Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

SSRF is a thing, just because you trust the code doesn't mean you've eliminated all security risks. The tools we use in the industry should all have secure defaults.

Glad to hear you're considering changing the default!

It would be enough for me if Caddy generated a password (that's hard for attackers to predict) on first launch, set that in a config file it has write access to (autosave.json for example), and then required Basic auth using this password unless the configuration specified otherwise. My problem is that this endpoint is entirely unauthenticated.



Have you demonstrated SSRF on a server that is not running insecure or untrusted code (i.e. is not already compromised)?

We have yet to see this, but if we do see a practical demonstration, we're happy to reconsider.


You've never seen an application with an SSRF vulnerability? I've encountered multiple working as a penetration tester.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: