Sec Research Lab
Infrastructure Lab

SSRF Playground

Lab Progress0%

Level 1: Basic SSRF

Server-Side Request Forgery allows an security tester to force the server to make requests to internal resources that are not directly accessible from the outside.

Objective

Access the local metadata service at http://169.254.169.254 to retrieve sensitive cloud credentials.

Educational Purpose Only — Practice only on systems you own or have explicit written permission to test.