Collected research
SSRF vulnerabilities caused by SNI proxy misconfigurations
SSRF against load balancers that route by the TLS SNI field. When a proxy such as nginx with ssl_preread passes the client-supplied server name straight into proxy_pass, or matches it with a loose regex, an attacker puts an arbitrary host or IP in the ClientHello and reaches backends behind the proxy.
Record
- Published by
- invicti.com
- Topic
- HTTP
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of invicti.com, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .