Why
The PoC demonstrates SSRF reaching a mock metadata service and the allowlist/egress controls that close it, connecting to the edge-jurisdiction cards' request-layer theme.
How it works
Not yet built.
Workspace Index › Dev Notes › SSRF — making the server fetch the URL you chose
#182PoC
Server-side request forgery tricks a backend into requesting an attacker-chosen URL, reaching internal metadata endpoints and cloud credentials — the class behind several large cloud breaches.
The PoC demonstrates SSRF reaching a mock metadata service and the allowlist/egress controls that close it, connecting to the edge-jurisdiction cards' request-layer theme.
Not yet built.
서버측 요청 위조는 백엔드가 공격자가 고른 URL을 요청하도록 속여 내부 메타데이터 엔드포인트와 클라우드 자격증명에 닿습니다 — 여러 대형 클라우드 침해 뒤의 계급입니다.
이 PoC는 모의 메타데이터 서비스에 닿는 SSRF와 이를 막는 허용목록/이그레스 통제를 시연하며, 엣지-법역 카드들의 요청 계층 주제로 연결합니다.
아직 만들지 않음.