Web Ssrf

Server-Side Request Forgery detection→internal-access→proof for web apps. Use when the app fetches a URL you influence (webhooks, url/image/pdf fetchers, link preview, import-from-URL, SSO/OIDC redirect, XML/SVG). Triggers - url=/uri=/dest=/callback= param, "fetch failed", webhook, image proxy, /_next/image, remotePatterns, redirect.

s0ld13rr Updated

File contents

s0ld13rr/pentestcode/tree/main/skills/web/ssrf commit 24dfbf3fde

Frequently asked questions

npx skillmds@latest add s0ld13rr/web-ssrf