0Pricing
Secure Coding & OWASP Top 10 for Backend · Ders

SSRF Saldırılarını Önleme

URL'leri doğrulayarak ve giden ağ isteklerini kısıtlayarak Sunucu Taraflı İstek Sahteciliği (SSRF) güvenlik açıklarını belirlemeyi ve azaltmayı öğrenin.

SSRF Saldırılarını Önleme, CoddyKit'te ücretsiz bir Secure Coding & OWASP Top 10 for Backend dersidir. Bu, 4 dersinin 3. dersidir. Aşağıdan dersin tamamını ücretsiz okuyabilir, sonra tarayıcıda yerleşik kod editörü ve 7/24 yapay zeka koçu ile uygulamalı olarak pratik yapabilirsin. Bu, Secure Coding & OWASP Top 10 for Backend öğrenme yolunun bir parçasıdır ve ilerlemeniz web ve CoddyKit uygulaması arasında senkronize olur. Secure Coding & OWASP Top 10 for Backend kursu toplamda 4 dersten oluşur.

Bu dersin bazı bölümleri henüz çevrilmemiş olup İngilizce olarak gösterilmektedir.

Understanding SSRF Attacks

Server-Side Request Forgery (SSRF) is a critical web security vulnerability. It tricks a server into making requests to an unintended location, often internal resources or other external services.

Imagine your backend application acts as a proxy, fetching data or resources on behalf of a user. If an attacker can control the destination of these requests, you have an SSRF vulnerability.

How SSRF Works

Here's how SSRF typically works:

  • Your application accepts a URL from a user.
  • The server then makes a request to that URL to fetch data (e.g., an image, a file, a webpage).
  • An attacker provides a malicious URL, pointing to an internal IP address or a sensitive service.
  • The server, trusting the input, makes the request, potentially exposing internal data or services.

The Dangers of SSRF

The consequences of a successful SSRF attack can be severe:

  • Access to internal systems: Attackers can scan internal networks, access databases, or administrative interfaces.
  • Cloud metadata exposure: On cloud platforms (AWS, GCP, Azure), SSRF can expose sensitive instance metadata, including temporary credentials.
  • Interaction with other services: The server might be forced to interact with other APIs or services it has access to, performing unauthorized actions.
  • Port scanning: Attackers can use the server to scan ports on other internal or external machines.

Vulnerable Code in Action

Consider a simple backend service that fetches content from a user-provided URL. This Java example shows a common pattern that can lead to SSRF.

The fetchContent method directly uses a user-supplied URL to make an HTTP request without validation.

import java.io.BufferedReader;
import java.io.InputStreamReader;
import java.net.URL;
import java.net.URLConnection;

public class Main {
  public static void main(String[] args) {
    // In a real app, this URL would come from user input (e.g., a web parameter)
    String userSuppliedUrl = "http://example.com/data.txt";
    // Malicious example: "http://169.254.169.254/latest/meta-data/"

    try {
      System.out.println("Fetching content from: " + userSuppliedUrl);
      String content = fetchContent(userSuppliedUrl);
      System.out.println("--- Fetched Content ---");
      System.out.println(content.substring(0, Math.min(content.length(), 100)) + "...");
      System.out.println("-----------------------");
    } catch (Exception e) {
      System.err.println("Error fetching content: " + e.getMessage());
    }
  }

  public static String fetchContent(String urlString) throws Exception {
    URL url = new URL(urlString);
    URLConnection connection = url.openConnection();
    BufferedReader in = new BufferedReader(
        new InputStreamReader(connection.getInputStream()));
    String inputLine;
    StringBuilder content = new StringBuilder();
    while ((inputLine = in.readLine()) != null) {
      content.append(inputLine);
    }
    in.close();
    return content.toString();
  }
}

The Power of Whitelisting

The most robust defense against SSRF is whitelisting. Instead of trying to block bad inputs, you should only allow known, safe inputs.

For URLs, this means defining a strict list of permitted domains, hostnames, or IP addresses that your application is allowed to connect to. Any request to a destination not on this list should be blocked.

Code for URL Whitelisting

Let's update our previous example to include a whitelist check. We'll define allowed domains and check the input URL against them before making any network requests.

This makes sure the server only connects to trusted external services.

import java.io.BufferedReader;
import java.io.InputStreamReader;
import java.net.URL;
import java.net.URLConnection;
import java.util.Arrays;
import java.util.List;

public class Main {
  private static final List<String> ALLOWED_HOSTS = Arrays.asList(
      "example.com", "mytrustedapi.com"
  );

  public static void main(String[] args) {
    String safeUrl = "http://example.com/data.txt";
    String maliciousUrl = "http://badsite.com/evil.php";

    try {
      System.out.println("\nAttempting to fetch from: " + safeUrl);
      String content = fetchContentSafely(safeUrl);
      System.out.println("Fetched (safe): " + content.substring(0, Math.min(content.length(), 50)) + "...");
    } catch (Exception e) {
      System.err.println("Error fetching (safe): " + e.getMessage());
    }

    try {
      System.out.println("\nAttempting to fetch from: " + maliciousUrl);
      String content = fetchContentSafely(maliciousUrl);
      System.out.println("Fetched (malicious): " + content.substring(0, Math.min(content.length(), 50)) + "...");
    } catch (Exception e) {
      System.err.println("Error fetching (malicious): " + e.getMessage());
    }
  }

  public static String fetchContentSafely(String urlString) throws Exception {
    URL url = new URL(urlString);
    String host = url.getHost();

    if (!ALLOWED_HOSTS.contains(host)) {
      throw new IllegalArgumentException("Host not allowed: " + host);
    }

    URLConnection connection = url.openConnection();
    BufferedReader in = new BufferedReader(
        new InputStreamReader(connection.getInputStream()));
    String inputLine;
    StringBuilder content = new StringBuilder();
    while ((inputLine = in.readLine()) != null) {
      content.append(inputLine);
    }
    in.close();
    return content.toString();
  }
}

Blacklisting: A Risky Approach

You might think blacklisting known bad IPs or domains is easier. However, blacklisting is inherently weak against SSRF.

