Author Archives: Vaadata Author

Exploiting the SSRF vulnerability (2/2)

In this previous article, we have seen what a SSRF vulnerability is, and how, in general, it can be exploited. We had placed ourselves in a quite simple theoretical framework, but various elements (either due to the vulnerability itself or due to security implementations) can make the task more complicated.

In this article, we will have a look at various methods to go further. On the agenda:

  • Various methods for manually bypassing filters;
  • SSRFMap: a semi-automatic operating tool.
Continue reading

Introduction to Burp, the Dedicated Tool to Web Platforms Security

Introduction to Burp Suite - Proxy, Scanner, Intruder and Repeater

Burp, by information security professionals, is often said to be our best friend. Burp doesn’t ring a bell? It is a software dedicated to web security audits, used by a majority of information security professionals. First, we will present you the software Burp and four fundamental modules. For those already familiar with the tool, a second more technical article details some functionalities and extensions to gain efficiency.

Continue reading