updated 3 years ago
- A tool to perform permutations, mutations and alteration of subdomains in golang.☆157Updated last year
- A tool to find subdomains or domains from passive sources.☆113Updated 4 years ago
- a tool that compiles a csv of all h1 program stats☆47Updated 2 years ago
- ☆108Updated 5 years ago
- It's an watcher for new scopes added to bounty-targets-data and send you alert to Slack.☆59Updated 3 years ago
- A really simple utility to concate wordlists to a domain name - to pipe into your favourite resolver!☆89Updated 5 years ago
- ☆22Updated 3 years ago
- Recon for Department of Defense HackerOne program☆46Updated 7 years ago
- ☆19Updated 5 years ago
- ☆16Updated 3 years ago