Skip to main content
Server-side request forgery

Server-side request forgery

Search complete. 62 mentions across 32 episodes found for "Server-side request forgery".

Sep 12, 2026

David GibsonHOST
9:32
This attack has been unfolding for a while.
David GibsonHOST
9:36
In May, late May, agents learned how to exploit the flaw in our artifactory, right, the SSRF flaw there.
David GibsonHOST
9:45
around July 8th there was an agent called phase one one zero eight four one crazy name right um but uh decided it it wasn't going to get to where it wanted to go the way it was going so it devised a new strategy and it established a message board which is kind of what you're talking about it's a little bit of memory persistence uh and it did that using artifactory And we'll talk about JFrog a little bit later too, but within a few hours, more than 50 agents started using it to work together.
David GibsonHOST
10:21
They hid evidence of cheating, not necessarily from humans, but from the automated scoring processes.
Joseph ThackerHOST
10:50
And then I'll go ahead and do the follow up.
Joseph ThackerHOST
10:52
Basically there was another thing where, um, kind of like you can, you can think of it as like another CSP bypass where on like Google, you can use like Google scripts to exfiltrate it basically on this same root domain that you actually do have access to like set up an SSRF or not.
Joseph ThackerHOST
11:06
Sorry.
Joseph ThackerHOST
11:06
I like a request handler.
Ido GeffenGUEST
57:49
the best practices in the industry.
Ido GeffenGUEST
57:52
Um, and you're right with covering from cross-site scripting, SSRF, um, privilege escalation, a-and et cetera.
Ido GeffenGUEST
58:00
But our claim to fame specifically at Novi is the ability to detect, um, novel business logic vulnerabilities.
Ido GeffenGUEST
58:07
Uh, I can give you examples.

8 MINS LATER

Ido GeffenGUEST
65:53
... uh, when it comes to prompts, but also there is a lot of issues when it comes to...
Ido GeffenGUEST
65:58
There's no question that the frontier models are capable of detecting vulnerabilities, but again, when it comes to precision, how many of, of those are really true positive? So the bottleneck really moved from finding issues to being validate what is truly exploitable and what is not.
Mike ShimaHOST
66:14
And I think what is important here, I, I, I think what you're also checking is it's good to have that benchmark, that training gym, just to say, we can find this type of input validation, SSRF, business logic, but you're also testing...
Mike ShimaHOST
66:26
I don't have a good metaphor here for the, for the, a physical gym yet, but what the cost.
Ido GeffenGUEST
57:42
So for example, when it comes to web applications, so we are mapping ourselves to OWSTG, which is the best practices in the industry.
Ido GeffenGUEST
57:52
And you're right, we're covering from cross-site scripting, SSRF, privilege escalation, etc., But our claim to fame specifically at Novi is the ability to detect novel business logic vulnerabilities.
Ido GeffenGUEST
58:07
I can give you examples.
Ido GeffenGUEST
58:08
Yeah, please.

8 MINS LATER

Ido GeffenGUEST
65:47
So what we're seeing in large organizations that are trying those types of tools, getting into very big checks when it comes to prompts, but also there is a lot of issues when it comes to, there's no question that the frontier models are capable of detecting vulnerabilities.
Ido GeffenGUEST
66:02
But again, when it comes to precision, how many of those are really true positive? So the bottleneck really moved from finding issues to being validate what is truly exploitable and what is not.
Mike SchemaHOST
66:14
And I think what is important here, I think what you're also checking is, it's good to have that benchmark, that training gym, just to say, we can find this type of input validation, SSRF business logic.
Mike SchemaHOST
66:25
but you're also testing, I don't have a good metaphor here for a physical jib yet, but what the cost, like what does it cost to find this? And I think, can you tell us a little bit about what that benchmark looks like?
Ido GeffenGUEST
57:42
So for example, when it comes to web applications, so we are mapping ourselves to OWSTG, which is the best practices in the industry.
Ido GeffenGUEST
57:52
And you're right, we're covering from cross-site scripting, SSRF, privilege escalation, et cetera.
Ido GeffenGUEST
58:00
But our claim to fame specifically at Novi is the ability to detect novel business logic vulnerabilities.
Ido GeffenGUEST
58:07
I can give you examples.

