Lazo Lab Sign up

Web Security / Injection

Lesson 12 of 27

Server-side request forgery (SSRF)

If a server fetches any URL a user gives it, attackers can make it request internal-only addresses. Restrict destinations to an allow-list.

Key points

  • Allow-list domains the server may fetch
  • Block internal IP ranges
  • Don't return raw responses
Watch a video on thisOpens YouTube search results for “Server-side request forgery (SSRF)” in a new tab

Quiz · +10 XP

What's the best defence against SSRF?

Log in to save progress and earn XP.