{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,9]],"date-time":"2026-07-09T15:18:19Z","timestamp":1783610299866,"version":"3.55.0"},"publisher-location":"Cham","reference-count":28,"publisher":"Springer International Publishing","isbn-type":[{"value":"9783319457185","type":"print"},{"value":"9783319457192","type":"electronic"}],"license":[{"start":{"date-parts":[[2016,1,1]],"date-time":"2016-01-01T00:00:00Z","timestamp":1451606400000},"content-version":"unspecified","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2016]]},"DOI":"10.1007\/978-3-319-45719-2_18","type":"book-chapter","created":{"date-parts":[[2016,9,6]],"date-time":"2016-09-06T02:11:24Z","timestamp":1473127884000},"page":"393-414","source":"Crossref","is-referenced-by-count":14,"title":["Uses and Abuses of Server-Side Requests"],"prefix":"10.1007","author":[{"given":"Giancarlo","family":"Pellegrino","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Onur","family":"Catakoglu","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Davide","family":"Balzarotti","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Christian","family":"Rossow","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2016,9,7]]},"reference":[{"key":"18_CR1","unstructured":"Almroth, F., Karlsson, M.: How we got read access on Googles production servers. http:\/\/blog.detectify.com\/post\/82370846588\/how-we-got-read-access-on-googles-production"},{"key":"18_CR2","doi-asserted-by":"crossref","unstructured":"Balzarotti, D., Cova, M., Felmetsger, V.V., Vigna, G.: Multi-module vulnerability analysis of web-based applications. In: ACM CCS 2007 (2007)","DOI":"10.1145\/1315245.1315250"},{"key":"18_CR3","doi-asserted-by":"crossref","unstructured":"Barth, A., Jackson, C., Mitchell, J.C.: Robust defenses for cross-site request forgery. In: ACM CCS 2008 (2008)","DOI":"10.1145\/1455770.1455782"},{"key":"18_CR4","doi-asserted-by":"crossref","unstructured":"Bau, J., Bursztein, E., Gupta, D., Mitchell, J.: State of the art:Automated black-box web application vulnerability testing. In: IEEE S&P 2010 (2010)","DOI":"10.1109\/SP.2010.27"},{"key":"18_CR5","unstructured":"Chauhan, J.: OWASP SKANDA - SSRF Exploitation framework. http:\/\/www.chmag.in\/article\/may2013\/owasp-skanda-%E2%80%93-ssrf-exploitation-framework"},{"key":"18_CR6","unstructured":"Eyeo GmbH: Adblock plus. https:\/\/adblockplus.org\/"},{"key":"18_CR7","unstructured":"Fielding, R., Gettys, J., Mogul, J., Frystyk, H., Masinter, L., Leach, P., Berners-Lee, T.: Hypertext Transfer Protocol \u2013 HTTP\/1.1. In: RFC 2616 (Draft Standard). Request for Comments. Internet Engineering Task Force (1999). http:\/\/www.ietf.org\/rfc\/rfc2616.txt"},{"key":"18_CR8","unstructured":"Fitzpatrick, B., Recordon, D., Hardt, D., Hoyt, J.: OpenID authentication 2.0 - Final. http:\/\/openid.net\/specs\/openid-authentication-2_0.html"},{"key":"18_CR9","unstructured":"Google Inc.: Safe browsing API. https:\/\/developers.google.com\/safe%2Dbrowsing\/"},{"key":"18_CR10","unstructured":"Grossman, J., Johansen, M.: Million browser botnet. https:\/\/media.blackhat.com\/us%2D13\/us%2D13%2DGrossman%2DMillion%2DBrowsed%2DBotnet.pdf"},{"key":"18_CR11","unstructured":"Hafif, O.: Reflected file download a new web attack vector. https:\/\/drive.google.com\/file\/d\/0B0KLoHg_gR_XQnV4RVhlNl96MHM\/view"},{"key":"18_CR12","unstructured":"Heiland, D.: Web portals gateway to information or a hole in our perimeter defenses. http:\/\/www.shmoocon.org\/2008\/presentations\/Web+portals,+gateway+to+information.ppt"},{"key":"18_CR13","unstructured":"InformAction: