performing-blind-ssrf-exploitation - Perform Blind SSRF Exploitation and Network Discovery
Detect and exploit blind Server-Side Request Forgery vulnerabilities using out-of-band techniques and timing analysis.
Tags
Updated: 2026-09-21Capabilities
Typical Inputs
Typical Outputs
What this skill does
- Identify blind SSRF input points
- Confirm blind SSRF using OOB detection
- Enumerate internal networks and ports
- Access cloud metadata endpoints
- Bypass SSRF filters
- Exfiltrate data via DNS
Inputs
- Target application URL or API endpoint
- Susceptible input parameters
- Out-of-band callback domain
- Authorization tokens
Outputs
- Blind SSRF assessment report
- Out-of-band interaction logs
- Internal network host and port map
Requirements
- Burp Suite Professional or interact.sh
- Python runtime with requests library
- Controlled server or VPS
