Rule Name:Disable File Protocol In ARGS for Blocking SSRF Attack
Severity:critical
CVE ID:
Descripiton:
SSRF(Server-Side Request Forgery)is a security vulnerability constructed by an attacker to form a request initiated by the server. The ways using SSRF: 1)Let the server visit the corresponding URL; 2)You can use file, dict, gopher, ftp protocol to request access to the corresponding file; 3)Attack intranet web applications; 4)Attact intranet applications; 5)visit to see if there is a port open. This rule supports to defend the A3: Injection of OWASP Top 10 - 2021. Other reference:None