Loading...
Loading...
Compare original and translation side by side
../../shared/schemas/flags.md--scopechanged--depth standard--depth deep--severitycriticalhigh../../shared/schemas/flags.md--scopechanged--depth standard--depth deep--severitycriticalhigh../../shared/frameworks/owasp-top10-2021.md../../shared/frameworks/owasp-top10-2021.mdreferences/detection-patterns.mdreferences/detection-patterns.md../../shared/schemas/flags.md**/http/****/client/****/fetch/****/request/****/webhooks/****/callbacks/****/proxy/****/gateway/****/integrations/****/connectors/****/services/****/upload/****/import/****/preview/****/unfurl/****/embed/****/pdf/****/screenshot/****/render/**../../shared/schemas/flags.md**/http/****/client/****/fetch/****/request/****/webhooks/****/callbacks/****/proxy/****/gateway/****/integrations/****/connectors/****/services/****/upload/****/import/****/preview/****/unfurl/****/embed/****/pdf/****/screenshot/****/render/**../../shared/schemas/scanners.mdsemgrepbanditgosec../../shared/schemas/scanners.mdsemgrepbanditgosecsemgrep scan --config auto --json --quiet <target>semgrep scan --config auto --json --quiet <target>http://https://file://gopher://dict://ftp://--depth deephttp://https://file://gopher://dict://ftp://--depth deep../../shared/schemas/findings.mdSSRFSSRF-001SSRF-002../../shared/schemas/findings.mdSSRFSSRF-001SSRF-002references/detection-patterns.mdreferences/detection-patterns.md| Scanner | Coverage | Command |
|---|---|---|
| semgrep | URL from user input, taint tracking through request calls | |
| bandit | Python requests/urllib with user input | |
| gosec | Go net/http with user input | |
references/detection-patterns.mdconfidence: mediumpython.requests.security.ssrf.*python.urllib.security.audit.ssrf.*javascript.fetch.security.ssrf.*java.net.security.audit.ssrf.*go.net.security.audit.ssrf.*| 扫描器 | 覆盖范围 | 命令 |
|---|---|---|
| semgrep | 用户输入URL追踪、请求调用的污点分析 | |
| bandit | Python requests/urllib的用户输入检测 | |
| gosec | Go语言net/http的用户输入检测 | |
references/detection-patterns.mdmediumpython.requests.security.ssrf.*python.urllib.security.audit.ssrf.*javascript.fetch.security.ssrf.*java.net.security.audit.ssrf.*go.net.security.audit.ssrf.*../../shared/schemas/findings.mdSSRFSSRF-001ssrfowaspA10A10:2021IE../../shared/schemas/findings.mdSSRFSSRF-001ssrfowaspA10A10:2021IE