André Baptista’s Post

Looking into a potential SSRF or OR but the server checks against a URL whitelist? Try the backslash trick! Due to a difference in URL specifications, some parsers will treat '\' the same as '/', while others will not. Here's an example payload: https://<attacker-url>\@<whitelisted-url>/ You can also use https://lnkd.in/dPvMsPzK to find potential new vectors 🥷

Thanks for sharing #CyberSecurity #Noted 📝

See more comments

To view or add a comment, sign in

Explore content categories