├── Dockerfile ├── Host_header ├── README.md ├── default └── images │ ├── Nginx_config.png │ ├── SSRF.png │ ├── actual_request.png │ └── readme.md ├── LICENSE.md ├── README.md └── www ├── DNS Rebinding based Bypass ├── README.md └── images │ ├── DNS_Rebinding_Attack_1.png │ ├── DNS_Rebinding_Attack_10.png │ ├── DNS_Rebinding_Attack_11.png │ ├── DNS_Rebinding_Attack_12.png │ ├── DNS_Rebinding_Attack_13.png │ ├── DNS_Rebinding_Attack_2.png │ ├── DNS_Rebinding_Attack_3.png │ ├── DNS_Rebinding_Attack_4.png │ ├── DNS_Rebinding_Attack_5.png │ ├── DNS_Rebinding_Attack_6.png │ ├── DNS_Rebinding_Attack_7.png │ ├── DNS_Rebinding_Attack_8.png │ ├── DNS_Rebinding_Attack_9.png │ └── README.md ├── DNS-Spoofing-based-Bypass ├── README.md └── images │ ├── README.md │ ├── dns spoofing 1.png │ ├── dns spoofing 2.png │ ├── dns spoofing 3.png │ ├── dns spoofing 4.png │ ├── dns spoofing 5.png │ ├── dns spoofing 6.png │ └── dns spoofing 7.png ├── File_Download ├── README.md └── images │ ├── README.md │ ├── file_download_1.png │ ├── file_download_10.png │ ├── file_download_11.png │ ├── file_download_2.png │ ├── file_download_3.png │ ├── file_download_4.png │ ├── file_download_6.png │ ├── file_download_7.png │ ├── file_download_8.png │ └── file_download_9.png ├── Remote_host_connect_interface ├── README.md └── images │ ├── MySQL_Connect_1.png │ ├── MySQL_Connect_2.png │ ├── MySQL_Connect_3.png │ ├── MySQL_Connect_4.png │ ├── MySQL_Connect_5.png │ ├── MySQL_Connect_6.png │ ├── MySQL_Connect_7.png │ └── README.md ├── XML ├── images │ └── README.md ├── sample_upload.xml └── ssrf_using_xxe.xml ├── all.css ├── dns-spoofing.php ├── dns_rebinding.php ├── download.php ├── file_content_fetch ├── README.md └── images │ ├── README.md │ ├── file1.png │ ├── file2.png │ ├── file3.png │ ├── file4.png │ ├── file5.png │ └── file6.png ├── file_get_content.php ├── head.php ├── images ├── README.md ├── SSRF_Vulnerable_Lab.png ├── head.jpg ├── indishell.jpg ├── matrix2.gif ├── ssrf_lab.gif └── who.jpg ├── index.php ├── local.txt ├── pdf_generator ├── images │ ├── README.md │ ├── w1.png │ ├── w2.png │ ├── w3.png │ ├── w4.png │ ├── w5.png │ ├── wk1.png │ ├── wk2.png │ ├── wk3.png │ └── wk4.png ├── readme.md └── weasy.py ├── pdf_ssrf_weasyprint.php ├── pdf_ssrf_wkhtmltopdf.php ├── sql_connect.php └── xml_ssrf.php /Dockerfile: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/incredibleindishell/SSRF_Vulnerable_Lab/HEAD/Dockerfile -------------------------------------------------------------------------------- /Host_header/README.md: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/incredibleindishell/SSRF_Vulnerable_Lab/HEAD/Host_header/README.md -------------------------------------------------------------------------------- /Host_header/default: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/incredibleindishell/SSRF_Vulnerable_Lab/HEAD/Host_header/default -------------------------------------------------------------------------------- /Host_header/images/Nginx_config.png: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/incredibleindishell/SSRF_Vulnerable_Lab/HEAD/Host_header/images/Nginx_config.png -------------------------------------------------------------------------------- /Host_header/images/SSRF.png: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/incredibleindishell/SSRF_Vulnerable_Lab/HEAD/Host_header/images/SSRF.png -------------------------------------------------------------------------------- /Host_header/images/actual_request.png: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/incredibleindishell/SSRF_Vulnerable_Lab/HEAD/Host_header/images/actual_request.png -------------------------------------------------------------------------------- /Host_header/images/readme.md: -------------------------------------------------------------------------------- 1 | 2 | -------------------------------------------------------------------------------- /LICENSE.md: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/incredibleindishell/SSRF_Vulnerable_Lab/HEAD/LICENSE.md -------------------------------------------------------------------------------- /README.md: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/incredibleindishell/SSRF_Vulnerable_Lab/HEAD/README.md -------------------------------------------------------------------------------- /www/DNS Rebinding based Bypass/README.md: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/incredibleindishell/SSRF_Vulnerable_Lab/HEAD/www/DNS Rebinding based Bypass/README.md -------------------------------------------------------------------------------- /www/DNS Rebinding based