Posts on ssrf
3 posts on ssrf. Notes from public sources and my own test lab.
The Silent Cry of Parameters: Hunting Logic and Architecture in Modern Web Apps
When you multiply the 'amount' parameter in a checkout request by -1 and the server returns a 200 OK, your entire security architecture just became a paper tiger. Let's dive into why logic and architecture hunting is the real frontier of modern security.
July 3, 2026·4 dk readbusiness-logicidorred-teaming
Görünmez Duvarları Aşmak: PDF Generator'dan Cloud Metadata'ya Uzanan O Tehlikeli Yol
Bir PDF oluşturma servisinin nasıl bir iç ağ casusuna dönüştüğünü ve bulut ortamındaki en değerli anahtarların nasıl tehlikeye girdiğini teknik bir kriz anıyla inceliyoruz.
June 18, 2026·3 dk readcloud-securitydefensered-teaming
The Shadow Creeping Behind the Walls: Anatomy of SSRF and Those 'Innocent' Looking Parameters
A deep dive into Server-Side Request Forgery (SSRF), exploring how 'innocent' URL parameters can lead to full cloud environment compromise, shared from the perspective of a Red Team Lead.
April 22, 2026·3 dk readcloud-securitydefensered-teaming