A list of resources for those interested in getting started in bug bounties
-
Updated
Jul 23, 2024
A list of resources for those interested in getting started in bug bounties
Automatic SSRF fuzzer and exploitation tool
SSRF (Server Side Request Forgery) testing resources
Recon & pentest skill pack. CORS, XSS, SQLi, SSRF, RCE, WordPress, MCP, cloud, subdomain takeover, and more. Field-tested. MIT. Full write-up at hiago.sh
Open-source AI agent firewall for MCP security and agent egress. Scans mediated HTTP, MCP, A2A, and WebSocket traffic for exfiltration, SSRF, and prompt injection, and emits mediator-signed action receipts: verifiable audit evidence from outside the agent.
This Lab contain the sample codes which are vulnerable to Server-Side Request Forgery attack
一款功能强大的漏洞扫描器,子域名爆破使用aioDNS,asyncio异步快速扫描,覆盖目标全方位资产进行批量漏洞扫描,中间件信息收集,自动收集ip代理,探测Waf信息时自动使用来保护本机真实Ip,在本机Ip被Waf杀死后,自动切换代理Ip进行扫描,Waf信息收集(国内外100+款waf信息)包括安全狗,云锁,阿里云,云盾,腾讯云等,提供部分已知waf bypass 方案,中间件漏洞检测(Thinkphp,weblogic等 CVE-2018-5955,CVE-2018-12613,CVE-2018-11759等),支持SQL注入, XSS, 命令执行,文件包含, ssrf 漏洞扫描, 支持自定义漏洞邮箱推送功能
Redis 4.x/5.x RCE
RevSuit is a flexible and powerful reverse connection platform designed for receiving connection from target host in penetration.
SSRF Proxy facilitates tunneling HTTP communications through servers vulnerable to Server-Side Request Forgery.
JAVA 漏洞靶场 (Vulnerability Environment For Java)
Find All Parameters - Tool to crawl pages, find potential parameters and generate a custom target parameter wordlist
Smart context-based SSRF vulnerability scanner.
To associate your repository with the ssrf topic, visit your repo's landing page and select "manage topics."