NoScript. https:\/\/noscript.net\/"},{"key":"18_CR14","unstructured":"Jack Whitton: SafeCurl. https:\/\/github.com\/fin1te\/safecurl"},{"key":"18_CR15","unstructured":"Kulkarni, P.: SSRF\/XSPA bug in https:\/\/www.coinbase.com 06, http:\/\/www.prajalkulkarni.com\/2013\/06\/ssrfxspa"},{"key":"18_CR16","unstructured":"ONsec Lab: SSRF Bible, Cheatsheet. https:\/\/docs.google.com\/document\/d\/1v1TkWZtrhzRLy0bYXBcdLUedXGb9njTNIJXa3u9akHM"},{"key":"18_CR17","unstructured":"OWASP: The OWASP top 10 project. https:\/\/www.owasp.org\/index.php\/Category:OWASP_Top_Ten_Project"},{"key":"18_CR18","doi-asserted-by":"crossref","unstructured":"Payet, P., Doup\u00e9, A., Kruegel, C., Vigna, G.: Ears in the wild: large-scale analysis of execution after redirect vulnerabilities. In: ACM SAC 2013 (2013)","DOI":"10.1145\/2480362.2480699"},{"key":"18_CR19","doi-asserted-by":"crossref","unstructured":"Pellegrino, G., Balzarotti, D.: Toward black-box detection of logic flaws in web applications. In: NDSS 2014 (2014)","DOI":"10.14722\/ndss.2014.23021"},{"key":"18_CR20","unstructured":"Pellegrino, G., Balzarotti, D., Winter, S., Suri, N.: In the compression Hornet\u2019s Nest: a security study of data compression in network services. In: USENIX Security 2015 (2015)"},{"key":"18_CR21","doi-asserted-by":"crossref","unstructured":"Pellegrino, G., Rossow, C., Ryba, F.J., Schmidt, T.C., W\u00e4hlisch, M.: Cashing out the great Cannon? On browser-based DDoS attacks and Economics. In: USENIX WOOT 2015 (2015)","DOI":"10.1016\/S1353-4858(15)30033-7"},{"key":"18_CR22","unstructured":"Polyakov, A., Chastukjin, D., Tyurin, A.: SSRF vs. business-critical applications. Part 1: XXE Tunnelling in SAP NetWeaver. http:\/\/erpscan.com\/wp%2Dcontent\/uploads\/2012\/08\/SSRF%2Dvs%2DBusinness%2Dcritical%2Dapplications%2Dwhitepaper.pdf"},{"key":"18_CR23","unstructured":"SANS Institute: Critical security controls for effective cyber defense. https:\/\/www.sans.org\/media\/critical-security-controls\/CSC-5.pdf"},{"key":"18_CR24","unstructured":"Santese, A.: Yahoo! SSRF\/XSPA vulnerability, 06. http:\/\/hacksecproject.com\/yahoo%2Dssrfxspa%2Dvulnerability\/"},{"key":"18_CR25","unstructured":"The MITRE Corporation: Common weakness enumeration. http:\/\/cwe.mitre.org\/"},{"key":"18_CR26","unstructured":"van Kesteren, A.: Cross-origin resource sharing - W3C Recommendation, 16 January 2014. http:\/\/www.w3.org\/TR\/cors\/"},{"key":"18_CR27","unstructured":"Walikar, R.A.: Cross site port attacks - XSPA. http:\/\/www.riyazwalikar.com\/2012\/11\/cross%2Dsite%2Dport%2Dattacks%2Dxspa%2Dpart%2D1.html"},{"key":"18_CR28","unstructured":"Zaitov, E.: Universal SSRF fuzzer. https:\/\/github.com\/kyprizel\/ussrfuzzer"}],"container-title":["Lecture Notes in Computer Science","Research in Attacks, Intrusions, and Defenses"],"original-title":[],"link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-319-45719-2_18","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2020,9,25]],"date-time":"2020-09-25T20:00:34Z","timestamp":1601064034000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/978-3-319-45719-2_18"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2016]]},"ISBN":["9783319457185","9783319457192"],"references-count":28,"URL":"https:\/\/doi.org\/10.1007\/978-3-319-45719-2_18","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"value":"0302-9743","type":"print"},{"value":"1611-3349","type":"electronic"}],"subject":[],"published":{"date-parts":[[2016]]}}}