Payload class · ssrf

Blind SSRF OAST Probes

One-destination callback probes for blind server-side fetch behavior. Give direct, parser, and redirect hypotheses separate unique tokens. Keep every request on a controlled listener and do not use internal, link-local, metadata, or third-party destinations.

ssrfblindoastdnshttp
Stable IDpayload:blind-ssrf-oastSource record dateHuman reviewNot recordedProvenanceSource-linked

Use as a detection primitive

One-destination callback probes for blind server-side fetch behavior. Give direct, parser, and redirect hypotheses separate unique tokens. Keep every request on a controlled listener and do not use internal, link-local, metadata, or third-party destinations.

Do not copy blind

Identify the parser, sink, encoding, and expected non-vulnerable behavior before choosing a sample. Prefer non-destructive markers.

Private OAST contract

Use one readable case ID plus a random opaque suffix for every request, field, and variant. Keep one unsubmitted ambient-noise token. Put no secrets or target data in labels, paths, or queries. Redact at ingestion, never publish raw callback logs, and clean up controlled records after sufficient proof.

Recorded payloads

Detection sampleAuthorization required

Confirm the sink and encoding context before use.

https://ssrf017-direct.UNIQUE.oast.example/probe
Expected signal
Not verified for this generic template. Confirm the exact tool version and expected output in its official documentation before use.
Negative control
Define a known-safe or nonexistent target that should produce a meaningfully different result.
Effect and bounds
Unknown until flags and target are reviewed. Assume the command sends traffic or changes local state unless the tool documentation proves otherwise.
Detection sampleAuthorization required

Confirm the sink and encoding context before use.

http://ssrf017-http.UNIQUE.oast.example/probe
Expected signal
Not verified for this generic template. Confirm the exact tool version and expected output in its official documentation before use.
Negative control
Define a known-safe or nonexistent target that should produce a meaningfully different result.
Effect and bounds
Unknown until flags and target are reviewed. Assume the command sends traffic or changes local state unless the tool documentation proves otherwise.
Detection sampleAuthorization required

Confirm the sink and encoding context before use.

//ssrf017-scheme-relative.UNIQUE.oast.example/probe
Expected signal
Not verified for this generic template. Confirm the exact tool version and expected output in its official documentation before use.
Negative control
Define a known-safe or nonexistent target that should produce a meaningfully different result.
Effect and bounds
Unknown until flags and target are reviewed. Assume the command sends traffic or changes local state unless the tool documentation proves otherwise.
Detection sampleAuthorization required

Confirm the sink and encoding context before use.

https://[email protected]/probe
Expected signal
Not verified for this generic template. Confirm the exact tool version and expected output in its official documentation before use.
Negative control
Define a known-safe or nonexistent target that should produce a meaningfully different result.
Effect and bounds
Unknown until flags and target are reviewed. Assume the command sends traffic or changes local state unless the tool documentation proves otherwise.
Detection sampleAuthorization required

Confirm the sink and encoding context before use.

https://ssrf017-port.UNIQUE.oast.example:8443/probe
Expected signal
Not verified for this generic template. Confirm the exact tool version and expected output in its official documentation before use.
Negative control
Define a known-safe or nonexistent target that should produce a meaningfully different result.
Effect and bounds
Unknown until flags and target are reviewed. Assume the command sends traffic or changes local state unless the tool documentation proves otherwise.
Detection sampleAuthorization required

Confirm the sink and encoding context before use.

https://ssrf017-fragment.UNIQUE.oast.example/probe#allowed.example
Expected signal
Not verified for this generic template. Confirm the exact tool version and expected output in its official documentation before use.
Negative control
Define a known-safe or nonexistent target that should produce a meaningfully different result.
Effect and bounds
Unknown until flags and target are reviewed. Assume the command sends traffic or changes local state unless the tool documentation proves otherwise.
Detection sampleAuthorization required

Confirm the sink and encoding context before use.

{"url":"https://ssrf017-json.UNIQUE.oast.example/probe"}
Expected signal
Not verified for this generic template. Confirm the exact tool version and expected output in its official documentation before use.
Negative control
Define a known-safe or nonexistent target that should produce a meaningfully different result.
Effect and bounds
Unknown until flags and target are reviewed. Assume the command sends traffic or changes local state unless the tool documentation proves otherwise.
Detection sampleAuthorization required

Confirm the sink and encoding context before use.

url=https%3A%2F%2Fssrf017-form.UNIQUE.oast.example%2Fprobe
Expected signal
Not verified for this generic template. Confirm the exact tool version and expected output in its official documentation before use.
Negative control
Define a known-safe or nonexistent target that should produce a meaningfully different result.
Effect and bounds
Unknown until flags and target are reviewed. Assume the command sends traffic or changes local state unless the tool documentation proves otherwise.

Attribution

Open the primary collection ↗

Version history: normalized permanent page created 2026-08-20.