KauanCosta2000 / Ultimate-ssrf-Framework
PublicAdvanced SSRF discovery, validation and analysis framework for bug bounty, pentesting and security research.
The Ultimate SSRF Framework is a security testing tool designed to help researchers and penetration testers find Server-Side Request Forgery vulnerabilities in web applications. It automatically discovers website endpoints, tests them with various attack patterns, and can access cloud provider metadata services (AWS, Azure, Google Cloud, Alibaba) to check for serious security issues. The tool supports blind vulnerability detection through callback services, AI-assisted attack generation, and produces reports in multiple formats for documentation or integration with other security tools. It is intended for authorized security testing, bug bounty hunting, and educational purposes.
How It Works
You hear about a tool that helps find security weaknesses in websites, specifically ones where servers can be tricked into fetching unexpected content.
You enter a website address you have permission to test, or provide a list of websites from a file.
The tool visits the website, finds hidden paths and parameters, and tests them for vulnerabilities—all while you watch.
The tool sends special requests and waits for the website to 'call back' to a service you provide, proving the vulnerability exists.
The tool shows you immediately what it found, including any sensitive data the server accidentally revealed.
If the target uses Amazon, Google, Azure, or Alibaba cloud services, the tool checks whether it can access secret metadata like access keys.
The tool creates easy-to-read reports showing what it found, how serious each issue is, and what happened during testing.
You now have documented evidence of security weaknesses that developers can fix, or findings to report through bug bounty programs.
Star Growth
Repurpose is a Pro feature
Generate ready-to-use prompts for X threads, LinkedIn posts, blog posts, YouTube scripts, and more -- with full repo context baked in.
Unlock RepurposeSimilar repos coming soon.