Top 10 winner
Novel SSRF Technique Involving HTTP Redirect Loops
A blind SSRF that discloses nothing for a successful response may return the whole response for an error status. Serving a redirect loop that increments the status code through the 3xx range drives the client into that error path, and the application then leaks the entire redirect chain plus the final body, enough to read cloud metadata credentials.
Record
- Researcher
- Shubham Shah and @searchlightsec
- Published by
- Searchlight Cyber
- Date
- Topic
- HTTP
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of Shubham Shah and @searchlightsec, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .