# Server-side request forgery checklist

Prove that the application—not the browser—fetches an attacker-influenced destination, then enumerate internal trust boundaries and services.

## Recognition

- [ ] Features import URLs, generate previews, fetch images, validate webhooks, render PDFs, check links, proxy APIs, or accept callback destinations.
- [ ] A controlled server receives a request with headers or source addresses different from the browser.
- [ ] Supplying localhost, private IPs, or alternate schemes changes status, body, timing, or error text.

## Manual workflow

- [ ] Use a unique callback path to prove the exact input causes a server-side request.
- [ ] Record method, headers, DNS behavior, redirects, URL parsing, response reflection, and whether the server follows redirects.
- [ ] Test loopback and likely internal services using controlled port and path hypotheses.
- [ ] Evaluate alternate host representations, scheme confusion, userinfo, fragments, redirects, and validation-versus-fetch parser differences.
- [ ] Distinguish blind reachability using timing or callbacks from content-retrieving SSRF.
- [ ] Interact with internal administrative or unauthenticated microservice endpoints using the supported method and body.
- [ ] Pursue cloud metadata only when environment clues support it and remain within the authorized target.

## Escalation

- [ ] Bypass network-based trust or authentication on localhost/internal services.
- [ ] Read internal API responses, configuration endpoints, or metadata credentials when reflected.
- [ ] Chain internal access into administrator actions, file access, or code execution.

## Pitfalls

- [ ] Mistaking a browser request for a server request.
- [ ] Scanning enormous private ranges instead of using application and error clues.
- [ ] Generating IP encodings without checking whether the actual URL parser accepts them.
- [ ] Stopping at a callback rather than reaching an exam objective.

## Evidence

- [ ] Unique callback request
- [ ] Server-fetch characteristics
- [ ] Internal destination evidence
- [ ] Privileged internal response/action
- [ ] Resulting objective

## Tools

- [ ] Controlled HTTP/DNS callback
- [ ] Burp/ZAP resend
- [ ] SSRF representation workbench
- [ ] Nmap only against authorized exam targets as allowed

## Online references

- [PortSwigger SSRF labs](<https://portswigger.net/web-security/ssrf>)
- [OWASP SSRF testing](<https://owasp.org/www-project-web-security-testing-guide/latest/4-Web_Application_Security_Testing/07-Input_Validation_Testing/19-Testing_for_Server-Side_Request_Forgery>)

> Do you want to live curiously?
