vulns.co
/
GKData.io MCP

Back to Payloads

Blind SSRF with OAST

Confirm a suspected server-side URL fetch with a unique, callback-only endpoint you control. Use one request at a time, record the parameter and correlation ID, and stop after proof of fetch.

Tags: ssrf, oast, blind, authorized-testing

Controlled probes

  • https://UNIQUE-CALLBACK.example/ssrf/preview-001
  • Use a fresh identifier for every parameter and redirect hop
  • Record DNS, HTTP, timestamp, and source-IP evidence; do not probe internal services

Source: https://owasp.org/www-community/attacks/Server_Side_Request_Forgery