20–30 min Updated

Server-Side Request Forgery

By Malcolm McDonald Founder, Editor-in-ChiefAuthor of Grokking Web Application Security

An attacker can use SSRF vulnerabilities to probe your internal network.

Prevalence
Common
Exploitability
Easy
Impact
Harmful

What is server-side request forgery (SSRF)?

Server-side request forgery (SSRF) is a request forgery attack in which an attacker causes your server to make an HTTP request to a destination they choose, usually by supplying a URL the server fetches. Because the request originates inside your network, it can reach internal services and cloud metadata endpoints that are hidden from the internet.

What you'll learn

  • How a URL-fetching feature lets attackers send requests from your server
  • Why requests from inside your network can reach internal services
  • How to validate and restrict the URLs your server will fetch

Where this lesson counts

OWASP Top 10

  • Server-Side Request Forgery lab

    A social site fetches a preview for every link its users share. See how an attacker uses that feature to make your server send requests of their choosing: flooding a third party from behind your address, or probing private IP addresses on your internal network.

  • How to prevent Server-Side Request Forgery

    The prevention guide covers five approaches:

    • Construct The Domains Of URLs On The Server
    • Disable External Validation URLs
    • Only Make Outgoing HTTP Calls On Behalf of Real Users
    • Validate The URLs You Do Access
    • Keep A Blocklist
  • Server-Side Request Forgery quiz

    Three questions. Passing marks the lesson complete.

Sources

  • Host Header Poisoning

    It's dangerous to rely on the value supplied in the Host header of an HTTP request.

  • Open Redirects

    Most web-applications make use of redirects. If your site forwards to URLs supplied in a query string, you could be enabling phishing attacks.

  • XML External Entities

    Unsafe treatment of external references in XML allows an attacker to probe your file system for sensitive information.

  • Broken Access Control

    All resources on your site need to have access control implemented, even if they aren't intended to be discoverable by a user.