logo

How To: Server-Side Request Forgery (SSRF)

ID: 462aab72-2491-5653-8f3a-f31793c74a4e

STIX ID: report--462aab72-2491-5653-8f3a-f31793c74a4e

Feed Name: HackerOne Blog

Threat Score
70/100

Date Published: 2023-09-15

Date Updated: 2026-06-11

...
...

This blog post explains Server-Side Request Forgery (SSRF): how it arises, how to test for it, practical exploitation techniques (including redirects, protocol pivots, and using internal services), and the typical impact such as internal service exposure, port scanning, and retrieval of EC2 instance metadata. It includes runnable examples, testing tips (netcat listener, timing-based discovery), common vulnerable features (webhooks, PDF generators, link expansion, file uploads), mitigation pitfalls (host blacklists, redirect handling), and suggested offensive pivots to increase impact.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.