Exploiting Ssrf

Find and exploit server-side request forgery — reaching cloud instance metadata on AWS IMDSv1/IMDSv2, Azure IMDS, and GCP, internal service discovery, filter and allowlist bypasses via DNS rebinding, redirects, and encoding, and blind SSRF confirmation out of band. Use when an application fetches a URL supplied by the user, when testing webhooks, importers, PDF or screenshot renderers, or when reviewing outbound HTTP calls in source.

trilwu 9e45f11 9.7 KB Updated

File contents

trilwu/secskills/tree/main/secskills-offense/skills/exploiting-ssrf commit 9e45f11769

Frequently asked questions

npx skillmds add trilwu/exploiting-ssrf