Skip to content
ssrfuzz exploit

ssrfuzz exploit

Sploitus • September 17, 2026

![](

SSRFuzz is a tool to find Server Side Request Forgery vulnerabilities, with CRLF chaining capabilities

* I wanted to write a tool in Golang for concurrency

* I wanted to fuzz parameters for SSRF vulnerablities, as well as fuzz _both_ paths and parameters for CRLF injections

* I was inspired by Orange's work for chaining these types of vulnerabilities together (

██████ ██████ ██▀███ █████▒█ ██ ▒███████▒▒███████▒

▒██ ▒ ▒██ ▒ ▓██ ▒ ██▒▓██ ▒ ██ ▓██▒▒ ▒ ▒ ▄▀░▒ ▒ ▒ ▄▀░

░ ▓██▄ ░ ▓██▄ ▓██ ░▄█ ▒▒████ ░▓██ ▒██░░ ▒ ▄▀▒░ ░ ▒ ▄▀▒░

▒ ██▒ ▒ ██▒▒██▀▀█▄ ░▓█▒ ░▓▓█ ░██░ ▄▀▒ ░ ▄▀▒ ░

▒██████▒▒▒██████▒▒░██▓ ▒██▒░▒█░ ▒▒█████▓ ▒███████▒▒███████▒

▒ ▒▓▒ ▒ ░▒ ▒▓▒ ▒ ░░ ▒▓ ░▒▓░ ▒ ░ ░▒▓▒ ▒ ▒ ░▒▒ ▓░▒░▒░▒▒ ▓░▒░▒

░ ░▒ ░ ░░ ░▒ ░ ░ ░▒ ░ ▒░ ░ ░░▒░ ░ ░ ░░▒ ▒ ░ ▒░░▒ ▒ ░ ▒

░ ░ ░ ░ ░ ░ ░░ ░ ░ ░ ░░░ ░ ░ ░ ░ ░ ░ ░░ ░ ░ ░ ░

░ ░ ░ ░ ░ ░ ░ ░

===============================================================

===============================================================A scanner for all your SSRF Fuzzing needs

-b, --call-back string Add callback for SSRF fuzzing (ie:

-c, --cookie string Cookie to use for requests

--crlf-path Add CRLF payloads to all available paths (ie: site.com/%0Atest.php)

--delay int The time each threads waits between requests in milliseconds (default 100)

-d, --domains string Location of domains with parameters to scan

-h, --help help for scan

-x, --http-method string HTTP Method - GET or POST (default "GET")

-o, --output string Location to save results

--skip-crlf Skip CRLF fuzzing

--skip-network Skip network fuzzing

--skip-scheme Skip scheme fuzzing

-s, --slack-webhook string Slack webhook to send findings to a channel

-t, --threads int Number of threads to run ssrfuzz on (default 50)

--timeout int The amount of time needed to close a connection that could be hung (default 10)

-u, --user-agent string User agent for requests (default "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.138 Safari/537.36")

-v, --verbose verbose output

* Scanning http and scheme payloads w/ crlf:

echo " | go run main.go scan

* 200

* 200

* 500

* 500

* 500

* 500

* 500

* 200

* %OA 200

* 500

* 500

echo " | go run main.go scan --skip-scheme

* 200

* 200

* 500

* 500

* 500

* 500

* 500

* 500

* 500

* 500

* 500

* htt p://192.168.1.10/test.php?u= 500

echo " | go run main.go scan --skip-scheme --skip-crlf

* 200

* 500

* 500

* 500

* 500

* 500

* Scanning only scheme payloads w/o crlf:

echo " | go run main.go scan --skip-network --skip-crlf

* 200

* 500

* 500

Pull requests are welcome. For major changes, please open an issue first to what you would like to change.

Please make sure to update tests as appropriate.

Extracted Entities

Domains (1)