Web Hack List

Collected research

SSRF vulnerabilities caused by SNI proxy misconfigurations

SSRF against load balancers that route by the TLS SNI field. When a proxy such as nginx with ssl_preread passes the client-supplied server name straight into proxy_pass, or matches it with a loose regex, an attacker puts an arbitrary host or IP in the ClientHello and reaches backends behind the proxy.

Record

Published by
invicti.com
Topic
HTTP

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of invicti.com, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .