--

Completely agree my friend but when the ping back points to the domain you are hunting rather than 3rd party, then it is a valid SSRF. Hope that make sense.

--

--

Jerry Shah (Jerry)
Jerry Shah (Jerry)

Written by Jerry Shah (Jerry)

|Penetration Tester| |Hack The Box| |Digital Forensics| |Malware Analysis|

No responses yet