Automatic SSRF fuzzer and exploitation tool
翻译 - 自动SSRF模糊器和开发工具
SSRF (Server Side Request Forgery) testing resources
This Lab contain the sample codes which are vulnerable to Server-Side Request Forgery attack
翻译 - 本实验包含易受服务器端请求伪造攻击的示例代码
A ruby gem for defending against Server Side Request Forgery (SSRF) attacks
Proof-of-Concept for Server Side Request Forgery (SSRF) in request-baskets (<= v.1.2.1)
Module to prevent SSRF when sending requests in NodeJS. Blocks request to local and private IP addresses
An ongoing & curated collection of awesome web vulnerability - Server-side request forgery software practices and remediation, libraries and frameworks, best guidelines and technical resources about ...
Example exploitable scenarios for CVE-2024-22243 affecting the Spring framework (open redirect & SSRF).
CVE-2021-40438 Apache <= 2.4.48 SSRF exploit
Server-Side Request Forgery (SSRF) protection plugin for HTTPlug
Gopher HTTP requests (POST/GET)
CloudSSRFer tests SSRF on Amazon AWS cloud to extract sensitive information.
node package to use ssrfproxy.com for protection against server side request forgery
CVE-2019-9849: Remote bullet graphics retrieved in “stealth mode” in LibreOffice
Spring boot application developed to learn how to use the framework and understand how vulnerabilities are manifested in the application and how to prevent them.
#安全#The repository includes various vulnerbilities, their types, identification, exploitation and mitigations along with payloads. Includes: Cross-Site Scripting (XSS) SQL Injection (SQLi) Directory Tra...