Facebook Designed A New Tool For Finding Ssrf Vulnerabilities Cybers Guards
A SSRF attack, according to the OWASP definition, allows an attacker to access or edit internal resources by abusing a server’s functionality. “By carefully picking the URLs, the attacker may be able to retrieve server configuration such as AWS information, connect to internal services like http enabled databases, or make post requests towards internal services that are not supposed to be exposed,” OWASP adds. The new Facebook tool, dubbed SSRF Dashboard, has a simple UI that allows researchers to define unique internal endpoint URLs for targeting and then see if those URLs have been hit during an SSRF attempt....