Skip to content

Commit

Permalink
Update ssrf_galatic_archives.py
Browse files Browse the repository at this point in the history
  • Loading branch information
santosomar authored Jul 4, 2023
1 parent af55514 commit 1c53606
Showing 1 changed file with 2 additions and 3 deletions.
5 changes: 2 additions & 3 deletions web_application_testing/ssrf_galatic_archives.py
Original file line number Diff line number Diff line change
Expand Up @@ -6,11 +6,10 @@
import requests

# The URL of the vulnerable web service.
vulnerable_url = 'http://127.0.0.1:5000'
vulnerable_url = 'http://10.6.6.20:5000'

# The internal URL that the attacker wants to access.
# AWS EC2 instances use this URL to provide instance metadata.
# This data should be inaccessible from outside the EC2 instance.
# This is to simulate that this data (secret.txt) should be inaccessible from attacker's network.
internal_url = 'https://internal.secretcorp.org/secret.txt'

# The attacker constructs the exploit URL by appending the internal URL
Expand Down

0 comments on commit 1c53606

Please sign in to comment.