All Projects

ID Status Summary Opened by
 507 Closed Server-Side Request Forgery (SSRF) via `reverse_proxy`  ...NOoobsec Task Description

Severity: High
CVSS 3.1: 7.5
Affected Component: `reverse_proxy` site type (`url` / “URL distante”)

## Summary

The `reverse_proxy` site type allows the configured `url` to be fetched server-side without restricting access to private, loopback, or link-local addresses.

I confirmed that the server can make external requests and access `127.0.0.1`. I did not enumerate internal services in accordance with the program rules.

## Steps to Reproduce

1. Set the site type to `reverse_proxy` and configure:

 {"type":"reverse_proxy","url":"http://example.com/"}
 The site returns the content from Example Domain, confirming server-side fetching.

2. Change the URL to:

 {"url":"http://127.0.0.1/"}
 The response changes to:
 404 Site not found
 Request ID: ...
 Server: Apache
 This confirms that the request reached the platform's loopback interface.

3. I also tested:

 {"url":"http://169.254.169.254/latest/meta-data/"}
 which returned `503`. No cloud metadata was obtained.

## Impact

An attacker can control a server-side request destination and reach the platform's loopback interface.

This creates an SSRF primitive that could potentially be used to access internal services or other restricted resources, depending on the services reachable from the server. Internal service enumeration was not performed.

## Recommendation

* Block private, loopback, and link-local IP ranges.
* Validate the resolved IP address, not only the supplied hostname.
* Protect against DNS rebinding.
* Apply outbound/egress network filtering for server-side requests.

Showing tasks 1 - 1 of 1 Page 1 of 1

Available keyboard shortcuts

Tasklist

Task Details

Task Editing