← All concepts
Server-side request forgery (SSRF)

Understanding Server-side request forgery

What it is

Server-side request forgery is coercing a server into making a request on your behalf. When a feature fetches a URL you supply — a webhook, an image importer, a link preview — and does not constrain where it may go, you can point it at internal services the network trusts and reach things the internet cannot.

How you approach it

  1. Which feature takes a URL and does something with what it finds there? Point it at a URL you can watch first, to confirm the server really fetches it.
  2. Now point it inward. Internal services often live on private ranges or on localhost — what would the metadata or admin endpoint be?
  3. The flag is served by an endpoint only something inside the network can reach. Make the server ask for it and read what comes back.

How it gets fixed

The fetcher followed any URL it was given, so aiming it at an internal address made the server retrieve a resource the outside world cannot. The response — flag included — came back through the feature's own output. The fix is an allowlist of destinations and a refusal to follow redirects into private ranges.

Practise it

Every lab in the Server-side request forgery (SSRF) category drills exactly this. Start at Apprentice and work up.

Practise it

PractitionerServer-side request forgery (SSRF)

The link-preview that fetches anything

Make the server fetch a URL of your choosing, from inside its network.

25 pts · 45 minStart →
PractitionerServer-side request forgery (SSRF)

An image importer aimed inward

Make the server fetch a URL of your choosing, from inside its network.

25 pts · 45 minStart →
PractitionerServer-side request forgery (SSRF)

A webhook tester pointed at localhost

Make the server fetch a URL of your choosing, from inside its network.

25 pts · 45 minStart →
ExpertServer-side request forgery (SSRF)

Reaching the cloud metadata endpoint

Make the server fetch a URL of your choosing, from inside its network.

50 pts · 90 minStart →
ExpertServer-side request forgery (SSRF)

Blind SSRF confirmed out of band

Make the server fetch a URL of your choosing, from inside its network.

50 pts · 90 minStart →
ExpertServer-side request forgery (SSRF)

Bypassing an allowlist with a DNS trick

Make the server fetch a URL of your choosing, from inside its network.

50 pts · 90 minStart →