SSRF: Attacks, Defense and Status Quo (god2024) episode artwork

EPISODE · Nov 13, 2024 · 10 MIN

SSRF: Attacks, Defense and Status Quo (god2024)

from Chaos Computer Club - archive feed · host Malte Wessels

Web apps use Server-Side Requests to request data from other servers, e.g., for link previews. However, they are exploited by attackers who might request internal resources or non-public services. This attack is called Server-Side Request Forgery (SSRF). The talk explains what SSRF is, how it can be used to exploit servers, and how to defend against it, which is surprisingly complex. Finally, we will discuss our research on the prevalence of countermeasures in the wild. Licensed to the public under https://creativecommons.org/licenses/by-sa/4.0/ about this event: https://c3voc.de

Episode metadata supplied by the publisher feed · Published Nov 13, 2024

Embed this episode

NOW PLAYING

SSRF: Attacks, Defense and Status Quo (god2024)

0:00 10:25

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

How long is this episode of Chaos Computer Club - archive feed?

This episode is 10 minutes long.

When was this Chaos Computer Club - archive feed episode published?

This episode was published on November 13, 2024.

Can I download this Chaos Computer Club - archive feed episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!