../web

// web · 01 / 08

SSRF

Make the server fetch

Practice this only on a lab you own, or a program whose scope you have read.

Server-side request forgery is when the application fetches an address the caller chose.

The impact can be an internal system the caller could not reach directly. Allow a list of hosts, and do not pass raw user URLs through.

// lab

// check yourself

SSRF is dangerous mainly because…

Advanced web attacks — Prashant Dangi