AppSec Tales XVII | SSRF

Karol Mazurek
5 min readAug 20, 2023

Application Security Testing for the Server Side Request Forgery.


The article describes how to test the application to find Server Side Request Forgery vulnerabilities. The advice in this article is based on the following:

  • OWASP Web Security Testing Guide
  • OWASP Application Security Verification Standard
  • Bug bounty reports
  • Own experience.


Tools with basic usage & wordlist used for SSRF detection.


  • SSRFmap— SSRF semi-automatic discovery and exploitation tool.

I am not using it due to problems with JSON parsing and the need to specify injection points manually. However, I decided to share it here in case it may be helpful to someone else and if the tool improves in the future.

Source: Own study — Script options.