SecurityCipher
Home Blog About Us

Learn Paths, courses, and reference docs

  • ๐Ÿš€ Start Here Beginner path through the site
  • ๐Ÿ—บ๏ธ Penetration Testing Roadmap Structured path to become a pentester
  • ๐ŸŽ“ Free Security Courses Current free Udemy coupon listings
  • ๐Ÿ“„ Secure Code Explain Vulnerable vs secure code side by side
  • ๐ŸŽฏ Penetration Testing Tricks Field notes for real engagements
  • ๐Ÿ“– Vulnerability Explain How common vulns actually work

Checklists Interactive reviews and LLM risks

  • โœ… Security Checklists Hub All interactive security checklists
  • ๐Ÿ“‹ Writeup Checklists Steps derived from real writeups
  • ๐Ÿง  LLM AI Security Checklist Controls for LLM apps
  • ๐Ÿค– OWASP LLM Top 10 LLM Top 10 risks mapped out
  • ๐Ÿงฐ Burp Suite Guide Step-by-step Burp tutorials
  • ๐Ÿ“˜ Payload Field Manual Safe-first probes and signals

Practice Browser labs, games, and explorers

  • ๐Ÿ”ฌ Interactive Labs SQL injection, AI, architecture review
  • ๐ŸŽฎ Security Games Phishing, JWT, WAF, and more
  • ๐Ÿš— On-Call Drive Neon-city arcade security missions
  • โ€ข Shift Zero SOC desk: phish, OTP, malware, tickets
  • โ“ Application Security Quiz Web, secure coding, and cloud quizzes
  • ๐Ÿ—บ๏ธ OWASP Top 10 Explorer Clickable risk map with signals
  • ๐Ÿ”€ Interactive Attack Paths Recon-to-impact chains

Tools & Career Databases, jobs, and community

  • ๐Ÿ› ๏ธ Security Tools Curated recon, SAST, and bounty tools
  • ๐Ÿ”Ž CVE Lookup Multi-source CVE intelligence
  • ๐Ÿ’ฐ Bug Bounty Programs Live public scopes to search
  • ๐Ÿ’ผ Cybersecurity Jobs Roles from company career pages
  • ๐Ÿง‘โ€๐Ÿ’ป Security Researchers Community profiles and submissions
  • ๐ŸŽค Security Conferences Upcoming and past events
Browse all Security resources hub Freelance Security โ†’
My Resume
Freelance SecurityFreelance
New Security Researchers Join the directory - submit your profile for review Submit profile โ†’
← Security Tools View on GitHub

ssrfDetector

Server-side request forgery detector

SSRF Detector

This is the application source code for the SSRF Detector website. The website has been EOL as of April 7th 2017, but the code has been updated to be run on a local machine. This documentation is a little touch-and-go as there is a lot of configuration for Nginx, SSL, etc... but for a local instance it can be run as-is.

Setup

Setting up the application is pretty easy. The following things will be needed:

  • Mailgun API key
  • Google Recaptcha site/private keys
  • Blinkie API key (create this yourself and set in core/Dockerfile as well as blinkie/Dockerfile)
  • Session secret (any >24 character random string)

These will be set in core/Dockerfile as environmental variables.

For the actual website these variables were set at runtime, as it is not secure to store these in files. These were fed in at runtime using RancherOS which is a great container management platform (among other things). RancherOS also helped secure the databases, that is why there is no DB auth set up in this instance.

Nginx

I used Nginx as a personal preference, but any web server will do. Nginx was used to route the proper domain names to the ports. This app works best when set up with Nginx server blocks to forward ssrfdetector.com:443 -> localhost:3000 and blinkie.xyz:80/443 -> localhost:3001. Otherwise the lack of hostnames can cause issues with Blinkie's reporting.

Ports

IP Tables rules will need to be made to forward a range of ports to the Blinkie application, so that it can detect requests outside of just ports 80 and 443. There currently is no DNS detection, but I would love if someone made a pull request to add that. Be careful when opening ports, MongoDB is run on port 27017 and should not be open to the public.

Ratelimiting

There will need to be a cronjob set up to run the blinkie/resetRateLimits.js NodeJS file. This can be set up easily and I ran it once a day to reset the ratelimits.

Local use

For local use add an entry into the /etc/hosts file for '127.0.0.1 a.blinkie.xyz' and register 'a' as the subdomain. Then http://a.blinkie.xyz:3001 can be used to trigger a request. The 3001 can be left off if a proper Nginx file is setup.

Running

Install docker-compose then run docker-compose build; docker-compose up;. The up command may have to be run twice, as docker-compose sometimes launches the NodeJS app before Mongo is done initializing. In that case run docker-compose down; docker-compose up;

The SSRF Detector website will be hosted on http://localhost:3000 and the Blinkie server will be run on http://localhost:3001. Note: the Blinkie server needs to be accessed by a domain name, otherwise it will not know which subdomain to report for.

Thanks!

Thanks for checking out SSRF Detector, it's been a fun project to help me learn more about Docker and MongoDB. If you find any issues or have any questions please feel free to create an Issue, or email me at jreynoldsdev@gmail.com.

Press Escape to close the search panel.

Donate

Buy me a Coffee

Penetration Testing Services

penetration Testing Services

Web Application Security Quiz

Web Application Security Quiz

Daily Bug Bounty Writeups - Twitter

Daily Bug Bounty Writeups

Download our Latest Android Application

Guide for Penetration Testing

Daily Bug Bounty Writeups - Telegram

Daily Bug Bounty Writeups

Author

Piyush
Senior Product Security Engineer

Ethical Hacker || Penetration Tester || Gamer || Blogger || Product Security Engineer || AI Security

READ ARTICLE

Donate

Buy me a Coffee

Recent Posts

  • AI-Generated Code Security Bugs: A Vibe Coding Case Study
    AI-Generated Code Security Bugs: A Vibe Coding Case Study
    October 7, 2026/
    0 Comments
  • Cloud Misconfig Bounty Hunting in 2026: Open Buckets, Firebase, and Secrets
    Cloud Misconfig Bounty Hunting in 2026: Open Buckets, Firebase, and Secrets
    September 8, 2026/
    0 Comments
  • DevSecOps From Laptop to Production: A Practical Security Pipeline Guide
    DevSecOps From Laptop to Production: A Practical Security Pipeline Guide
    August 27, 2026/
    0 Comments

Follow Us

SecurityCipher

Practical security guides, vulnerability deep-dives, and hands-on resources for bug bounty hunters and penetration testers.

Useful Links

  • Security Checklists
  • Cybersecurity Jobs
  • Blogs
  • About
  • Contact
ยฉ 2026 Security Cipher. All rights reserved. Privacy Policy ยท Terms & Conditions