streaak / SSRF-TestingLinks
SSRF (Server Side Request Forgery) testing resources
☆12Updated 8 years ago
Alternatives and similar repositories for SSRF-Testing
Users that are interested in SSRF-Testing are comparing it to the libraries listed below
Sorting:
- Detects request smuggling via HTTP/2 downgrades.☆94Updated 3 years ago
- Real world bug bounty wordlists☆117Updated 2 years ago
- Just some public notes that can be useful and i want let the world knows.☆88Updated 5 years ago
- Dump all available paths and/or endpoints on WADL file.☆98Updated 2 months ago
- Pass list of urls with FUZZ in and it will check if it has found a potential SSRF.☆112Updated 3 years ago
- Tool to find the real IP behind CDNs/WAFs like cloudflare using passive recon by retrieving the favicon hash. For the same hash value, al…☆185Updated 5 years ago
- A tool to perform permutations, mutations and alteration of subdomains in golang.☆156Updated 2 years ago
- Recon for Department of Defense HackerOne program☆47Updated 7 years ago
- ☆105Updated 5 years ago
- Match and Replace script used to automatically generate JSON option file to BurpSuite☆215Updated 6 years ago
- GH Scanner Tool is written in Python3 and designed for penetration testers and bug bounty hunters to scan Organization/User repositories …☆34Updated 6 months ago
- API Key/Token Exploitation Made easy.☆93Updated 4 years ago
- Utility to pull disclosed vulnerabilities from HackerOne private programs - for personal use only☆13Updated 4 years ago
- Fleex makes it easy to create multiple VPS on cloud providers and use them to distribute workloads.☆265Updated this week
- X-Forwarded-For [403 forbidden] enumeration☆99Updated last year
- Subdomain Monitor A production-ready subdomain monitoring system with both API and CLI interfaces.☆74Updated last week
- 📚 An ultimate collection wordlists of the best-known CMS☆93Updated last year
- List of domains in scope for bug bounties (HackerOne, Bugcrowd, etc.)☆74Updated 4 years ago
- ☆31Updated 5 years ago
- ☆18Updated 4 years ago
- A collection of simple tools and poc-builders☆39Updated 6 months ago
- ☆16Updated 4 years ago
- GitHub Recon — and what you can achieve with it!☆121Updated 4 years ago
- A Burp extension adding a passive scan check to flag parameters whose name or value may indicate a possible insertion point for SSRF or L…☆132Updated 4 years ago
- 🏵 Gee is tool of stdin to each files and stdout. It is similar to the tee command, but there are more functions for convenience. In addi…☆85Updated 4 months ago
- Implementation of Wappalyzer in Python☆55Updated 3 years ago
- A list of Awesome Bughunting oneliners , collected from the various sources☆69Updated 2 years ago
- This Repo contains wordlist for subdomain enumeration , php file path, html file path, and js file path☆107Updated 5 years ago
- 31 Tips for pentesters & security engineers☆87Updated 4 years ago
- ☆75Updated last year