<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>SSRF on seraldinho.pages.dev</title><link>https://seraldinho.pages.dev/tags/ssrf/</link><description>Recent content in SSRF on seraldinho.pages.dev</description><generator>Hugo -- gohugo.io</generator><language>es</language><managingEditor>nseral@proton.me (Nicolás Seral)</managingEditor><webMaster>nseral@proton.me (Nicolás Seral)</webMaster><copyright>© 2026 Nicolás Seral</copyright><lastBuildDate>Wed, 10 Jun 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://seraldinho.pages.dev/tags/ssrf/index.xml" rel="self" type="application/rss+xml"/><item><title>HackTheBox - Cobblestone</title><link>https://seraldinho.pages.dev/writeups/cobblestone/</link><pubDate>Wed, 10 Jun 2026 00:00:00 +0000</pubDate><author>nseral@proton.me (Nicolás Seral)</author><guid>https://seraldinho.pages.dev/writeups/cobblestone/</guid><description>OS: Linux | Dificultad: Insane | Conceptos: Apache, Vulnerabilidades encadenadas, SQLi, LFI, XSS, SSRF, Cobbler, Script custom, XML-RPC, CVE Público</description><media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://seraldinho.pages.dev/writeups/cobblestone/featured.png"/></item><item><title>HackTheBox - DevArea</title><link>https://seraldinho.pages.dev/writeups/devarea/</link><pubDate>Mon, 30 Mar 2026 00:00:00 +0000</pubDate><author>nseral@proton.me (Nicolás Seral)</author><guid>https://seraldinho.pages.dev/writeups/devarea/</guid><description>OS: Linux | Dificultad: Medium | Conceptos: Hoverfly, SSRF, Servicios, Flask, Writable bash</description><media:content xmlns:media="http://search.yahoo.com/mrss/" url="https://seraldinho.pages.dev/writeups/devarea/featured.png"/></item><item><title>SSRF</title><link>https://seraldinho.pages.dev/notas/tecnicas/ssrf/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><author>nseral@proton.me (Nicolás Seral)</author><guid>https://seraldinho.pages.dev/notas/tecnicas/ssrf/</guid><description>&lt;h1 class="relative group"&gt;Server-Side Request Forgery
 &lt;div id="server-side-request-forgery" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#server-side-request-forgery" aria-label="Ancla"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h1&gt;
&lt;p&gt;Una vulnerabilidad SSRF se da cuando un atacante manipula una aplicación para realizar solicitudes a URLs arbitrarias.&lt;/p&gt;
&lt;p&gt;Por ejemplo, si un servidor debe solicitar datos de otros servidores en función del input de un usuario, un atacante puede hacer que las solicitudes se hagan a sitios o recursos en los que el desarrollador no había pensado en un primer momento.&lt;/p&gt;</description></item></channel></rss>