All Projects → ssrf-vuls → Similar Projects or Alternatives

56 Open source projects that are alternatives of or similar to ssrf-vuls

Resources-for-Application-Security
Some good resources for getting started with application security
Stars: ✭ 97 (-58.72%)
Mutual labels:  websecurity
wybug
一款复现wooyun经典漏洞的docker靶机环境
Stars: ✭ 17 (-92.77%)
Mutual labels:  websecurity
ssrf filter
A ruby gem for defending against Server Side Request Forgery (SSRF) attacks
Stars: ✭ 68 (-71.06%)
Mutual labels:  ssrf
WebSecurityScannerWhitePaper
收集网络上公开的漏洞扫描器的白皮书。
Stars: ✭ 25 (-89.36%)
Mutual labels:  websecurity
netizenship
a commandline #OSINT tool to find the online presence of a username in popular social media websites like Facebook, Instagram, Twitter, etc.
Stars: ✭ 33 (-85.96%)
Mutual labels:  websecurity
caddy-security
🔐 Authentication, Authorization, and Accounting (AAA) App and Plugin for Caddy v2. 💎 Implements Form-Based, Basic, Local, LDAP, OpenID Connect, OAuth 2.0 (Github, Google, Facebook, Okta, etc.), SAML Authentication. MFA/2FA with App Authenticators and Yubico. 💎 Authorization with JWT/PASETO tokens. 🔐
Stars: ✭ 696 (+196.17%)
Mutual labels:  websecurity
proxylogscan
A fast tool to mass scan for a vulnerability on Microsoft Exchange Server that allows an attacker bypassing the authentication and impersonating as the admin (CVE-2021-26855).
Stars: ✭ 145 (-38.3%)
Mutual labels:  ssrf
exprolog
ProxyLogon Full Exploit Chain PoC (CVE-2021–26855, CVE-2021–26857, CVE-2021–26858, CVE-2021–27065)
Stars: ✭ 131 (-44.26%)
Mutual labels:  ssrf
Blind-SSRF
Nuclei Templates to reproduce Cracking the lens's Research
Stars: ✭ 111 (-52.77%)
Mutual labels:  ssrf
CVE-2020-36179
CVE-2020-36179~82 Jackson-databind SSRF&RCE
Stars: ✭ 77 (-67.23%)
Mutual labels:  ssrf
Ssrf Testing
SSRF (Server Side Request Forgery) testing resources
Stars: ✭ 1,718 (+631.06%)
Mutual labels:  ssrf
Resources For Beginner Bug Bounty Hunters
A list of resources for those interested in getting started in bug bounties
Stars: ✭ 7,185 (+2957.45%)
Mutual labels:  ssrf
Priest
Extract server and IP address information from Browser SSRF
Stars: ✭ 13 (-94.47%)
Mutual labels:  ssrf
SecExample
JAVA 漏洞靶场 (Vulnerability Environment For Java)
Stars: ✭ 228 (-2.98%)
Mutual labels:  ssrf
Eagle
Multithreaded Plugin based vulnerability scanner for mass detection of web-based applications vulnerabilities
Stars: ✭ 85 (-63.83%)
Mutual labels:  ssrf
Flag-Capture
Solutions and write-ups from security-based competitions also known as Capture The Flag competition
Stars: ✭ 84 (-64.26%)
Mutual labels:  ssrf
ssrf-agent
make http(s) request to prevent SSRF
Stars: ✭ 16 (-93.19%)
Mutual labels:  ssrf
SSRF payload
本脚本旨在生成各类畸形URL链接,进行探测使用的payload,尝试绕过服务端ssrf限制。
Stars: ✭ 28 (-88.09%)
Mutual labels:  ssrf
ctf
CTF programs and writeups
Stars: ✭ 22 (-90.64%)
Mutual labels:  ssrf
bulkssrf
Tests for SSRF by injecting a specified location into different headers. This is a Rust port of m4ll0k's tool.
Stars: ✭ 35 (-85.11%)
Mutual labels:  ssrf
Virtual-Host
Modified Nuclei Templates Version to FUZZ Host Header
Stars: ✭ 38 (-83.83%)
Mutual labels:  ssrf
Sourceleakhacker
🐛 A multi threads web application source leak scanner
Stars: ✭ 226 (-3.83%)
Mutual labels:  websecurity
Open Redirect Payload List
🎯 Open Redirect Payload List
Stars: ✭ 214 (-8.94%)
Mutual labels:  websecurity
Rfi Lfi Payload List
🎯 RFI/LFI Payload List
Stars: ✭ 202 (-14.04%)
Mutual labels:  websecurity
Recsech
Recsech is a tool for doing Footprinting and Reconnaissance on the target web. Recsech collects information such as DNS Information, Sub Domains, HoneySpot Detected, Subdomain takeovers, Reconnaissance On Github and much more you can see in Features in tools .
