Server-Side Request Forgery (SSRF)

intermediateWeb

TL;DR

Server-Side Request Forgery (SSRF) makes the server fetch a URL of the attacker’s choosing, often reaching internal systems the attacker can’t hit directly. The fix is to validate and allow-list where the server is allowed to go, and to lock down internal metadata endpoints.

Only test apps you’re authorised to test.

What it is

Lots of apps fetch URLs on your behalf — a “preview this link” feature, an image importer, a webhook. If the app takes a URL from the user and fetches it without restriction, an attacker can point it at internal addresses the app server can reach but they can’t.

How it works

The classic target is cloud metadata (for example 169.254.169.254) or internal services on localhost and private ranges. The attacker supplies an internal URL where an external one is expected, and the server dutifully makes the request and sometimes hands back the response.

How to test for it

How to fix it

Reference: OWASP A10: SSRF.

← Back to Web