Attackers can use various tricks to bypass blacklists:

  • IP address encoding: Using decimal, octal, or hexadecimal representations (e.g., http://0x7f000001 for localhost).
  • DNS rebinding: Changing DNS records to point a 'safe' domain to an internal IP after the initial check.
  • URL shorteners: Masking malicious URLs behind a seemingly benign short URL.
  • Special protocols: Using file://, gopher://, or data:// schemes if not explicitly blocked.

Always prefer whitelisting!

Layered Defense: Network Rules

Beyond application-level URL validation, you should also implement network-level controls:

  • Firewall rules: Configure firewalls to block outgoing connections from your application server to internal IP ranges (e.g., 10.0.0.0/8, 172.16.0.0/12, 192.168.0.0/16, 127.0.0.1/8).
  • Network segmentation: Isolate the server making external requests into its own network segment, with minimal access to other internal resources.
  • Least privilege: Ensure the application's runtime environment has only the necessary network access.

These measures provide a crucial second layer of defense.

Tricky URLs and Redirects

SSRF attacks can also exploit nuances in URL handling:

  • Inconsistent URL parsers: Different libraries or systems might interpret a URL differently, potentially bypassing your validation. Always use a consistent, robust parser.
  • HTTP Redirects: An attacker might provide a whitelisted URL that then redirects to a blacklisted internal IP. Your application must follow redirects carefully and re-validate the final destination URL.

Always validate the resolved URL after any redirects and before making the final request.

Preventing SSRF Attacks

Which of the following is the most effective strategy to prevent Server-Side Request Forgery (SSRF) vulnerabilities?

Recap: Secure Against SSRF

You've learned how to identify and prevent SSRF attacks!

  • SSRF allows a server to make unauthorized requests to internal or external systems.
  • The most effective defense is URL whitelisting, allowing connections only to trusted destinations.
  • Avoid blacklisting, as it's prone to bypasses.
  • Supplement application-level defenses with network firewalls and segmentation.
  • Be cautious of URL parsing inconsistencies and always re-validate URLs after redirects.

Keep your backend secure by strictly controlling outgoing connections!

Sıkça Sorulan Sorular

“SSRF Saldırılarını Önleme” dersi ücretsiz mi?

Evet — “SSRF Saldırılarını Önleme” dersin tüm metni burada web'de ücretsiz olarak okunabilir. Etkileşimli olarak pratik yapmak (yerleşik kod editörü ve 7/24 yapay zeka koçu) ve Secure Coding & OWASP Top 10 for Backend kursunun geri kalanını açmak için CoddyKit PRO'ya yükselt. Secure Coding & OWASP Top 10 for Backend kursu toplamda 4 dersten oluşur.

“SSRF Saldırılarını Önleme” dersinde ne öğreneceğim?

URL'leri doğrulayarak ve giden ağ isteklerini kısıtlayarak Sunucu Taraflı İstek Sahteciliği (SSRF) güvenlik açıklarını belirlemeyi ve azaltmayı öğrenin. Secure Coding & OWASP Top 10 for Backend ile uygulamalı kodu tarayıcıda doğrudan çalıştırarak pratik yaparsın ve 7/24 yapay zeka koçu dersi çalışırken sorularını yanıtlar.

Secure Coding & OWASP Top 10 for Backend öğrenmeye başlamak için deneyim gerekli mi?

Önceden deneyim gerekmez. CoddyKit'te Secure Coding & OWASP Top 10 for Backend, başlangıçtan ileri seviyeye kadar yapılandırıldığı için buradan başlayabilir veya başından başlayıp kendi hızında ilerleme yapabilirsin. Bu, 4 dersinin 3. dersidir.

“SSRF Saldırılarını Önleme” dersi ne kadar sürer?

Çoğu CoddyKit dersi yaklaşık 5–10 dakika sürer. Her biri kısa ve etkileşimli olduğu için sabit ilerleme yaparsın ve web ile uygulama arasında tam olarak bıraktığın yerden devam edebilirsin.

Bu Secure Coding & OWASP Top 10 for Backend dersinde kod yazıp çalıştırabilir miyim?

Evet. Her Secure Coding & OWASP Top 10 for Backend dersi yerleşik bir kod editörü içerir, bu sayede tarayıcıda gerçek kod yazıp çalıştırabilir ve anlık yapay zeka geri bildirimi alırsın — yerel kurulum gerekli değildir.

Bu kursun tüm dersleri

  1. Güvenli RESTful API Tasarlama
  2. GraphQL API Güvenliği
  3. SSRF Saldırılarını Önleme
  4. API Hız Sınırlama ve Kısıtlama
← Secure Coding & OWASP Top 10 for Backend Sayfasına Dön