RSSAmplifier

Posts on jub0bs.com · Jun 22, 2020

Leveraging an SSRF to leak a secret API key

0
Sign in to vote or save

This site does not allow itself to be embedded. You can still read it on the original site — the toolbar below keeps your place in the directory.

A server-side request forgery (SSRF) is a type of vulnerability that consists in tricking a server into sending network requests to unintended hosts. In some cases (e.g. Scott Helme ’s Security Headers tool ), allowing users to trigger HTTP requests from some backend to arbitrary hosts is a feature. In many other cases, though, it is a serious security bug that may enable attackers to wreak…

Read on //jub0bs.com/posts/2020-06-23-ssrf/

Comments

Nothing yet. Say the first thing.

    Sign in to join the conversation.