Owning the Cloud Through SSRF
44CON Information Security Conference via YouTube
Earn a Michigan Engineering AI Certificate — Stay Ahead of the AI Revolution
Get 20% off all career paths from fullstack to AI
Overview
Syllabus
Intro
WHO ARE WE
SSRF According to OWASP
What is Cloud Metadata?
Basic Example
CVE Examples
SSRF Hurdles
Headless Browsers
HTML Renderers
Simple XSS- SSRF via wkhtmltopdf
When Simple Fails
XSS via escaping tag
WeasyPrint Makes Hacking (W)easy
Use The Source
Attachments
DNS Rebinding for Fun and Profit
HTTPRebind
Recap
Keep in Touch
Taught by
44CON Information Security Conference