
Proof-of-concept di exploit SSRF per CVE-2021-40438 che colpisce Apache mod_proxy. Script Python con supporto proxy per test controllati e dimostrazioni educative.
Nota: Inteso esclusivamente per scopi educativi e test controllati. Testare solo su sistemi per cui si ha l'autorizzazione.
░█▀▀░█░█░█▀▀░░░░░▀▀▄░▄▀▄░▀▀▄░▀█░░░░░░█░█░▄▀▄░█░█░▀▀█░▄▀▄
░█░░░▀▄▀░█▀▀░▄▄▄░▄▀░░█/█░▄▀░░░█░░▄▄▄░░▀█░█/█░░▀█░░▀▄░▄▀▄
░▀▀▀░░▀░░▀▀▀░░░░░▀▀▀░░▀░░▀▀▀░▀▀▀░░░░░░░▀░░▀░░░░▀░▀▀░░░▀░
# Utilizzo base
python3 exploit.py "http://vulnerable-site.com" "http://internal-service/"
# Con proxy (es. Burp Suite)
python3 exploit.py "http://vulnerable-site.com" "http://internal-service/" --proxy "http://127.0.0.1:8080"
url: L'URL target vulnerabilessrf: L'URL del servizio interno da recuperare-p, --proxy: (Opzionale) Proxy HTTP da utilizzare per il debug