Bypass/images/DNS_Rebinding_Attack_1.png: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/incredibleindishell/SSRF_Vulnerable_Lab/HEAD/www/DNS Rebinding based Bypass/images/DNS_Rebinding_Attack_1.png -------------------------------------------------------------------------------- /www/DNS Rebinding based Bypass/images/DNS_Rebinding_Attack_10.png: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/incredibleindishell/SSRF_Vulnerable_Lab/HEAD/www/DNS Rebinding based Bypass/images/DNS_Rebinding_Attack_10.png -------------------------------------------------------------------------------- /www/DNS Rebinding based Bypass/images/DNS_Rebinding_Attack_11.png: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/incredibleindishell/SSRF_Vulnerable_Lab/HEAD/www/DNS Rebinding based Bypass/images/DNS_Rebinding_Attack_11.png -------------------------------------------------------------------------------- /www/DNS Rebinding based Bypass/images/DNS_Rebinding_Attack_12.png: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/incredibleindishell/SSRF_Vulnerable_Lab/HEAD/www/DNS Rebinding based Bypass/images/DNS_Rebinding_Attack_12.png -------------------------------------------------------------------------------- /www/DNS Rebinding based Bypass/images/DNS_Rebinding_Attack_13.png: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/incredibleindishell/SSRF_Vulnerable_Lab/HEAD/www/DNS Rebinding based Bypass/images/DNS_Rebinding_Attack_13.png -------------------------------------------------------------------------------- /www/DNS Rebinding based Bypass/images/DNS_Rebinding_Attack_2.png: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/incredibleindishell/SSRF_Vulnerable_Lab/HEAD/www/DNS Rebinding based Bypass/images/DNS_Rebinding_Attack_2.png -------------------------------------------------------------------------------- /www/DNS Rebinding based Bypass/images/DNS_Rebinding_Attack_3.png: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/incredibleindishell/SSRF_Vulnerable_Lab/HEAD/www/DNS Rebinding based Bypass/images/DNS_Rebinding_Attack_3.png -------------------------------------------------------------------------------- /www/DNS Rebinding based Bypass/images/DNS_Rebinding_Attack_4.png: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/incredibleindishell/SSRF_Vulnerable_Lab/HEAD/www/DNS Rebinding based Bypass/images/DNS_Rebinding_Attack_4.png -------------------------------------------------------------------------------- /www/DNS Rebinding based Bypass/images/DNS_Rebinding_Attack_5.png: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/incredibleindishell/SSRF_Vulnerable_Lab/HEAD/www/DNS Rebinding based Bypass/images/DNS_Rebinding_Attack_5.png -------------------------------------------------------------------------------- /www/DNS Rebinding based Bypass/images/DNS_Rebinding_Attack_6.png: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/incredibleindishell/SSRF_Vulnerable_Lab/HEAD/www/DNS Rebinding based Bypass/images/DNS_Rebinding_Attack_6.png -------------------------------------------------------------------------------- /www/DNS Rebinding based Bypass/images/DNS_Rebinding_Attack_7.png: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/incredibleindishell/SSRF_Vulnerable_Lab/HEAD/www/DNS Rebinding based Bypass/images/DNS_Rebinding_Attack_7.png -------------------------------------------------------------------------------- /www/DNS Rebinding based Bypass/images/DNS_Rebinding_Attack_8.png: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/incredibleindishell/SSRF_Vulnerable_Lab/HEAD/www/DNS Rebinding based Bypass/images/DNS_Rebinding_Attack_8.png -------------------------------------------------------------------------------- /www/DNS Rebinding based Bypass/images/DNS_Rebinding_Attack_9.png: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/incredibleindishell/SSRF_Vulnerable_Lab/HEAD/www/DNS Rebinding based Bypass/images/DNS_Rebinding_Attack_9.png -------------------------------------------------------------------------------- /www/DNS Rebinding based Bypass/images/README.md: -------------------------------------------------------------------------------- 1 | 2 | -------------------------------------------------------------------------------- /www/DNS-Spoofing-based-Bypass/README.md: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/incredibleindishell/SSRF_Vulnerable_Lab/HEAD/www/DNS-Spoofing-based-Bypass/README.md -------------------------------------------------------------------------------- /www/DNS-Spoofing-based-Bypass/images/README.md: -------------------------------------------------------------------------------- 1 | 2 | -------------------------------------------------------------------------------- /www/DNS-Spoofing-based-Bypass/images/dns spoofing 1.png: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/incredibleindishell/SSRF_Vulnerable_Lab/HEAD/www/DNS-Spoofing-based-Bypass/images/dns spoofing 1.png -------------------------------------------------------------------------------- /www/DNS-Spoofing-based-Bypass/images/dns spoofing 2.png: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/incredibleindishell/SSRF_Vulnerable_Lab/HEAD/www/DNS-Spoofing-based-Bypass/images/dns spoofing 2.png -------------------------------------------------------------------------------- /www/DNS-Spoofing-based-Bypass/images/dns spoofing 3.png: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/incredibleindishell/SSRF_Vulnerable_Lab/HEAD/www/DNS-Spoofing-based-Bypass/images/dns spoofing 3.png -------------------------------------------------------------------------------- /www/DNS-Spoofing-based-Bypass/images/dns spoofing 4.png: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/incredibleindishell/SSRF_Vulnerable_Lab/HEAD/www/DNS-Spoofing-based-Bypass/images/dns spoofing 4.png -------------------------------------------------------------------------------- /www/DNS-Spoofing-based-Bypass/images/dns spoofing 5.png: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/incredibleindishell/SSRF_Vulnerable_Lab/HEAD/www/DNS-Spoofing-based-Bypass/images/dns spoofing 5.png -------------------------------------------------------------------------------- /www/DNS-Spoofing-based-Bypass/images/dns spoofing 6.png: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/incredibleindishell/SSRF_Vulnerable_Lab/HEAD/www/DNS-Spoofing-based-Bypass/images/dns spoofing 6.png -------------------------------------------------------------------------------- /www/DNS-Spoofing-based-Bypass/images/dns spoofing 7.png: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/incredibleindishell/SSRF_Vulnerable_Lab/HEAD/www/DNS-Spoofing-based-Bypass/images/dns spoofing 7.png -------------------------------------------------------------------------------- /www/File_Download/README.md: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/incredibleindishell/SSRF_Vulnerable_Lab/HEAD/www/File_Download/README.md -------------------------------------------------------------------------------- /www/File_Download/images/README.md: -------------------------------------------------------------------------------- 1 | 2 | -------------------------------------------------------------------------------- /www/File_Download/images/file_download_1.png: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/incredibleindishell/SSRF_Vulnerable_Lab/HEAD/www/File_Download/images/file_download_1.png -------------------------------------------------------------------------------- /www/File_Download/images/file_download_10.png: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/incredibleindishell/SSRF_Vulnerable_Lab/HEAD/www/File_Download/images/file_download_10.png -------------------------------------------------------------------------------- /www/File_Download/images/file_download_11.png: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/incredibleindishell/SSRF_Vulnerable_Lab/HEAD/www/File_Download/images/file_download_11.png -------------------------------------------------------------------------------- /www/File_Download/images/file_download_2.png: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/incredibleindishell/SSRF_Vulnerable_Lab/HEAD/www/File_Download/images/file_download_2.png -------------------------------------------------------------------------------- /www/File_Download/images/file_download_3.png: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/incredibleindishell/SSRF_Vulnerable_Lab/HEAD/www/File_Download/images/file_download_3.png -------------------------------------------------------------------------------- /www/File_Download/images/file_download_4.png: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/incredibleindishell/SSRF_Vulnerable_Lab/HEAD/www/File_Download/images/file_download_4.png -------------------------------------------------------------------------------- /www/File_Download/images/file_download_6.png: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/incredibleindishell/SSRF_Vulnerable_Lab/HEAD/www/File_Download/images/file_download_6.png -------------------------------------------------------------------------------- /www/File_Download/images/file_download_7.png: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/incredibleindishell/SSRF_Vulnerable_Lab/HEAD/www/File_Download/images/file_download_7.png -------------------------------------------------------------------------------- /www/File_Download/images/file_download_8.png: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/incredibleindishell/SSRF_Vulnerable_Lab/HEAD/www/File_Download/images/file_download_8.png -------------------------------------------------------------------------------- /www/File_Download/images/file_download_9.png: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/incredibleindishell/SSRF_Vulnerable_Lab/HEAD/www/File_Download/images/file_download_9.png -------------------------------------------------------------------------------- /www/Remote_host_connect_interface/README.md: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/incredibleindishell/SSRF_Vulnerable_Lab/HEAD/www/Remote_host_connect_interface/README.md -------------------------------------------------------------------------------- /www/Remote_host_connect_interface/images/MySQL_Connect_1.png: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/incredibleindishell/SSRF_Vulnerable_Lab/HEAD/www/Remote_host_connect_interface/images/MySQL_Connect_1.png -------------------------------------------------------------------------------- /www/Remote_host_connect_interface/images/MySQL_Connect_2.png: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/incredibleindishell/SSRF_Vulnerable_Lab/HEAD/www/Remote_host_connect_interface/images/MySQL_Connect_2.png -------------------------------------------------------------------------------- /www/Remote_host_connect_interface/images/MySQL_Connect_3.png: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/incredibleindishell/SSRF_Vulnerable_Lab/HEAD/www/Remote_host_connect_interface/images/MySQL_Connect_3.png -------------------------------------------------------------------------------- /www/Remote_host_connect_interface/images/MySQL_Connect_4.png: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/incredibleindishell/SSRF_Vulnerable_Lab/HEAD/www/Remote_host_connect_interface/images/MySQL_Connect_4.png -------------------------------------------------------------------------------- /www/Remote_host_connect_interface/images/MySQL_Connect_5.png: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/incredibleindishell/SSRF_Vulnerable_Lab/HEAD/www/Remote_host_connect_interface/images/MySQL_Connect_5.png -------------------------------------------------------------------------------- /www/Remote_host_connect_interface/images/MySQL_Connect_6.png: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/incredibleindishell/SSRF_Vulnerable_Lab/HEAD/www/Remote_host_connect_interface/images/MySQL_Connect_6.png -------------------------------------------------------------------------------- /www/Remote_host_connect_interface/images/MySQL_Connect_7.png: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/incredibleindishell/SSRF_Vulnerable_Lab/HEAD/www/Remote_host_connect_interface/images/MySQL_Connect_7.png -------------------------------------------------------------------------------- /www/Remote_host_connect_interface/images/README.md: -------------------------------------------------------------------------------- 1 | 2 | -------------------------------------------------------------------------------- /www/XML/images/README.md: -------------------------------------------------------------------------------- 1 | POC images for the vunerability demo. 2 | -------------------------------------------------------------------------------- /www/XML/sample_upload.xml: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/incredibleindishell/SSRF_Vulnerable_Lab/HEAD/www/XML/sample_upload.xml -------------------------------------------------------------------------------- /www/XML/ssrf_using_xxe.xml: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/incredibleindishell/SSRF_Vulnerable_Lab/HEAD/www/XML/ssrf_using_xxe.xml -------------------------------------------------------------------------------- /www/all.css: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/incredibleindishell/SSRF_Vulnerable_Lab/HEAD/www/all.css -------------------------------------------------------------------------------- /www/dns-spoofing.php: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/incredibleindishell/SSRF_Vulnerable_Lab/HEAD/www/dns-spoofing.php -------------------------------------------------------------------------------- /www/dns_rebinding.php: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/incredibleindishell/SSRF_Vulnerable_Lab/HEAD/www/dns_rebinding.php -------------------------------------------------------------------------------- /www/download.php: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/incredibleindishell/SSRF_Vulnerable_Lab/HEAD/www/download.php -------------------------------------------------------------------------------- /www/file_content_fetch/README.md: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/incredibleindishell/SSRF_Vulnerable_Lab/HEAD/www/file_content_fetch/README.md -------------------------------------------------------------------------------- /www/file_content_fetch/images/README.md: -------------------------------------------------------------------------------- 1 | 2 | -------------------------------------------------------------------------------- /www/file_content_fetch/images/file1.png: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/incredibleindishell/SSRF_Vulnerable_Lab/HEAD/www/file_content_fetch/images/file1.png -------------------------------------------------------------------------------- /www/file_content_fetch/images/file2.png: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/incredibleindishell/SSRF_Vulnerable_Lab/HEAD/www/file_content_fetch/images/file2.png -------------------------------------------------------------------------------- /www/file_content_fetch/images/file3.png: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/incredibleindishell/SSRF_Vulnerable_Lab/HEAD/www/file_content_fetch/images/file3.png -------------------------------------------------------------------------------- /www/file_content_fetch/images/file4.png: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/incredibleindishell/SSRF_Vulnerable_Lab/HEAD/www/file_content_fetch/images/file4.png -------------------------------------------------------------------------------- /www/file_content_fetch/images/file5.png: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/incredibleindishell/SSRF_Vulnerable_Lab/HEAD/www/file_content_fetch/images/file5.png -------------------------------------------------------------------------------- /www/file_content_fetch/images/file6.png: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/incredibleindishell/SSRF_Vulnerable_Lab/HEAD/www/file_content_fetch/images/file6.png -------------------------------------------------------------------------------- /www/file_get_content.php: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/incredibleindishell/SSRF_Vulnerable_Lab/HEAD/www/file_get_content.php -------------------------------------------------------------------------------- /www/head.php: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/incredibleindishell/SSRF_Vulnerable_Lab/HEAD/www/head.php -------------------------------------------------------------------------------- /www/images/README.md: -------------------------------------------------------------------------------- 1 | 2 | -------------------------------------------------------------------------------- /www/images/SSRF_Vulnerable_Lab.png: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/incredibleindishell/SSRF_Vulnerable_Lab/HEAD/www/images/SSRF_Vulnerable_Lab.png -------------------------------------------------------------------------------- /www/images/head.jpg: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/incredibleindishell/SSRF_Vulnerable_Lab/HEAD/www/images/head.jpg -------------------------------------------------------------------------------- /www/images/indishell.jpg: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/incredibleindishell/SSRF_Vulnerable_Lab/HEAD/www/images/indishell.jpg -------------------------------------------------------------------------------- /www/images/matrix2.gif: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/incredibleindishell/SSRF_Vulnerable_Lab/HEAD/www/images/matrix2.gif -------------------------------------------------------------------------------- /www/images/ssrf_lab.gif: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/incredibleindishell/SSRF_Vulnerable_Lab/HEAD/www/images/ssrf_lab.gif -------------------------------------------------------------------------------- /www/images/who.jpg: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/incredibleindishell/SSRF_Vulnerable_Lab/HEAD/www/images/who.jpg -------------------------------------------------------------------------------- /www/index.php: -------------------------------------------------------------------------------- https://raw.githubusercontent.com/incredibleindishell/SSRF_Vulnerable_Lab/HEAD/www/index.php -------------------------------------------------------------------------------- /www/local.txt: -------------------------------------------------------------------------------- 1 | This is just dummy text file xD