Workspace IndexDev Notes › SSRF — making the server fetch the URL you chose

#182PoC

SSRF — making the server fetch the URL you chose

Server-side request forgery tricks a backend into requesting an attacker-chosen URL, reaching internal metadata endpoints and cloud credentials — the class behind several large cloud breaches.

Not yet scoped.

Why

The PoC demonstrates SSRF reaching a mock metadata service and the allowlist/egress controls that close it, connecting to the edge-jurisdiction cards' request-layer theme.

How it works

Not yet built.

← All Dev Notes · Workspace Index · Top ↑

SSRF — 서버가 내가 고른 URL을 가져오게 하기

서버측 요청 위조는 백엔드가 공격자가 고른 URL을 요청하도록 속여 내부 메타데이터 엔드포인트와 클라우드 자격증명에 닿습니다 — 여러 대형 클라우드 침해 뒤의 계급입니다.

아직 범위 미정.

이 PoC는 모의 메타데이터 서비스에 닿는 SSRF와 이를 막는 허용목록/이그레스 통제를 시연하며, 엣지-법역 카드들의 요청 계층 주제로 연결합니다.

동작 방식

아직 만들지 않음.

← 전체 개발 노트 · 워크스페이스 인덱스 · 맨 위 ↑