Web Hack List

Collected research

Another vision for SSRF

Turns a low-impact SSRF that acts as a configurable proxy on a subdomain into client-side session theft. The attacker points the proxy at their own server and serves content through the vulnerable subdomain, so a victim lured to that URL sends the wildcard-domain session cookie (domain=.example.com) along with the request and it is read from the attacker's logs, reaching a cookie that HttpOnly and SameSite would deny to an XSS.

Record

Researcher
@phor3nsic_br
Published by
gccybermonks.com
Topic
Server

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of @phor3nsic_br, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .