Web Security / Injection
Lesson 12 of 27
Server-side request forgery (SSRF)
If a server fetches any URL a user gives it, attackers can make it request internal-only addresses. Restrict destinations to an allow-list.
Key points
- Allow-list domains the server may fetch
- Block internal IP ranges
- Don't return raw responses
Quiz · +10 XP
What's the best defence against SSRF?
Log in to save progress and earn XP.