{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,9]],"date-time":"2026-07-09T15:18:57Z","timestamp":1783610337670,"version":"3.55.0"},"publisher-location":"New York, NY, USA","reference-count":45,"publisher":"ACM","license":[{"start":{"date-parts":[[2021,3,22]],"date-time":"2021-03-22T00:00:00Z","timestamp":1616371200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"funder":[{"DOI":"10.13039\/100000001","name":"National Science Foundation","doi-asserted-by":"publisher","award":["CNS-1703454"],"award-info":[{"award-number":["CNS-1703454"]}],"id":[{"id":"10.13039\/100000001","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2021,3,22]]},"DOI":"10.1145\/3412841.3442036","type":"proceedings-article","created":{"date-parts":[[2021,4,23]],"date-time":"2021-04-23T05:09:16Z","timestamp":1619154556000},"page":"1626-1635","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":32,"title":["Preventing server-side request forgery attacks"],"prefix":"10.1145","author":[{"given":"Bahruz","family":"Jabiyev","sequence":"first","affiliation":[{"name":"Northeastern University"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Omid","family":"Mirzaei","sequence":"additional","affiliation":[{"name":"Northeastern University"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Amin","family":"Kharraz","sequence":"additional","affiliation":[{"name":"Florida International University"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Engin","family":"Kirda","sequence":"additional","affiliation":[{"name":"Northeastern University"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2021,4,22]]},"reference":[{"key":"e_1_3_2_1_1_1","unstructured":"2016. The Magical Code Injection Rainbow! https:\/\/github.com\/SpiderLabs\/MCIR. Accessed: 2020-05-11."},{"key":"e_1_3_2_1_2_1","unstructured":"2017. The UFW firewall configuration tool. https:\/\/help.ubuntu.com\/community\/UFW. Accessed: 2020-06-10."},{"key":"e_1_3_2_1_3_1","unstructured":"2019. Accept-Charset. https:\/\/developer.mozilla.org\/en-US\/docs\/Web\/HTTP\/Headers\/Accept-Charset. Accessed: 2020-05-26."},{"key":"e_1_3_2_1_4_1","unstructured":"2019. Character encoding. https:\/\/developer.mozilla.org\/en-US\/docs\/Glossary\/character_encoding. Accessed: 2020-05-26."},{"key":"e_1_3_2_1_5_1","unstructured":"2019. Vulnerable Java based Web Application. https:\/\/github.com\/CSPF-Founder\/JavaVulnerableLab. Accessed: 2020-05-11."},{"key":"e_1_3_2_1_6_1","unstructured":"2019. XVWA is a badly coded web application written in PHP\/MySQL that helps security enthusiasts to learn application security. https:\/\/github.com\/s4n7h0\/xvwa. Accessed: 2020-05-11."},{"key":"e_1_3_2_1_7_1","unstructured":"2020. The Burp Suite family. https:\/\/portswigger.net\/burp. Accessed: 2020-06-10."},{"key":"e_1_3_2_1_8_1","unstructured":"2020. Configuring the instance metadata service. https:\/\/docs.aws.amazon.com\/AWSEC2\/latest\/UserGuide\/configuring-instance-metadata-service.html. Accessed: 2020-08-29."},{"key":"e_1_3_2_1_9_1","unstructured":"2020. Embed the Power of Lua into NGINX HTTP servers. https:\/\/github.com\/openresty\/lua-nginx-module. Accessed: 2020-05-08."},{"key":"e_1_3_2_1_10_1","unstructured":"2020. Implementation Materials. https:\/\/github.com\/bahruzjabiyev\/prevent-ssrf\/. Accessed: 2020-12-16."},{"key":"e_1_3_2_1_11_1","unstructured":"2020. The NGINX reverse proxy. https:\/\/www.nginx.com. Accessed: 2020-06-10."},{"key":"e_1_3_2_1_12_1","unstructured":"2020. OWASP Juice Shop: Probably the most modern and sophisticated insecure web application. https:\/\/github.com\/bkimminich\/juice-shop. Accessed: 2020-05-11."},{"key":"e_1_3_2_1_13_1","unstructured":"2020. OWASP Mutillidae II is a free open source deliberately vulnerable web-application. https:\/\/github.com\/webpwnized\/mutillidae. Accessed: 2020-05-11."