SSRF without impact is NOT a vulnerability

Поделиться
HTML-код
  • Опубликовано: 26 окт 2024

Комментарии • 11

  • @payloadartist
    @payloadartist 3 года назад +10

    Great video mate! Also I thought it might be worth mentioning that the definition of SSRF is a bit misleading on some sources such as Portswigger page, a lot of people refer to it. They use terms such as “inducing the server to make HTTP requests to arbitrary domain of attacker’s choosing“. I don’t quite agree to this the reason being the points you mentioned, attacker should be able to hit internal endpoints or access some part of network which is not reachable outside, say a cloud instance metadata endpoint. Maybe this is why a lot of people confuse this with SSRF.

  • @Matt0x00
    @Matt0x00 3 года назад +3

    Thank you! I finally have a video to send the "beg bounty" people.

  • @maratmkhitaryan9723
    @maratmkhitaryan9723 3 года назад +4

    3:26 actually it is. You can set up a squid proxy, allow only external ip requests. AFAIK many social networks use such proxies which limit the internal network access.

    • @LiveOverflow
      @LiveOverflow 3 года назад +1

      yeah true, you can do that for your app. My investigation was based on having a CTF challenge with RCE, and thus cannot block that kind of traffic

  • @larszii
    @larszii 3 года назад

    Does some have the Github Url with the Metadata Urls?

    • @tini_
      @tini_ 3 года назад +1

      2:01 you can see it there

  • @roarene317
    @roarene317 2 года назад

    It's actually similar to CVSS but without impact any CIA Triads. It's useless.
    It should be consider as CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:N which is again 0/10.

  • @shantanusharma5624
    @shantanusharma5624 3 года назад

    Hey @LiveUnderflow,
    please do a video on how to learn hacking technically.

    • @shantanusharma5624
      @shantanusharma5624 3 года назад

      @KushalThanks for the help but I've already seen this video of him millions of times

  • @preetiff8187
    @preetiff8187 3 года назад +4

    Love from india ❤️🇮🇳

  • @xar512
    @xar512 3 года назад

    I WAS LOOK ON THIS VULN AND I FOUND YOU MADE VEDIO LOL