Understanding Server-side request forgery
What it is
Server-side request forgery is coercing a server into making a request on your behalf. When a feature fetches a URL you supply — a webhook, an image importer, a link preview — and does not constrain where it may go, you can point it at internal services the network trusts and reach things the internet cannot.
How you approach it
- Which feature takes a URL and does something with what it finds there? Point it at a URL you can watch first, to confirm the server really fetches it.
- Now point it inward. Internal services often live on private ranges or on localhost — what would the metadata or admin endpoint be?
- The flag is served by an endpoint only something inside the network can reach. Make the server ask for it and read what comes back.
How it gets fixed
The fetcher followed any URL it was given, so aiming it at an internal address made the server retrieve a resource the outside world cannot. The response — flag included — came back through the feature's own output. The fix is an allowlist of destinations and a refusal to follow redirects into private ranges.
Practise it
Every lab in the Server-side request forgery (SSRF) category drills exactly this. Start at Apprentice and work up.