Zum Hauptinhalt springen
Echtzeit-Radar & Feeds
Alle RSS Feeds ➔
👥 Community & Social
Sicherheitslücken (CVE)USN-8840-1: libevent vulnerabilities(28.09.2026 um 22:05 Uhr)
•••••
Sichere ProgrammierungStyle Is Grammar: Making Agreement Visible in Native ECMAScript(29.09.2026 um 17:29 Uhr)
•
Sichere ProgrammierungWhat Is Aqiron Security Missing? I Want You to Find Out.(29.09.2026 um 17:29 Uhr)
•
Sichere ProgrammierungQuerying Qdrant from .NET(29.09.2026 um 17:30 Uhr)
••
Sichere ProgrammierungHow to make a Currency Converter with tkinter and forex-python.(29.09.2026 um 17:30 Uhr)
•
Sicherheitslücken (CVE)USN-8840-1: libevent vulnerabilities(28.09.2026 um 22:05 Uhr)
•••••
Sichere ProgrammierungStyle Is Grammar: Making Agreement Visible in Native ECMAScript(29.09.2026 um 17:29 Uhr)
•
Sichere ProgrammierungWhat Is Aqiron Security Missing? I Want You to Find Out.(29.09.2026 um 17:29 Uhr)
•
Sichere ProgrammierungQuerying Qdrant from .NET(29.09.2026 um 17:30 Uhr)
••
Sichere ProgrammierungHow to make a Currency Converter with tkinter and forex-python.(29.09.2026 um 17:30 Uhr)
•
Intelligence View
⚡ tsecurity.de Intelligence

SSRF Attacks: The Silent Threat Hiding in Your Server

What is SSRF (Server-Side Request Forgery)? Server-Side Request Forgery (SSRF) is a web vulnerability where attackers trick a server into making unauthorized requests to internal or external systems. How Does It Work? An…

0
↗ Quelle (dev.to)
Reagiere als Erste:r — dein Feedback zählt!




What is SSRF (Server-Side Request Forgery)?



Server-Side Request Forgery (SSRF) is a web vulnerability where attackers trick a server into making unauthorized requests to internal or external systems.






How Does It Work?



An attacker sends a malicious URL in a request that the server processes as legitimate. The server then makes the request on the attacker’s behalf.



Example:


A shopping app checks stock by making a backend API request:




POST /product/stock  
stockApi=http://stock.server.com/check?productId=6&storeId=1






An attacker modifies the URL to point to the server's admin page:




POST /product/stock  
stockApi=http://localhost/admin






The server fetches and returns restricted admin data, bypassing access controls.






Why Does This Happen?





  1. Access Control Gaps: Checks are skipped for local requests.


  2. Recovery Features: Admin access is granted to local users without authentication.


  3. Hidden Interfaces: Admin tools on separate ports trust local machine requests.






Protect Against SSRF




  • Validate and sanitize input URLs.

  • Use URL whitelists.

  • Restrict internal service access.



SSRF can be critical, but good design and input validation can prevent it.






Acknowledgment: This document references information from PortSwigger Web Security and ChatGPT.

2. Cyber Threat Intelligence & Forensik

CTI Threat Relationship Graph4 Knoten / 3 Relationen
CVE / Incident Software MITRE ATT&CK CWE Weakness IoC
MITRE ATT&CK Matrix Navigator 14 Taktiken
1 belegte TechnikenLive-Mapping
Reconnaissance
Resource Development
Initial Access
Execution
Persistence
Privilege Escalation
Defense Evasion
Credential Access
Discovery
Lateral Movement
Collection
Command and Control
Exfiltration
Impact
Ähnliche Beiträge
🔍 Verwandte News

Auch interessante Nachrichten SSRF Attacks: The Silent Threat Hiding in Your Server

Thematisch verwandte Begriffe: SSRF, Attacks, Silent, Threat · 6 Treffer

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

💬 Kommentare werden geladen…
Zum Aktualisieren ziehen
ZERO-DAY CVE-2026-8065 | An authentication bypass vulnerability in the firmware update endpoint of…
Advisory →
tsecurity.de Icon
Offline-Lesen, Eilmeldungen & 0ms Ladezeit

Installiere tsecurity.de direkt auf deinen Home-Bildschirm für das ultimative Vollbild-Magazinerlebnis ohne Browser-Leisten.

Nächster Beitrag