A successful SSRF attack can result in any of the following: - Access to unauthorised areas. - Access to customer/organisational data. - Ability to Scale to internal networks. - Reveal authentication tokens/credentials.

Request forgery

https://website.thm/item/2?server=server.website.thm/flag?id=9&x=

Server Requesting: https://server.website.thm/flag?id=9&x=.website.thm/api/item?id=2

THM{SSRF_MASTER}

requestbin.com