Problem Statement
How do you detect and contain SSRF attempts in production?
Explanation
Watch for egress calls to link-local and RFC-1918 ranges, odd DNS names, and unusual response sizes from metadata hosts. Add egress allowlists at app and network layers. Log request targets and block raw redirects. Use DNS and HTTP proxies with policies to prevent direct access to internal endpoints. In cloud, harden the metadata service and use instance profiles with the latest protections. Alerts on these signals help you stop credential theft and lateral movement early.
Code Solution
SolutionRead Only
Alert if dest in 169.254.169.0/16 or 10.0.0.0/8 and Host header not in allowlist
