Cyberlium

Bug › Module 6 › Lesson 3

BeginnerModule 6Lesson 3/5

SSRF and Logic

SSRF, open redirect, and business logic named — hunter framing and defender notes on $PROGRAM scope, not cloud metadata raid kits.

15 min+40 XP3 quiz
Module progress3 of 5

Visual · t20_ssrf_and_logic

SSRF = server fetches attacker-chosen URL. Logic = rules bypass without classic injection. $PROGRAM only. Original Cyberlium.

Opening

SSRF and logic bugs break assumptions — learn the names and defender patterns, not how to pivot through stranger cloud metadata.

Server-Side Request Forgery (SSRF) tricks the application server into requesting internal or external URLs the attacker chooses — cloud metadata endpoints, internal admin panels, loopback services — with impact depending on network placement. Open redirect sends users to attacker-controlled URLs via trusted domain — often chained, rarely Critical alone. Business logic flaws abuse intended workflows: coupon stacking, race conditions, negative quantities, step-skipping in multi-stage flows — no classic CVE, still real impact. Cyberlium names these classes, CWE-918/CWE-601 literacy, and defender mitigations (URL allowlists, network segmentation, workflow validation) on $PROGRAM in-scope features or $LAB_BOUNTY — NOT SSRF cookbooks against stranger AWS accounts, NOT DoS via request floods, NOT phishing redirects at real users, NOT destructive cart/checkout abuse on production strangers. Hunters read program rules on automated scanning and internal network testing before any SSRF hypothesis.

1. SSRF and open redirect (named)

SSRF hunter question: can I supply a URL/IP the server will fetch server-side? Metadata and internal IPs are impact context — proof stays minimal on scope.

Open redirect: does the app redirect to arbitrary URLs via parameter? Note chaining potential; validate with harmless destination you control.

Command guide

Try these commands — SSRF and open redirect (named)

═══ TOOLS & WEBSITES ═══ Browse / read these (authorized learning only — stay in YOUR lab / program scope)

SSRF literacy — server fetches URL (scope/lab only) Business logic — rules broken without classic CVE

═══ INSTALL ═══

Linux (Debian/Ubuntu):

Command — copy this

sudo apt install curl
sudo apt install python3

macOS:

Command — copy this

brew install python3

Windows: Built-in (PowerShell: Invoke-WebRequest) Download https://python.org/downloads/

═══ LINUX / macOS ═══

Command — copy this

python3 -c "print('SSRF: test only on in-scope/lab — never internal metadata on strangers')"
curl -sS 'https://httpbin.org/get?url=https://httpbin.org/get' | jq '.args' | head -5

Primary tools to practice this lesson: curl, python3. Reference sites: SSRF literacy; Business logic. Run every command in the box — install first, then the usage lines — only on YOUR lab / program scope.

2. Business logic (named)

Logic flaws break intended rules: price, quantity, state machine order, referral limits — think like product abuse, not SQLi.

Use two test accounts and small transactions on scope or lab — never drain real inventory, payment rails, or loyalty balances on strangers.

3. Defender and refusal lines

SSRF: deny-by-default egress, metadata IMDSv2, split DMZ, monitor unexpected outbound from app tier. Logic: server-side validation, idempotency, rate limits, fraud rules.

Refused: mass internal port scan via SSRF on unenrolled targets, DoS, phishing redirect campaigns, logic abuse that destroys merchant data.

4. What you ship: SSRF/logic/redirect literacy

One-line each for SSRF, open redirect, logic flaw + defender control each + NEVER stranger cloud/metadata raids.

5. What you record before the next lesson

SSRF and logic literacy path.

6. Wrong vs right: random sites vs in-scope program

Worked failure — same MSF word, opposite target. Right never needs a café Wi-Fi or classmate laptop.

  • Wrong

    SSRF scan 169.254.169.254 on every bug-bounty target without reading program SSRF rules.

  • Right

    Name SSRF, redirect, logic classes and defenses. Next: Classes Lab.

Mission: three-class literacy

1) Define SSRF, open redirect, logic flaw in one line each. 2) Write hunter question for each. 3) Name one defender control per class. 4) Write NEVER DoS/phishing/stranger metadata raids.

Stuck? Ask Cyberlium AI Mentor

Ask Mentor: “When is open redirect in-scope on $PROGRAM?”

Knowledge Check

1

APPLY: SSRF means:

Multiple choice

Knowledge Check

2

APPLY: True or False: Business logic testing may destroy real merchant inventory on strangers.

True or False

Knowledge Check

3

APPLY: Open redirect impact is often:

Multiple choice

← Previous

Answer all 3 knowledge checks to continue. (0/3 answered)