SSRF
Server Side Request Forgery: Methodology, payloads, tools

Detection - Vulnerable Parameters
Basic payload
Paylod List
SSRF to LFI
File Inclusion LFI / RFIFinding SSRF with Burp

Port scan

Filter Bypass
Decimal notation
Other notation

IP encoding
Use your own server to redirect on localhost


DNS Rebinding


More payloads
Cloud Metadata IP
URL / Host Validation Bypass

Bypassing protocol whitelists
URL Schemes
Gopher
Blind SSRF with OOB
Exploit Blind SSRF with OOB Techniques - TCM SecurityTCM Security - Penetration Testing & ConsultingPlatform to receive HTTP & DNS callbacks for SSRF (Blind) - interactsh
SSRF (XSS) in PDF Generator
XSSPDF Generator - SSRF in .NET Application to RCE
NextJS apps
Next.js / ReactTools
SSRFmap
Autossrf
0dSSRF
SSRFPwned
Interesting Books
Interesting BooksSupport this Gitbook
Resources
Last updated

