EC-Council Certified Ethical Hacker (CEH) v12Web Application HackingMedium

A web application is designed to convert user-submitted URLs into PDF documents. A security researcher attempts to submit an internal URL (e.g., `http://localhost/admin`) to the conversion service and observes that the PDF output includes content from the internal resource. Which web application attack does this scenario demonstrate?

  1. ACross-Site Scripting (XSS)
  2. BHTTP Smuggling
  3. COpen Redirect
  4. DServer-Side Request Forgery (SSRF)
Show answer & explanation

Correct answer: D. Server-Side Request Forgery (SSRF)

The scenario describes a web application making a request to an internal resource (`http://localhost/admin`) based on user-supplied input (the URL for PDF conversion). The server then fetches this internal resource and processes its content, which is the definition of a Server-Side Request Forgery (SSRF) attack.

Why the other options are wrong

  • A. XSS injects client-side scripts, not forces the server to make internal requests.
  • B. HTTP Smuggling exploits discrepancies in how proxies/firewalls and web servers interpret HTTP requests, unrelated to this URL conversion scenario.
  • C. Open Redirect redirects the user's browser to an arbitrary URL, it doesn't involve the server fetching internal resources.

Server-Side Request Forgery (SSRF)

A web security vulnerability that allows an attacker to induce the server-side application to make HTTP requests to an arbitrary domain of the attacker's choosing.

  • Can target internal networks, cloud instance metadata, or local files.
  • Often used to bypass firewalls or access internal services.
  • Mitigation involves input validation and restricting server-side requests.

Memory trick: SSRF makes the 'Server Request For' the attacker.

More Web Application Hacking questions