Authorized Security Assessment

SSRF Proof of Concept

This page is served through the application's SSRF vulnerability

⚠️

Server-Side Request Forgery — Content Injection via Proxy

This page is hosted on an attacker-controlled server but rendered under the application's domain. Because the browser treats this as same-origin content, all cookies, localStorage, and session tokens for this domain are accessible to this page.

Demonstrated Data Access
Cookies (document.cookie)
Collecting...
localStorage Keys
Collecting...
Session / Origin Info
Collecting...
Browser Fingerprint
Collecting...
Simulated Exfiltration Log
Impact if Users Browse This URL
Phishing Simulation

The form below demonstrates how an attacker could present a fake login page that appears to be served from the company's domain. Users would have no visual indicator that this is malicious.