},{"key":"e_1_3_2_1_14_1","unstructured":"2020. The OWASP NodeGoat project. https:\/\/github.com\/OWASP\/NodeGoat. Accessed: 2020-05-11."},{"key":"e_1_3_2_1_15_1","unstructured":"2020. Retrieving instance metadata. https:\/\/docs.aws.amazon.com\/AWSEC2\/latest\/UserGuide\/instancedata-data-retrieval.html. Accessed: 2020-04-30."},{"key":"e_1_3_2_1_16_1","unstructured":"2020. Running attacks. https:\/\/portswigger.net\/burp\/documentation\/desktop\/tools\/intruder\/attacks. Accessed: 2020-05-25."},{"key":"e_1_3_2_1_17_1","unstructured":"2020. Server Side Request Forgery. https:\/\/owasp.org\/www-community\/attacks\/Server_Side_Request_Forgery. Accessed: 2020-05-18."},{"key":"e_1_3_2_1_18_1","unstructured":"2020. Storing and retrieving instance metadata. https:\/\/cloud.google.com\/compute\/docs\/storing-retrieving-metadata. Accessed: 2020-04-30."},{"key":"e_1_3_2_1_19_1","unstructured":"2020. Unvalidated Redirects and Forwards Cheat Sheet. https:\/\/cheatsheetseries.owasp.org\/cheatsheets\/Unvalidated_Redirects_and_Forwards_Cheat_Sheet.html. Accessed: 2020-06-12."},{"key":"e_1_3_2_1_20_1","unstructured":"2020. XML External Entity (XXE) Processing. https:\/\/owasp.org\/www-community\/vulnerabilities\/XML_External_Entity_(XXE)_Processing. Accessed: 2020-05-19."},{"key":"e_1_3_2_1_21_1","unstructured":"Jobert Abma. 2017. Evaluating Ruby code by injecting Rescue job on the system_hook_push queue through web hook. https:\/\/hackerone.com\/reports\/299473"},{"key":"e_1_3_2_1_22_1","unstructured":"Peter Adkins. 2017. Pivoting from blind SSRF to RCE with HashiCorp Consul. https:\/\/www.kernelpicnic.net\/2017\/05\/29\/Pivoting-from-blind-SSRF-to-RCE-with-Hashicorp-Consul.html"},{"key":"e_1_3_2_1_23_1","unstructured":"Andre Baptista. 2018. SSRF in Exchange leads to ROOT access in all instances. https:\/\/hackerone.com\/reports\/341876"},{"key":"e_1_3_2_1_24_1","unstructured":"Alex Chapman. 2019. GitLab::UrlBlocker validation bypass leading to full Server Side Request Forgery. https:\/\/hackerone.com\/reports\/541169"},{"key":"e_1_3_2_1_25_1","unstructured":"Soroush Dalili. 2017. Request encoding to bypass web application firewalls. https:\/\/www.nccgroup.com\/uk\/about-us\/newsroom-and-events\/blogs\/2017\/august\/request-encoding-to-bypass-web-application-firewalls\/"},{"key":"e_1_3_2_1_26_1","volume-title":"Arnaud Le Hors","author":"Dave Raggett Ian Jacobs","year":"1999","unstructured":"Ian Jacobs Dave Raggett, Arnaud Le Hors. 1999. HTML 4.01 Specification. https:\/\/www.w3.org\/TR\/html401\/interact\/forms.html"},{"key":"e_1_3_2_1_27_1","unstructured":"Ed. 2017. SSRF vulnerability in gitlab.com via project import. https:\/\/hackerone.com\/reports\/215105"},{"key":"e_1_3_2_1_28_1","unstructured":"Elb. 2019. Bypass of the SSRF protection in Event Subscriptions parameter. https:\/\/hackerone.com\/reports\/386292"},{"key":"e_1_3_2_1_29_1","unstructured":"Eugene Farfel. 2016. SSRF in https:\/\/imgur.com\/vidgif\/url. https:\/\/hackerone.com\/reports\/115748"},{"key":"e_1_3_2_1_30_1","volume-title":"The Web SSO Standard OpenID Connect: In-depth Formal Security Analysis and Security Guidelines. In 2017 IEEE 30th Computer Security Foundations Symposium (CSF). 189--202","author":"Fett Daniel","year":"2017","unstructured":"Daniel Fett, Ralf K\u00fcsters, and Guido Schmitz. 2017. The Web SSO Standard OpenID Connect: In-depth Formal Security Analysis and Security Guidelines. In 2017 IEEE 30th Computer Security Foundations Symposium (CSF). 189--202."},{"key":"e_1_3_2_1_31_1","unstructured":"floyd. 2017. SVG Server Side Request Forgery (SSRF). https:\/\/hackerone.com\/reports\/223203"},{"key":"e_1_3_2_1_32_1","volume-title":"Writing Csound Opcodes in Lua. In Ways Ahead: Proceedings of the First International Csound Conference. Cambridge Scholars Publishing, 32","author":"Gogins Michael","year":"2013","unstructured":"Michael Gogins. 