Server-Side Request Forgery (SSRF)

How attackers turn a harmless server-side URL fetcher into a portal straight into your VPC. Every SSRF variant: cloud metadata exfiltration (the Capital One playbook), URL parser bypasses, blind detection via OOB and timing, DNS rebinding TOCTOU attacks, protocol smuggling with gopher/file/dict, and the six-layer defence model.

Related Articles