Let's talk about your project

Server-side request forgery

SSRF · A flaw that lets an attacker make the server itself send requests to an address of their choice, often to reach internal systems that cannot be accessed from outside.

  1. 01

    Why it matters

    Features that fetch an image from a URL, build link previews or call another service can be open to SSRF. Because the server sits inside the internal network, it can reach admin panels, databases or the cloud environment's service that hands out secret keys. Requests should go only to allowed addresses, with internal addresses blocked.

  2. 02

    Example

    An app downloads a profile picture from a URL the user provides. The attacker enters the cloud server's internal metadata address and sees the server's access keys in the response.

  3. 03

    Common mistake

    Checking only the URL text. A domain can resolve to an internal address after the check or redirect to one; the resolved IP address must be checked too and the connection pinned to it.

  4. 04
Let's begin

Let's talk about your project.

Tell us what you need; we will define the scope together.