Finding SSRF BY Full Automation

2 months ago 25
BOOK THIS SPACE FOR AD
ARTICLE AD

Santosh Kumar Sha(@killmongar1996)

InfoSec Write-ups

Published in

3 min read

Jan 27, 2021

--

Hi, everyone

My name is Santosh Kumar Sha, I’m a security researcher from India(Assam). In this article, I will be describing how I was able to Find SSRF vulnerability by by automating it and leak private information amazon metadata, ec2 and cloud services.

I am now offering 1:1 sessions to share my knowledge and expertise:

topmate.io/santosh_kumar_sha

Tools Requried:

gf (tomnomnom) — https://github.com/tomnomnom/gfqsreplace(tomnomnom) — https://github.com/tomnomnom/qsreplaceffuf — https://github.com/ffuf/ffufgau(Corben) — https://github.com/lc/gauwaybackurls(tomnomnom) — https://github.com/tomnomnom/waybackurls

Here get access to internal metadata by ssrf we will collect all URL from way-back machine and look for access the internal data by ssrf

Suppose the the target is targetme.com

Now here process the process for find the ssrf to access internal metadata

Command for getting the URL:

waybackurl targetme.com >> blindssrftesturl.txt

Read Entire Article