SSRF - Lab #3 SSRF with blacklist-based input filter | Short Version

Опубликовано: 15 Октябрь 2024
на канале: Rana Khalil
12,055
131

In this video, we cover Lab #3 in the SSRF module of the Web Security Academy. This application's stock check feature is vulnerable to SSRF. The developer has deployed two weak anti-SSRF defenses that will need to be bypassed. To solve the lab, we bypass the defenses and change the stock check URL to access the admin interface at http://localhost/admin and delete the user carlos.

▬ ✨ Support Me ✨ ▬▬▬▬▬▬▬▬▬▬
Buy my course: https://bit.ly/30LWAtE

▬ 🔗 Links 🔗 ▬▬▬▬▬▬▬▬▬▬
Python script: https://github.com/rkhal101/Web-Secur...
Notes.txt document: https://github.com/rkhal101/Web-Secur...
Web Security Academy Exercise Link: https://portswigger.net/web-security/...
Rana's Twitter account:   / rana__khalil