SSRF Hunting
Confirm the server requests a host you control. Cloud metadata is a later step, and only when the program allows it. In the 2025 OWASP list, SSRF sits under broken access control.
Tags: ssrf, cloud, oob, owasp-a01
Level: advanced
Method
Find request-issuing features
Webhooks, URL previews, PDF or image fetchers, and import-from-URL features ask the server to fetch a URL. Write down the feature before you change the URL.
Set up a callback you control
Use an interaction server you are allowed to use. A DNS or HTTP hit on that host is the first proof the server fetched a URL.
interactsh-client -vTools: interactsh
Canary before internal addresses
Point the feature at the callback host. If that hit is real, record the request and the response. Internal addresses and cloud metadata come later, and only when the program explicitly allows them.
Scope the next hop
If the program allows an internal target, name the address the program allowed and the response you received. A template scan is not the proof.
Field notes
- A callback you control is the proof that the server made a request.
- Metadata endpoints are out of scope unless the program says they are in scope.