Web Hack List

Other nomination

Blind SSRF exploitation

A field guide to exploiting server-side request forgery when no response comes back: brute-forcing basic auth through credentials in the URL, timing anomalies to map internal hosts and ports, multiple DNS A records and rebinding services to defeat internal-IP checks and scan ports, and redirects to switch protocol to file or gopher.

Record

Researcher
@bo0om
Published by
Wallarm
Date

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of @bo0om, first published at the original source. Preserved copies are kept so the citation survives its host.