SSRF Sentinel 2D: Server-Side Request Forgery Defense
Interactive 2D SSRF simulator: fire crafted URL payloads at a web server's outbound-fetch feature and watch validation modes (none, blocklist, allowlist, allowlist+DNS re-resolve) allow or block requests to the public internet, private LAN, loopback and the cloud metadata service. Drag to pan, scroll to zoom.
Every "fetch a URL for me" feature — image proxies, webhook senders, PDF renderers, link previews — is a potential Server-Side Request Forgery vector: an attacker who controls the URL can point the server at internal-only destinations, including the cloud metadata service that hands out IAM credentials with no authentication. This 2D simulator fires seven realistic payloads, including numeric-IP obfuscation and DNS-rebinding bypasses, through four server-side validation modes and renders each request as a dot traveling from the client through a gateway checkpoint to its real destination — public internet, private network, or cloud metadata — so you can watch exactly where a naive blocklist or a parse-time-only allowlist lets a request slip past defenses that a connect-time re-resolve would have caught. Drag the canvas to pan and scroll to zoom around the topology.
Fire seven realistic SSRF payloads — including decimal-IP obfuscation and DNS rebinding — through four server-side validation modes on a top-down 2D map and watch which ones leak a request to the private network or the cloud metadata service.
2D · HTML5 Canvas 2D · 60 FPS target · runs fully client-side, no install