Skip to content
#

blind-ssrf

Here are 5 public repositories matching this topic...

Language: All
Filter by language

Header-based SSRF (scanner-for-debugging) fuzzing utility inspired by a HackerOne Blind SSRF report. Automates injection of Forwarded-type headers, detects time-delay behavior and 429 responses, supports authenticated flows, logs results, and optionally integrates Telegram notifications for controlled security testing.

  • Updated Feb 21, 2026
  • Python

This repository contains a professional bug bounty report demonstrating the successful exploitation of a Blind SSRF vulnerability that reached an internal CGI endpoint vulnerable to Shellshock (CVE-2014-6271). Remote command execution was confirmed using an out-of-band (OAST) DNS callback, showcasing the complete attack chain, technical analysis.

  • Updated Jul 5, 2026

Improve this page

Add a description, image, and links to the blind-ssrf topic page so that developers can more easily learn about it.

Curate this topic

Add this topic to your repo

To associate your repository with the blind-ssrf topic, visit your repo's landing page and select "manage topics."

Learn more