Collected research
Another vision for SSRF
Turns a low-impact SSRF that acts as a configurable proxy on a subdomain into client-side session theft. The attacker points the proxy at their own server and serves content through the vulnerable subdomain, so a victim lured to that URL sends the wildcard-domain session cookie (domain=.example.com) along with the request and it is read from the attacker's logs, reaching a cookie that HttpOnly and SameSite would deny to an XSS.
Record
- Researcher
- @phor3nsic_br
- Published by
- gccybermonks.com
- Topic
- Server
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of @phor3nsic_br, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .