📦 GitHub 全球红队渗透资源中转站。
​旨在收录那些“好用却难找”的安全项目。
🔗 定时推送:GitHub Trending (Security)
🛠 必备清单:后渗透、远控、免杀、提权工具集
📅 更新频率:每日精选,绝不灌水。
⚠️ 本频道仅供安全研究与授权测试使用。
🚨 GitHub 监控消息提醒

🚨 发现关键词: #SSRF #POC

📦 项目名称: PenTesting-001
👤 项目作者: Nizuii
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-14 04:58:56

📝 项目描述:
OWASP checklist mastery, auth flow attacks, CSRF/SSRF/Session Fixation/Hijacking, payment gateway pentesting, VulnHub VMs (Mr. Robot, Zero Bank, Jangow, N7), and PoC/VAPT-style reporting.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #SSRF #metadata

📦 项目名称: dsh-webfetch
👤 项目作者: withlovehub
🛠 开发语言: JavaScript
Star数量: 1 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-13 16:12:34

📝 项目描述:
Zero-dependency webfetch MCP server for DeepSeek Harness and any MCP client: clean text / markdown / raw HTML / JSON, robots.txt compliance, chunked reading, SSRF protection.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #SSRF #metadata

📦 项目名称: site-checker
👤 项目作者: igor-zatochniy
🛠 开发语言: Go
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-13 16:47:56

📝 项目描述:
Website monitoring backend with a REST API, PostgreSQL, RabbitMQ workers, Prometheus metrics, and Kubernetes manifests.

🔗 点击访问项目地址 GitHub - igor-zatochniy/site-checker: Website monitoring backend with a REST API, PostgreSQL, RabbitMQ workers, Prometheus metrics…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #SSRF #metadata

📦 项目名称: cloud-security-open-bucket
👤 项目作者: pavansai124
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-12 16:01:48

📝 项目描述:
Self-hosted cloud security attack range using LocalStack, Terraform, Docker and AWS CLI to demonstrate IAM, S3, SSRF, metadata credential exposure, remediation and verification.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #SSRF #metadata

📦 项目名称: ens-metadata-security-disclosure
👤 项目作者: Julik000
🛠 开发语言: JavaScript
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-12 11:20:59

📝 项目描述:
Security vulnerability disclosure for ENS Metadata Service (SSRF & DoS)

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #SSRF #CVE #metadata

📦 项目名称: cyber-threat-intelligence-platform
👤 项目作者: mojtaba-py-code
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-12 06:21:02

📝 项目描述:
Self-hostable Threat Intelligence Platform: collects, enriches, scores and correlates IOCs, with STIX 2.1/MISP sharing and live alerting. Offline-first and SSRF-guarded. FastAPI, async SQLAlchemy, Celery.

🔗 点击访问项目地址 GitHub - mojtaba-py-code/cyber-threat-intelligence-platform: Self-hostable Threat Intelligence Platform: collects, enriches, scores…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #SSRF #云元数据

📦 项目名称: agent-audit
👤 项目作者: simisdav55-oss
🛠 开发语言: Python
Star数量: 1 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-12 06:54:52

📝 项目描述:
AI Agent 安全测试工具 — 一键扫描 75+ 攻击向量,含 Prompt Injection / Tool Abuse / Data Exfiltration / SSRF / 中文场景

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #SSRF #云元数据

📦 项目名称: SSRF
👤 项目作者: TaoLjx
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-12 05:35:54

📝 项目描述:
SSRF靶场,覆盖9大分类(基础SSRF、协议级SSRF、IP地址过滤绕过、URL解析器混淆、302重定向SSRF、DNS Rebinding、Blind SSRF、云元数据攻击、真是业务场景),真实业务场景覆盖12个真实的业务场景(webhook测试器、URL预览、图片代理/CDN、PDF生成器、API网关/代理、RSS阅读器、从URL导入文件、短链接展开器、健康检查监控、OAuth SSO重定向、支付回调曾是、网页截图服务)

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #SSRF #POC #CVE

📦 项目名称: CVE-2022-3590
👤 项目作者: 4chech
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-12 04:26:34

📝 项目描述:
PoC Exploit for blind SSRF in XML-RPC Wordpress

🔗 点击访问项目地址 4chech/CVE-2022-3590
🚨 GitHub 监控消息提醒

🚨 发现关键词: #SSRF #metadata

📦 项目名称: ssrf
👤 项目作者: 0xSt4rk007
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-11 22:07:50

📝 项目描述:
无描述

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #SSRF #metadata

📦 项目名称: security-boundary-tests
👤 项目作者: messaging-intel-test
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-11 22:26:21

📝 项目描述:
Tenant isolation, replay protection, signature verification, path traversal, SSRF, redaction, and CI supply-chain boundary tests.

