Overview
SSRF turns the application into a proxy that bypasses the network boundary the attacker cannot cross directly.\nThe prize is usually the cloud metadata service at 169.254.169.254, which hands out temporary credentials, or internal admin panels bound to localhost.\nWebhook, file-import, PDF-render and image-proxy features are the usual entry points.
Indicators of Compromise
Signals that suggest this is present on a system.
- Requests to link-preview or import features reaching internal ranges
- Metadata-service IP appearing in outbound logs
- Responses differing between public and internal URLs
Controls that stop it
-
Segment the Network and Restrict Egress
Do not let every host talk to every other host or to the whole internet. Segment by role, deny inbound administration from user networks, and filter outbound traffic so only the destinations a workload genuinely needs are reachable. Egress control is what stops an SSRF or an implant from reaching cloud metadata and command infrastructure.