vulns.co
/
GKData.io MCP

Back to Playbooks

SSRF Hunting

Confirm the server requests a host you control. Cloud metadata is a later step, and only when the program allows it. In the 2025 OWASP list, SSRF sits under broken access control.

Tags: ssrf, cloud, oob, owasp-a01

Level: advanced

Method

  1. Find request-issuing features

    Webhooks, URL previews, PDF or image fetchers, and import-from-URL features ask the server to fetch a URL. Write down the feature before you change the URL.

  2. Set up a callback you control

    Use an interaction server you are allowed to use. A DNS or HTTP hit on that host is the first proof the server fetched a URL.

    interactsh-client -v

    Tools: interactsh

  3. Canary before internal addresses

    Point the feature at the callback host. If that hit is real, record the request and the response. Internal addresses and cloud metadata come later, and only when the program explicitly allows them.

  4. Scope the next hop

    If the program allows an internal target, name the address the program allowed and the response you received. A template scan is not the proof.

Field notes

  • A callback you control is the proof that the server made a request.
  • Metadata endpoints are out of scope unless the program says they are in scope.

References