7 MINS LATER

Ido GeffenGUEST
65:25
Yeah, so one of the big things, especially for very large enterprises, the ones that have thousands of applications and they want to test it continuously, Part of the unique thing that we are providing is the fact that we are optimizing all the time the right models for the right tasks and building our own model is the ability to provide a predictable cost.
Ido GeffenGUEST
65:47
So what we're seeing in large organizations that are trying those types of tools, getting into very big checks when it comes to prompts, but also there is a lot of issues when it comes to, there's no question that The frontier models are capable of detecting vulnerabilities, but again, when it comes to precision, how many of those are really true positive? So the bottleneck really moved from finding issues to being validate what is truly exploitable and what is not.
Mike SchemaHOST
66:14
And I think what is important here, I think what you're also checking is, it's good to have that benchmark, that training gym, just to say, we can find this type of input validation, SSRF business logic.
Mike SchemaHOST
66:25
but you're also testing, I don't have a good metaphor here for a physical jib yet, but what the cost, like what does it cost to find this? And I think, can you tell us a little bit about what that benchmark looks like?
Ido GeffenGUEST
57:42
So for example, when it comes to web applications, so we are mapping ourselves to OWSTG, which is the best practices in the industry.
Ido GeffenGUEST
57:52
And you're right, we're covering from cross-site scripting, SSRF, privilege escalation, etc., But our claim to fame specifically at Novi is the ability to detect novel business logic vulnerabilities.
Ido GeffenGUEST
58:07
I can give you examples.
Ido GeffenGUEST
58:08
Yeah, please.

8 MINS LATER

Ido GeffenGUEST
65:47
So what we're seeing in large organizations that are trying those types of tools, getting into very big checks when it comes to prompts, but also there is a lot of issues when it comes to, there's no question that the frontier models are capable of detecting vulnerabilities.
Ido GeffenGUEST
66:02
But again, when it comes to precision, how many of those are really true positive? So the bottleneck really moved from finding issues to being validate what is truly exploitable and what is not.
Mike SchemaHOST
66:14
And I think what is important here, I think what you're also checking is, it's good to have that benchmark, that training gym, just to say, we can find this type of input validation, SSRF business logic.
Mike SchemaHOST
66:25
but you're also testing, I don't have a good metaphor here for a physical jib yet, but what the cost, like what does it cost to find this? And I think, can you tell us a little bit about what that benchmark looks like?
Duane LaFlotteHOST
14:56
It is super easy to run.
Duane LaFlotteHOST
14:58
Um, it is a form of SSRF, which is a server side request forgery attack.
Carl FranklinHOST
15:03
Yeah.
Duane LaFlotteHOST
15:03
Um, so for those of you who haven't, like, been familiar with SSRF attacks, an SSRF attack is where I can make a call out to a service, whether it's a web server or in this case a VPN service.
Duane LaFlotteHOST
15:16
Um, most of the SonicWall VPN services are a web server.
Duane LaFlotteHOST
15:20
Whatever.
Duane LaFlotteHOST
15:25
Um, but you go out to a website, and you make a request, and what happens is that server then makes a request to itself on your behalf.
Duane LaFlotteHOST
15:34
So it looks like it's coming from inside.
James AzarHOST
2:49
which is suggesting attackers are chaining them.
James AzarHOST
2:53
So the unauthenticated SSRF bug for a foothold, and then command injection bug to actually execute code.
James AzarHOST
3:02
And this hits the SMA 1000 series specifically, the 6210, 7210, and 8200 V models.
James AzarHOST
3:09
The separate SMA 100 series and SonicWall's SSL VPN on its firewall are not affected by this, so don't confuse the product lines.
Shane ThomasHOST
12:57
The sandbox needed access to a local JFrog artifactory server.
Shane ThomasHOST
13:02
Anyways, the models use the basic SSRF exploit to route web traffic through the proxy to the public internet.
Shane ThomasHOST
13:09
Stop.
Shane ThomasHOST
13:09
Did they vibe up this isolated environment? Their IT team can't be this bad.
speaker_0NARRATOR
2:56
Cover a broad range, not only injection.
speaker_0NARRATOR
2:59
Invent realistic situations, weak password reset, unencrypted password storage, outdated library, verbose error messages, IDER on TaskEd, missing logs on failed logins, an SSRF via an import from URL feature, etc.
speaker_0NARRATOR
3:14
Step 3.
speaker_0NARRATOR
3:15
Map each scenario.

22 more episodes mention Server-side request forgery.

Create an account to see the whole feed, search across every transcript, and follow the entities you care about.

We value your privacy

We use cookies to understand how you use our platform and to improve your experience. Click “Accept All” to consent, or “Decline non-essential” to opt out of non-essential cookies. Read our Privacy Policy.