// web · 01 / 08
SSRF
Make the server fetch
Practice this only on a lab you own, or a program whose scope you have read.
Server-side request forgery is when the application fetches an address the caller chose.
The impact can be an internal system the caller could not reach directly. Allow a list of hosts, and do not pass raw user URLs through.
// lab
// check yourself
SSRF is dangerous mainly because…