{"id":13762714,"url":"https://github.com/ksharinarayanan/SSRFire","last_synced_at":"2025-05-10T15:31:45.920Z","repository":{"id":40613293,"uuid":"262062302","full_name":"ksharinarayanan/SSRFire","owner":"ksharinarayanan","description":"An automated SSRF finder. Just give the domain name and your server and chill! ;) Also has options to find XSS and open redirects","archived":false,"fork":false,"pushed_at":"2021-12-08T04:22:11.000Z","size":2642,"stargazers_count":946,"open_issues_count":1,"forks_count":158,"subscribers_count":25,"default_branch":"master","last_synced_at":"2024-10-29T16:58:31.595Z","etag":null,"topics":[],"latest_commit_sha":null,"homepage":"","language":"Shell","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":null,"status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/ksharinarayanan.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":null,"license":null,"code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null}},"created_at":"2020-05-07T13:46:06.000Z","updated_at":"2024-10-28T18:14:15.000Z","dependencies_parsed_at":"2022-07-14T04:00:41.442Z","dependency_job_id":null,"html_url":"https://github.com/ksharinarayanan/SSRFire","commit_stats":null,"previous_names":["micha3lb3n/ssrfire"],"tags_count":0,"template":false,"template_full_name":null,"repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/ksharinarayanan%2FSSRFire","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/ksharinarayanan%2FSSRFire/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/ksharinarayanan%2FSSRFire/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/ksharinarayanan%2FSSRFire/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/ksharinarayanan","download_url":"https://codeload.github.com/ksharinarayanan/SSRFire/tar.gz/refs/heads/master","host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":253436562,"owners_count":21908355,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2022-07-04T15:15:14.044Z","host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":[],"created_at":"2024-08-03T14:00:54.880Z","updated_at":"2025-05-10T15:31:45.671Z","avatar_url":"https://github.com/ksharinarayanan.png","language":"Shell","funding_links":[],"categories":["Weapons","Shell"],"sub_categories":["Tools"],"readme":"# SSRFIRE\r\nAn automated [SSRF](https://en.wikipedia.org/wiki/Server-side_request_forgery) finder. Just give the domain name and your server and chill! ;)\r\nIt also has options to find XSS and open redirects.\r\n\r\n![SSRFIRE](https://github.com/michaelben6/SSRFIRE/blob/master/static/ssrfire.png)\r\n\r\n### Syntax\r\n./ssrfire.sh -d domain.com -s yourserver.com -f custom_file.txt -c cookies\r\n\r\n\r\n**domain.com**        ---\u003e  The domain for which you want to test\r\n\r\n**yourserver.com**    ---\u003e  Your server which detects SSRF. Eg. Burp collaborator\r\n\r\n**custom_file.txt**   ---\u003e  Optional argument. You give your own custom URLs instead of using gau\r\n\r\n**cookies**           ---\u003e  Optional argument. To send requests as an authenticated user\r\n\r\n\r\nIf you don't have burpsuite professional, you can use [interact sh](https://interact.projectdiscovery.io/) by the awesome projectdiscovery team as your server.\r\n\r\n### Requirements\r\nSince this uses GAU, FFUF, qsreplace and OpenRedirex, you need GO and python 3.7+. You need not have the tools installed, as the script **setup.sh** will install everything.\r\nYou just need to install python and GO.\r\nEven if you have the tools installed I would highly recommend you to install them again so that there no conflicts while setting the paths.\r\n\r\nIf you don't want to install the tools again, paste this code in your .profile in your home directory and source .profile them.\r\nAlso, you have to make a small change in the ssrfire.sh on line 10, where you have to replace source /home/hari/.profile without\r\nyour .profile path. **(Only if you are not installing tools through setup.sh)**\r\n```\r\n#Replace /path/to/ with the specific directory where the tool is installed\r\n#If you already have configured paths for any of the tools, replace that code with the below one.\r\nffuf(){\r\n        echo \"Usage: ffuf https://www.domain.com/FUZZ payloads.txt\"\r\n        /path/to/ffuf/./main -u $1 -w $2 -b $3 -c -t 100\r\n}\r\n\r\ngau(){\r\n        echo \"Usage: gau domain.com\"\r\n        /path/to/gau/./main $1\r\n}\r\n\r\ngau_s(){\r\n\t/path/to/gau/./main --subs $1\r\n}\r\n\r\nopenredirex(){\r\n        echo \"Usage: openredirex urls.txt payloads.txt\"\r\n        python3 /path/to/OpenRedireX/openredirex.py -l $1 -p $2 --keyword FUZZ\r\n}\r\nqsreplace(){\r\n\t\t/path/to/qsreplace/./main $1\r\n}\r\n```\r\n## Usage\r\n```\r\nchmod +x setup.sh\r\n./setup.sh (preferably yes for all ---\u003e **highly recommended**)\r\n./ssrfire.sh -d domain.com -s yourserver.com\r\n```\r\n### Finding SSRF\r\nNow, gau gets into action by fetching all the URLs of the domain. This may take a lot of time.\r\nYou can check the output generated till now at output/domain.com/raw_urls.txt\r\n\r\nLet it run for at least 10-15 minutes, and then if you want to continue, you can.\r\nBut if you want to test the URLs fetched till now, quit the process.\r\nCopy the raw_urls.txt inside of output/domain.com and place it outside the domain.com folder\r\nNow run\r\n```\r\n./ssrfire.sh -d domain.com -s yourserver.com -f /path/to/copied_raw_urls.txt\r\n```\r\nSelect yes when asked whether to delete the existing folder.\r\n\r\nThis will skip the process of GAU fetching URLs.\r\n\r\nNow all the URLs with parameters will be filtered and yourserver.com will be placed into their parameter values.(final_urls.txt)\r\n\r\nThe next step is to fire requests to all the final URLs.\r\n\r\n### Finding XSS\r\n\r\n**Warning: This generates a lot of traffic. Do not use this against sites which you are not authorized to test**\r\n\r\nThis tests all the URLs fetched, and based on how the input is reflected in the response, it adds that particular URL to the output/domain.com/xss-suspects.txt **(This may contain false positives)**\r\n\r\nFor further testing this, you can input this list to the XSS detection tools like XSStrike to find XSS.\r\n\r\n### Finding open redirects\r\n\r\nJust enter the path to a payload file or use the default payload.\r\nI personally prefer openredirex, as it is specifically designed to check for open redirects by loading the URLs from the list\r\nand it looks a lot cleaner, and doesn't flood your terminal.\r\n\r\n## Tools used:\r\n\r\nGAU - [https://github.com/lc/gau](https://github.com/lc/gau)\r\n\r\nffuf - [https://github.com/ffuf/ffuf](https://github.com/ffuf/ffuf)\r\n\r\nqspreplace - [https://github.com/tomnomnom/qsreplace](https://github.com/tomnomnom/qsreplace)\r\n\r\nOpenRedireX - [https://github.com/devanshbatham/OpenRedireX](https://github.com/devanshbatham/OpenRedireX)\r\n\r\nThanks to all the authors of the tools.\r\n\r\n***\r\n\r\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fksharinarayanan%2FSSRFire","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fksharinarayanan%2FSSRFire","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fksharinarayanan%2FSSRFire/lists"}