Skip to main content
在 Manus 中运行任何 Skill
一键导入
$pwd:

ssrf-to-internal-service-breach

// Escalate a suspected or confirmed Server-Side Request Forgery into proof of internal-service access — cloud metadata, internal-only APIs, database greetings, or redacted-but-fetchable HTTP. Use when a parameter takes a URL (image proxy, webhook, fetcher, URL preview, PDF render) and the server reaches outbound on your behalf, or when an audit finding tags CWE-918. Confirms reachability via OAST, then walks targeted internal endpoints, ending with a finding sized by the highest-value asset reached.

$ git log --oneline --stat
stars:586
forks:90
updated:2026年5月23日 16:43
SKILL.md
readonly