Skip to content

Posts tagged: #web-security

Why SSRF filters fail in practice. Parser confusion, IP encoding, DNS rebinding, and redirect chains explained from the attacker's side, with the defensive fixes that actually hold.
A working SSRF payload list from real engagements: IP encoding tricks, allow-list bypasses, protocol smuggling, and the cloud metadata endpoints worth memorizing.