
Episode 13: How to Find a Good BBP + Acropalypse + ZDI
Critical Thinking - Bug Bounty Podcast
00:00
The SSRF Sheriff
An SSRF sheriff is an internal service that's designed to make testing SSRF easier. It responds to basically any type of request so it'll respond to Images with various different images Usually with a secret identifier that is Within the image. The goal is that can I hit this service and if so, I should be able to get this secret string back That will prove definitively that I have an SSRF right? You know we could spend hours sitting there poking that within you know blind SSRF trying to prove internal impact or you could set up the server We could hit it in in two minutes and have that sort of decided So I'd love to see when programs set up that that tool that that
Transcript
Play full episode