Blind SSRF with OAST
Confirm a suspected server-side URL fetch with a unique, callback-only endpoint you control. Use one request at a time, record the parameter and correlation ID, and stop after proof of fetch.
Tags: ssrf, oast, blind, authorized-testing
Controlled probes
https://UNIQUE-CALLBACK.example/ssrf/preview-001Use a fresh identifier for every parameter and redirect hopRecord DNS, HTTP, timestamp, and source-IP evidence; do not probe internal services
Source: https://owasp.org/www-community/attacks/Server_Side_Request_Forgery