Stars: ✭ 173 (-26.38%)
Mutual labels:  websecurity
Oscp Pentest Methodologies
备考 OSCP 的各种干货资料/渗透测试干货资料
Stars: ✭ 166 (-29.36%)
Mutual labels:  websecurity
Ssti Payloads
🎯 Server Side Template Injection Payloads
Stars: ✭ 150 (-36.17%)
Mutual labels:  websecurity
Xss Payload List
🎯 Cross Site Scripting ( XSS ) Vulnerability Payload List
Stars: ✭ 2,617 (+1013.62%)
Mutual labels:  websecurity
Wossl
OpenSSL对称算法、哈希校验、非对称算法、证书管理、SSL安全
Stars: ✭ 144 (-38.72%)
Mutual labels:  websecurity
Jwtxploiter
A tool to test security of json web token
Stars: ✭ 130 (-44.68%)
Mutual labels:  websecurity
Horn3t
Powerful Visual Subdomain Enumeration at the Click of a Mouse
Stars: ✭ 120 (-48.94%)
Mutual labels:  websecurity
Quarantyne
Modern Web Firewall: stop account takeovers, weak passwords, cloud IPs, DoS attacks, disposable emails
Stars: ✭ 113 (-51.91%)
Mutual labels:  websecurity
Vailyn
A phased, evasive Path Traversal + LFI scanning & exploitation tool in Python
Stars: ✭ 103 (-56.17%)
Mutual labels:  websecurity
Ctfcracktools
China's first CTFTools framework.中国国内首个CTF工具框架,旨在帮助CTFer快速攻克难关
Stars: ✭ 1,118 (+375.74%)
Mutual labels:  websecurity
Ostrio
▲ Web services for JavaScript, Angular.js, React.js, Vue.js, Meteor.js, Node.js, and other JavaScript-based websites, web apps, single page applications (SPA), and progressive web applications (PWA). Our services: Pre-rendering, Monitoring, Web Analytics, WebSec, and Web-CRON
Stars: ✭ 52 (-77.87%)
Mutual labels:  websecurity
Holisticinfosec For Webdevelopers Fascicle0
📚 Overview 🔒 Tooling 🔒 Process 🔒 Physical 🔒 People 📚
Stars: ✭ 37 (-84.26%)
Mutual labels:  websecurity
Intranet penetration cheetsheets
做redteam时使用,修改自Ridter的https://github.com/Ridter/Intranet_Penetration_Tips
Stars: ✭ 29 (-87.66%)
Mutual labels:  websecurity
Broxy
An HTTP/HTTPS intercept proxy written in Go.
Stars: ✭ 912 (+288.09%)
Mutual labels:  websecurity
Sql Injection Payload List
🎯 SQL Injection Payload List
Stars: ✭ 716 (+204.68%)
Mutual labels:  websecurity
Awesome Web Security
🐶 A curated list of Web Security materials and resources.
Stars: ✭ 6,623 (+2718.3%)
Mutual labels:  websecurity
Dictionary Of Pentesting
Dictionary collection project such as Pentesing, Fuzzing, Bruteforce and BugBounty. 渗透测试、SRC漏洞挖掘、爆破、Fuzzing等字典收集项目。
Stars: ✭ 492 (+109.36%)
Mutual labels:  websecurity
Zvuldrill
Web漏洞演练平台
Stars: ✭ 440 (+87.23%)
Mutual labels:  websecurity
Newbie Security List
网络安全学习资料,欢迎补充
Stars: ✭ 402 (+71.06%)
Mutual labels:  websecurity
Cerberus
一款功能强大的漏洞扫描器,子域名爆破使用aioDNS,asyncio异步快速扫描,覆盖目标全方位资产进行批量漏洞扫描,中间件信息收集,自动收集ip代理,探测Waf信息时自动使用来保护本机真实Ip,在本机Ip被Waf杀死后,自动切换代理Ip进行扫描,Waf信息收集(国内外100+款waf信息)包括安全狗,云锁,阿里云,云盾,腾讯云等,提供部分已知waf bypass 方案,中间件漏洞检测(Thinkphp,weblogic等 CVE-2018-5955,CVE-2018-12613,CVE-2018-11759等),支持SQL注入, XSS, 命令执行,文件包含, ssrf 漏洞扫描, 支持自定义漏洞邮箱推送功能
Stars: ✭ 389 (+65.53%)
Mutual labels:  websecurity
Rta
Red team Arsenal - An intelligent scanner to detect security vulnerabilities in company's layer 7 assets.
Stars: ✭ 358 (+52.34%)
Mutual labels:  websecurity
Xxe Injection Payload List
🎯 XML External Entity (XXE) Injection Payload List
Stars: ✭ 304 (+29.36%)
Mutual labels:  websecurity
Shell Backdoor List
🎯 PHP / ASP - Shell Backdoor List 🎯
Stars: ✭ 288 (+22.55%)
Mutual labels:  websecurity
Application Security Engineer Interview Questions
Some of the questions which i was asked when i was giving interviews for Application/Product Security roles. I am sure this is not an exhaustive list but i felt these questions were important to be asked and some were challenging to answer
Stars: ✭ 267 (+13.62%)
Mutual labels:  websecurity
Sherlock
This script is designed to help expedite a web application assessment by automating some of the assessment steps (e.g., running nmap, sublist3r, metasploit, etc.)
Stars: ✭ 36 (-84.68%)
Mutual labels:  websecurity
wasec
Examples of security features (or mishaps) on web applications -- these are mostly examples and tutorials from the WASEC book.
Stars: ✭ 74 (-68.51%)
Mutual labels:  websecurity
HolyTips
A Collection of Notes, Checklists, Writeups on Bug Bounty Hunting and Web Application Security.
Stars: ✭ 1,210 (+414.89%)
Mutual labels:  websecurity
pentest-notes
渗透测试☞经验/思路/总结/想法/笔记
Stars: ✭ 734 (+212.34%)
Mutual labels:  websecurity
awesome-web-security
📓 Some notes and impressive articles of Web Security
Stars: ✭ 72 (-69.36%)
Mutual labels:  websecurity
firecracker
Stop half-done API specifications! Cherrybomb is a CLI tool that helps you avoid undefined user behaviour by validating your API specifications.
Stars: ✭ 438 (+86.38%)
Mutual labels:  websecurity
cero
Scrape domain names from SSL certificates of arbitrary hosts
Stars: ✭ 316 (+34.47%)
Mutual labels:  websecurity
Vulhub
Pre-Built Vulnerable Environments Based on Docker-Compose
Stars: ✭ 9,044 (+3748.51%)
Mutual labels:  vulhub
1-56 of 56 similar projects