166 terms · 75/46/45
kompozit · edukator režim · za predavanje i PDF

SSRF

Pretnja u centru, tehnike kojima se izvodi levo, odbrane koje je suzbijaju desno. Ispod — mapa faza napada: kojom tehnikom se ulazi i koja odbrana je presreće.

↘ Techniques used to carry it out3

Techniques used to carry it out. Klik vodi na stranicu pojma.

threat · № 045 · applications

SSRF

SSRF is a vulnerability in which the attacker gets a web server to send a request to an address of the attacker's choosing. The distinction matters: the request is not sent by the user's browser but by the server. That opens the door to internal services which from the outside ought to remain invisible.

↓ mapa faza · kojom tehnikom se ulazi, koja odbrana presreće
faza · ubacivanje · tehnika URL ili adresa kroz parametar koji server obrađuje
presreće · odbrana Validacija unosa · allowlist odredišta · zabrana privatnih opsega
faza · pristup · tehnika Server poziva interne servise, lokalne adrese ili metadata endpoint
presreće · odbrana Segmentacija · blokiranje metadata pristupa · least privilege
faza · izvlačenje · tehnika Čitanje internih odgovora, tokena ili konfiguracije
presreće · odbrana Monitoring egress saobraćaja · WAF · cloud hardening

↗ How it is defended against5