Server Side Request Forgery 04

Bookmarked!

This exercise is one of our challenges on Server-Side Request Forgery

PRO Easy < 1 Hr. 10034 Essential Badge
Course

In this lab, we examine a weak regular expression used to match the hostname "assets.pentesterlab.com" and demonstrate how it can be exploited due to unescaped dots and missing boundary anchors. We also discuss the implications of using <code>$_GET['url']</code> instead of a validated variable.

Injection Network
CWE-918
Full course content 2 videos

Ready to practice?

Get access to this lab and 600+ hands-on exercises with a PRO subscription.