Server Side Request Forgery (SSRF)

What You Need To Know About  Server Side Request Forgery (SSRF)

SSRF or Server Side Request Forgery is an attack vector that has been around for a long time, but do you actually know what it is?



"Server-Side Request Forgery (SSRF) refers to an attack wherein an attacker is able to send a crafted request from a vulnerable web application. SSRF is usually used to target internal systems behind firewalls that are normally inaccessible to an attacker from the external network".

There are various things you can use SSRF for such as:


  • Scanning other machines within the private network of the vulnerable server that aren’t externally accessible
  • Performing Remote File Inclusion (RFI) attacks
  • Bypassing firewalls and use the vulnerable server to carry out malicious attacks
  • Retrieving server files (including /etc/password etc)
Read more about Acunetix here: Click Here

Comments

Popular posts from this blog

CAREER TECHNOLOGY CYBER SECURITY INDIA PVT LTD.

Cyber Security Audits

Some Dark web Links