Case 57A936 · Web AppSec · L3 Applied
Server-Side Request Forgery
Practise as: Explain it · Interview · Deep dive
Interview questionExplain SSRF and why it is so dangerous in cloud environments.
- 01 What is it?
- 02 How is it abused?
- 03 How do you stop it?
What a strong answer covers
Try it out loud first. Then check yourself:
- SSRF makes the server fetch an attacker-chosen URL, reaching internal-only services from a trusted network position
- Cloud impact: 169.254.169.254 metadata returns IAM role credentials; IMDSv2 session tokens blunt simple GET SSRF
- Blocklists fail: decimal/IPv6 encodings, DNS rebinding, open redirects, and gopher:// or file:// schemes
- Fix: allowlist destinations, resolve DNS once and validate the IP, block private ranges, disable redirects
- Network-level egress control: route fetchers through a proxy with no path to metadata or internal subnets
If the interviewer pushes back
- How does DNS rebinding bypass a check that validates the resolved IP before fetching?
- What is blind SSRF and how would you prove exploitability without seeing responses?
Go deeper
cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.