EC-Council Certified Ethical Hacker (CEH) v12Web Application HackingMedium
A web application is designed to convert user-submitted URLs into PDF documents. A security researcher attempts to submit an internal URL (e.g., `http://localhost/admin`) to the conversion service and observes that the PDF output includes content from the internal resource. Which web application attack does this scenario demonstrate?
- ACross-Site Scripting (XSS)
- BHTTP Smuggling
- COpen Redirect
- DServer-Side Request Forgery (SSRF)
Show answer & explanationAnswer & explanation
Correct answer: D. Server-Side Request Forgery (SSRF)
The scenario describes a web application making a request to an internal resource (`http://localhost/admin`) based on user-supplied input (the URL for PDF conversion). The server then fetches this internal resource and processes its content, which is the definition of a Server-Side Request Forgery (SSRF) attack.
Why the other options are wrong
- A. XSS injects client-side scripts, not forces the server to make internal requests.
- B. HTTP Smuggling exploits discrepancies in how proxies/firewalls and web servers interpret HTTP requests, unrelated to this URL conversion scenario.
- C. Open Redirect redirects the user's browser to an arbitrary URL, it doesn't involve the server fetching internal resources.
Server-Side Request Forgery (SSRF)
A web security vulnerability that allows an attacker to induce the server-side application to make HTTP requests to an arbitrary domain of the attacker's choosing.
- Can target internal networks, cloud instance metadata, or local files.
- Often used to bypass firewalls or access internal services.
- Mitigation involves input validation and restricting server-side requests.
Memory trick: SSRF makes the 'Server Request For' the attacker.