Soham7-dev/AspGoat

SSRF Bypass Challenge

Ouverte

#2 ouverte le 31 août 2025

 (0 commentaire) (0 réaction) (0 personne assignée)JavaScript (92 forks)auto 404
bugenhancementhelp wanted

Métriques du dépôt

Stars
 (106 étoiles)
Métriques de merge PR
 (Métriques PR en attente)

Description

🔒 Security Lab Enhancement : SSRF Bypass Challenge

Description

Currently, AspGoat includes one SSRF lab with both:

  • ❌ Vulnerable version
  • ✅ Secure version (with basic whitelist)

However, in real-world scenarios, attackers may find ways to bypass the secure code as well (e.g., via redirects, alternate encodings, or dns rebinding).

Tasks

  • Analyze the current SSRF "secure" implementation via AspGoat UI (Login -> SSRF lab -> Identify Vulnerability -> Secure Code Modal).
  • Copy the Secure Code and replace the Vulnerable Code with the Secure Code inside Controllers/HomeController.cs under SSRF POST ACTION
  • Now try various methods to bypass this protection. (Note: Modifying the /etc/hosts file via RCE or manually to gain access to an internal ip address does not count 😅)

Guide contributeur