Ssrf To Internal Service Breach

Escalate a suspected or confirmed Server-Side Request Forgery into proof of internal-service access — cloud metadata, internal-only APIs, database greetings, or redacted-but-fetchable HTTP. Use when a parameter takes a URL (image proxy, webhook, fetcher, URL preview, PDF render) and the server reaches outbound on your behalf, or when an audit finding tags CWE-918. Confirms reachability via OAST, then walks targeted internal endpoints, ending with a finding sized by the highest-value asset reached.

vigolium Updated

File contents

vigolium/vigolium/tree/main/internal/resources/olium/skills/ssrf-to-internal-service-breach commit 885acfc5ff

Frequently asked questions

npx skillmds@latest add vigolium/ssrf-to-internal-service-breach