How Attackers Use It
Attack Summary
Attacker supplies a crafted URL that tricks the server into making requests to internal resources — cloud metadata APIs (169.254.169.254), internal admin panels, or other backend services.
- User-controlled URL input is accepted by image fetchers, webhooks, or import features.
- Attacker probes internal ranges and cloud metadata endpoints.
- Redirect abuse and DNS rebinding bypass weak allow/deny filters.
- Stolen credentials are reused for lateral movement and persistence.