What problem does it solve?
This Skill addresses the common gap in basic SSRF detection by providing expert-level techniques to exploit Server-Side Request Forgery vulnerabilities that are often missed during standard security assessments, including advanced filter bypasses, cloud metadata access, and full exploitation chains to compromise internal services.
Core Features & Use Cases
- Comprehensive SSRF Playbook: Covers URL filter bypass, protocol abuse (gopher, dict, file), blind SSRF detection, and chaining to RCE via internal services like Redis and Docker.
- Cloud Metadata Exploitation: Includes pre-built payloads for AWS, GCP, Azure, Alibaba Cloud, and Kubernetes metadata endpoints to steal credentials and sensitive cloud resources.
- Real-World CVE Chains: Provides step-by-step exploitation guides for public SSRF vulnerabilities including WebLogic SSRF (CVE-2014-4210) and Kubernetes SSRF (CVE-2020-8555/8562).
- Use Case: Use this Skill during authorized penetration tests of web applications that fetch remote URLs, cloud-hosted services, or internal network-facing applications to identify unauthorized access risks.
Quick Start
Use the ssrf-server-side-request-forgery skill to test the target application's URL input parameter for SSRF vulnerabilities, including checking for accessible cloud metadata endpoints and exposed internal services.