Open cardosec

Case 57A936 · Web AppSec · L3 Applied

Server-Side Request Forgery

Practise as: Explain it · Interview · Deep dive

Interview questionExplain SSRF and why it is so dangerous in cloud environments.

  1. 01 What is it?
  2. 02 How is it abused?
  3. 03 How do you stop it?
What a strong answer covers

Try it out loud first. Then check yourself:

  1. SSRF makes the server fetch an attacker-chosen URL, reaching internal-only services from a trusted network position
  2. Cloud impact: 169.254.169.254 metadata returns IAM role credentials; IMDSv2 session tokens blunt simple GET SSRF
  3. Blocklists fail: decimal/IPv6 encodings, DNS rebinding, open redirects, and gopher:// or file:// schemes
  4. Fix: allowlist destinations, resolve DNS once and validate the IP, block private ranges, disable redirects
  5. Network-level egress control: route fetchers through a proxy with no path to metadata or internal subnets

If the interviewer pushes back

  • How does DNS rebinding bypass a check that validates the resolved IP before fetching?
  • What is blind SSRF and how would you prove exploitability without seeing responses?

Go deeper

cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.