🔗 点击访问项目地址 GitHub - messaging-intel-test/security-boundary-tests: Tenant isolation, replay protection, signature verification, path traversal…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #SSRF #CVE

📦 项目名称: btcpay-scanner
👤 项目作者: iktok90-design
🛠 开发语言: JavaScript
Star数量: 1 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-10 05:59:57

📝 项目描述:
Network scanner for BTCPay Server instances — version detection, SSRF CVE auditor (< 2.4.2), and Lightning node discovery

🔗 点击访问项目地址 GitHub - iktok90-design/btcpay-scanner: Network scanner for BTCPay Server instances — version detection, security audit, and Lightning…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #SSRF #metadata

📦 项目名称: seo-auditor
👤 项目作者: igor-zatochniy
🛠 开发语言: Go
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-09 14:11:20

📝 项目描述:
Technical SEO audit service built with Go and PostgreSQL, with concurrent crawling, robots.txt support, and SSRF protection.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #SSRF #metadata

📦 项目名称: engineering-patterns
👤 项目作者: cryptothud
🛠 开发语言: TypeScript
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-08 23:54:38

📝 项目描述:
Reference implementations of the patterns I rely on in production: Solana transaction sending and confirmation, SSRF-safe URL handling, and environment/secret loading.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #SSRF #metadata

📦 项目名称: webhook-delivery-service
👤 项目作者: sidyn4444
🛠 开发语言: Java
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-09 00:26:21

📝 项目描述:
Distributed webhook delivery service in Java 21 / Spring Boot 3. At-least-once delivery with a Redis reliable queue, jittered exponential-backoff retries, dead-letter queue, HMAC-SHA256 signing, and SSRF-hardened ingest.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #SSRF #metadata

📦 项目名称: algovoi-rfc9421-keyid
👤 项目作者: chopmob-cloud
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-08 11:03:45

📝 项目描述:
SSRF-guarded RFC 9421 keyid resolver (did:key / did:web / HTTPS) to Ed25519 public keys. Apache-2.0.

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #SSRF #metadata

📦 项目名称: Common-Web-Application-Bug-Classes-Cheatsheet
👤 项目作者: fantasywastaken
🛠 开发语言: Unknown
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-08 06:32:05

📝 项目描述:
Defensive OWASP-style cheatsheet of common web application bug classes including SQLi, XSS, SSRF, XXE, IDOR, path traversal, deserialization, and command injection with mitigations.

🔗 点击访问项目地址 GitHub - fantasywastaken/Common-Web-Application-Bug-Classes-Cheatsheet: Defensive OWASP-style cheatsheet of common web application…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #SSRF #CVE

📦 项目名称: api-security-scanner
👤 项目作者: ridhinva
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-07 21:52:12

📝 项目描述:
Scanner: OWASP API Top 10 2023 + GraphQL security scanner — BOLA, BFLA, SSRF, introspection leaks, depth DoS in Python

🔗 点击访问项目地址 GitHub - ridhinva/api-security-scanner: Scanner: OWASP API Top 10 2023 + GraphQL security scanner — BOLA, BFLA, SSRF, introspection…
🚨 GitHub 监控消息提醒

🚨 发现关键词: #SSRF #metadata

📦 项目名称: ssrf-gateway
👤 项目作者: picoclone
🛠 开发语言: Python
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-07 10:50:37

📝 项目描述:
picoclone CTF challenge: SSRF Safari (web · hard)

🔗 点击访问项目地址
🚨 GitHub 监控消息提醒

🚨 发现关键词: #SSRF #metadata

📦 项目名称: ssrf-safe-fetch
👤 项目作者: owner-stack
🛠 开发语言: TypeScript
Star数量: 0 | 🍴 Fork数量: 0
📅 更新时间: 2026-08-07 08:07:07

📝 项目描述:
Zero-dependency SSRF-hardened fetch for Node: blocks private networks, cloud metadata, and DNS-rebinding redirects. 114 tests.

🔗 点击访问项目地址
 
 
Back to Top