SHUNYAX LABS // SECURITY SCANNING HUB
NANDIX
Nothing passes without inspection. Paste your API endpoint and scan it for SSRF vulnerabilities — instant grade and fix recommendations.
9 VECTORS · 6 CATEGORIES
Cloud Metadata
AWS / GCP / Azure instance metadata endpoints
Internal Network
Loopback, private ranges, IPv6
Scheme Abuse
file://, gopher://, dict://
Bypass Techniques
Decimal / hex / octal IPs, encoding, @-bypass
Redirect Chain
Open redirects into internal hosts
DNS Rebinding
Hostnames resolving to loopback