blind-ssrf-chains
blind-ssrf-chains copied to clipboard
An exhaustive list of all the possible ways you can chain your Blind SSRF vulnerability
Hey @infosec-au, I don't saw Springboot actuators in the list, like: ``` /shutdown /actuator/shutdown ``` Any reason for that? Can I submit a PR?
Hello! I found this https://github.com/assetnote/blind-ssrf-chains#confluence in a website... But I am not able to show much impact then DNS and http interactions... Can you help me?
Coldfusion uses a GET parameter to perform SSRF via LDAP protocol, and also to execute arbitrary code via LDAP deserialization.