Soham7-dev/AspGoat

SSRF Bypass Challenge

Offen

#2 geöffnet am 31.08.2025

 (0 Kommentare) (0 Reaktionen) (0 zugewiesene Personen)JavaScript (92 Forks)auto 404
bugenhancementhelp wanted

Repository-Metriken

Stars
 (106 Sterne)
PR-Merge-Metriken
 (PR-Metriken ausstehend)

Beschreibung

🔒 Security Lab Enhancement : SSRF Bypass Challenge

Description

Currently, AspGoat includes one SSRF lab with both:

  • ❌ Vulnerable version
  • ✅ Secure version (with basic whitelist)

However, in real-world scenarios, attackers may find ways to bypass the secure code as well (e.g., via redirects, alternate encodings, or dns rebinding).

Tasks

  • Analyze the current SSRF "secure" implementation via AspGoat UI (Login -> SSRF lab -> Identify Vulnerability -> Secure Code Modal).
  • Copy the Secure Code and replace the Vulnerable Code with the Secure Code inside Controllers/HomeController.cs under SSRF POST ACTION
  • Now try various methods to bypass this protection. (Note: Modifying the /etc/hosts file via RCE or manually to gain access to an internal ip address does not count 😅)

Contributor Guide