OceanAltOceanAlt

SSRF

服务端请求伪造(SSRF)

Tricking a server into fetching an attacker-chosen internal address. Any feature that fetches a user-supplied URL must defend against it.

RELATED TERMS

  • WebhookA server-initiated notification pushed to a URL you supply w
  • Endpoint screeningChecking whether the URL or domain about to be called is a k

This definition is citable at a stable URL: https://oceanalt.com/en/glossary/ssrf

← Back to the glossary