SSRF
URL Schemes
Scheme
Use Case
Confirm SSRF
# Start listener
nc -lnvp 8000
# Inject your URL in vulnerable parameter
http://YOUR_IP:8000/ssrfInternal Port Scan
Generate Ports Wordlist
Fuzz Open Ports
Enumerate Internal Endpoints
Local File Inclusion via SSRF
Gopher Protocol (Send POST Requests)
Manual Gopher URL
Gopherus (Generate Gopher URLs)
Blind SSRF
Detect Open Ports (Blind)
SSRF Bypass Techniques
Localhost Alternatives
URL Encoding
Double URL Encoding
Decimal IP
Hex IP
DNS Rebinding
Cloud Metadata Endpoints
AWS
GCP
Azure
Common SSRF Parameters
Last updated