Sort SSRF defenses by layer
Classify SSRF defenses by the layer of the URL-fetching pipeline they protect.
Sort each SSRF defense by the layer it protects. Parser and scheme DNS and IP resolution Network egress Redirect and response handling Allow only https URLs and reject embedded credentials in the URL. Resolve the hostname and block loopback, private, link-local, and metadata IP ranges. Run the fetcher in a subnet that cannot reach cloud metadata or internal admin networks. Revalidate every Location target before following an HTTP redirect. Use a real URL parser instead of regex matching against the raw string. Pin DNS results for the connection attempt and reject DNS rebinding to private ranges. Apply firewall or service-mesh…
Sign up free — one personalized lesson every day, matched to your role and goals.
Already have an account? Sign in