ssrf-methodology

Installation
SKILL.md

SSRF 攻击方法论

深入参考


Phase 1: 发现 SSRF 入口

参数名线索(高度可疑): url, uri, path, src, dest, redirect, callback, next, data, reference, site, html, imageUrl, feed, target, proxy, link

功能线索:URL 预览、PDF/图片生成(wkhtmltopdf, puppeteer)、Webhook、远程图片获取、RSS 导入

Phase 2: 基础 SSRF 验证

Related skills

More from wgpsec/aboutsecurity

Installs
6
GitHub Stars
1.3K
First Seen
Apr 22, 2026