2013. Writing Csound Opcodes in Lua. In Ways Ahead: Proceedings of the First International Csound Conference. Cambridge Scholars Publishing, 32."},{"key":"e_1_3_2_1_33_1","doi-asserted-by":"publisher","DOI":"10.1109\/QRS.2015.42"},{"key":"e_1_3_2_1_34_1","unstructured":"James Kettle. 2019. HTTP Desync Attacks: Request Smuggling Reborn. https:\/\/portswigger.net\/research\/http-desync-attacks-request-smuggling-reborn"},{"key":"e_1_3_2_1_35_1","unstructured":"Brian Krebs. 2019. Capital One Data Theft Impacts 106M People. https:\/\/krebsonsecurity.com\/2019\/08\/what-we-can-learn-from-the-capital-one-hack\/"},{"key":"e_1_3_2_1_36_1","unstructured":"Corben Leo. 2018. Sending Emails from DNSDumpster - Server-Side Request Forgery to Internal SMTP Access. https:\/\/hackerone.com\/reports\/392859"},{"key":"e_1_3_2_1_37_1","doi-asserted-by":"publisher","DOI":"10.1109\/EuroSP.2017.32"},{"key":"e_1_3_2_1_38_1","unstructured":"OWASP. 2020. OWASP Vulnerable Web Applications Directory. https:\/\/owasp.org\/www-project-vulnerable-web-applications-directory\/"},{"key":"e_1_3_2_1_39_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-45719-2_18"},{"key":"e_1_3_2_1_40_1","unstructured":"Raymond Pompon. 2017. URL Obfuscation---Still a Phisher's Phriend. https:\/\/www.f5.com\/labs\/articles\/threat-intelligence\/url-obfuscationstill-a-phishers-phriend"},{"key":"e_1_3_2_1_41_1","unstructured":"Slim Shady. 2016. SSRF and local file read in video to gif converter. https:\/\/hackerone.com\/reports\/115857"},{"key":"e_1_3_2_1_42_1","volume-title":"SoK: XML Parser Vulnerabilities. In 10th USENIX Workshop on Offensive Technologies (WOOT 16)","author":"Sp\u00e4th Christopher","year":"2016","unstructured":"Christopher Sp\u00e4th, Christian Mainka, Vladislav Mladenov, and J\u00f6rg Schwenk. 2016. SoK: XML Parser Vulnerabilities. In 10th USENIX Workshop on Offensive Technologies (WOOT 16). USENIX Association, Austin, TX. https:\/\/www.usenix.org\/conference\/woot16\/workshop-program\/presentation\/spath"},{"key":"e_1_3_2_1_43_1","doi-asserted-by":"crossref","unstructured":"L. Masinter T. Berners-Lee R. Fielding. 2005. Uniform Resource Identifier (URI): Generic Syntax. https:\/\/tools.ietf.org\/html\/rfc3986","DOI":"10.17487\/rfc3986"},{"key":"e_1_3_2_1_44_1","unstructured":"Cheng-Da Tsai. 2017. How I Chained 4 vulnerabilities on GitHub Enterprise From SSRF Execution Chain to RCE! http:\/\/blog.orange.tw\/2017\/07\/how-i-chained-4-vulnerabilities-on.html"},{"key":"e_1_3_2_1_45_1","unstructured":"ylujion. 2016. Blind SSRF on synthetics.newrelic.com. https:\/\/hackerone.com\/reports\/141304"}],"event":{"name":"SAC '21: The 36th ACM\/SIGAPP Symposium on Applied Computing","location":"Virtual Event Republic of Korea","acronym":"SAC '21","sponsor":["SIGAPP ACM Special Interest Group on Applied Computing"]},"container-title":["Proceedings of the 36th Annual ACM Symposium on Applied Computing"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3412841.3442036","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3412841.3442036","content-type":"application\/pdf","content-version":"vor","intended-application":"syndication"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3412841.3442036","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,17]],"date-time":"2025-06-17T21:24:25Z","timestamp":1750195465000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3412841.3442036"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2021,3,22]]},"references-count":45,"alternative-id":["10.1145\/3412841.3442036","10.1145\/3412841"],"URL":"https:\/\/doi.org\/10.1145\/3412841.3442036","relation":{},"subject":[],"published":{"date-parts":[[2021,3,22]]},"assertion":[{"value":"2021-04-22","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}