The server that talked back: a deep dive into SSRFs - Sofia Lindqvist - NDC Security 2026

Security
youtube
The server that talked back: a deep dive into SSRFs - Sofia Lindqvist - NDC Security 2026 This talk was recorded at NDC Security in Oslo, Norway. #ndcsecurity #ndcconferences #security #developer #softwaredeveloper Attend the next NDC conference near you: Subscribe to our YouTube channel and learn every day: @NDC Follow our Social Media! #hacker #owasp #azure Server-Side Request Forgery (SSRF) is a web application vulnerability where an attacker forces a web server to make a request to a URL of the attackers choosing. SSRFs can be used for instance to bypass access controls, access hidden internal resources or access cloud credentials. These vulnerabilities are nothing new. In fact the term SSRF has been in use for nearly twenty years, and since 2021 SSRF has been a part of the OWASP top 10 list. Even though the bug class has been around "forever", SSRF vulnerabilities still keep turning up, and applications keep failing to properly protect against them. In this talk we'll start with the most basic example of an SSRF, and then work our way to increasingly more interesting cases. There will be real world examples of bugs found during engagements and in the wild in products like Azure, as well as examples of bypasses of the mitigations made by the vendors.
  2026/03/19      youtube

関連するプログラミング動画 [security]

Our Tag

最近投稿されたプログラミング学習動画

MITRE ATT&CK for Developers - Chris Ayers - NDC Security 2026

Security

This talk was recorded at NDC Security i...

  2026/03/19

Worms in our software supply chain - Where do we go from here? - Charl

Security

This talk was recorded at NDC Security i...

  2026/03/19

The server that talked back: a deep dive into SSRFs - Sofia Lindqvist

Security

This talk was recorded at NDC Security i...

  2026/03/19

Building Community-Driven Security Analysis for Your .NET Software Sup

unity
Security

Beyond Trust: Building Community-Driven ...

  2026/03/19

Safe by design: the UX of secure banking - Dora Makszy - NDC Security

Security
Design

This talk was recorded at NDC Security i...

  2026/03/19

Coding with a Controller: My Claude Code Gamepad Setup

game

← View the Full Syllabus and Reserve Yo...

  2026/03/18

Constraints Can Help Writer's Block

python

Download your free Python Cheat Sheet he...

  2026/03/18

19 Web Dev Projects – HTML, CSS, JavaScript Tutorial

javascript

Improve your web development skills by b...

  2026/03/18

Learn the basics of LLMs in 60 seconds with Beau Carnes

Learn the basics of LLMs in 60 seconds w...

  2026/03/18

最先端でAI活用したいならこのステップで学習してください!AI活用のプロがAI初心者からAIを使いこなすまでの学習法を解説します

本日はAIを0から学ぶステップについてお話させて頂きました! ぜひご視聴ください...

  2026/03/18

モンスターハンターワイルズ 100万以上のユーザー同時接続を支えたネットワークアーキテクチャ(CUS-52)

モンスターハンターワイルズは多くのユーザからのアクセスを見込んだクロスプラットフ...

  2026/03/18

PointFive Cloud Optimization and AI Efficiency for AWS Customers | Ama

Amazon
cloud

PointFive is a Cloud and AI Efficiency E...

  2026/03/17

Inside the Ropes with the @PGATOUR Episode 2: PGA TOUR Studios | Amazo

Amazon

Go Inside the Ropes with host Amanda Bal...

  2026/03/17

Machine Learning Full Course - Learn Machine Learning (2026) | Machine

study

🔥PGP in Generative AI and ML in collabor...

  2026/03/17

AWS Identity Center Multi Region Replication Enablement Deep Dive | Am

Amazon

This video walks you through enabling mu...

  2026/03/17