SSRF via FFMPEG

Bookmarked!

This exercise covers how you can read arbitrary files when an application uses ffmpeg to render videos from a video you provide

PRO Medium < 1 Hr. 255 Media Badge
Course

This lab explores a Server Side Request Forgery (SSRF) vulnerability where attackers can exploit a web application's functionality to gain access to internal resources. The challenge is based on a BlackHat talk and involves using FFMPEG to leak the content of a specific file.

Skills covered
Injection Operating System Network
CWE-918

Ready to practice?

Get access to this lab and 600+ hands-on exercises with a PRO subscription.