Mastering Server-Side Request Forgery (SSRF) Vulnerabilities (Udemy.com)
How to Find, Exploit and Defend Against SSRF Vulnerabilities. For Ethical Hackers, Developers & Pentesters
Created by: Experts with David Bombal
Last updated January 2024
What you will learn
- Learn how to find SSRF vulnerabilities from a black box and white box perspective.
- Gain hands-on experience exploiting SSRF vulnerabilities using Burp Suite Community and Professional editions.
- Learn secure coding practices to prevent and mitigate SSRF vulnerabilities.
- Learn how to exploit SSRF vulnerabilities of varying difficulty levels.
- Learn how to automate attacks in Python.
Quality Score
No CourseDuck member has rated this course yet. Taken it? Give each part a thumbs up or down.
Overall Score : 94 / 100
Course Description
Server-Side Request Forgery (SSRF) is a vulnerability that allows an attacker to coerce the application into making requests to unintended locations. SSRF attacks are typically used to establish connections with internal services, which are safeguarded by firewalls within an organization's infrastructure. This could result in sensitive data exposure, denial of service attacks, and in the most severe cases, remote code execution.
SSRF is ranked as the 10th most critical security risk facing web applications today according to the OWASP Top 10 list. Therefore, mastering the ability to identify and exploit SSRF vulnerabilities has become an essential and foundational skill.
In this course, we dive into the technical details behind SSRF vulnerabilities. We explore methods for detecting these vulnerabilities from both black-box and white-box perspectives, along with various techniques for exploiting them. Moreover, we provide insights into preventive and mitigative measures to safeguard against SSRF attacks.
This course goes beyond the basics, offering a well-balanced blend of theoretical knowledge and practical experience! It contains seven hands-on lab exercises of varying complexity levels, guiding you through the process of manually exploiting the vulnerability and then scripting and automating your exploits using Python.
By the end of this course, you'll not only have a solid understanding of SSRF vulnerabilities, but also the ability to identify and exploit these vulnerabilities in real-world applications. We've designed the course content to be beginner-friendly, so you'll never feel overwhelmed.
Whether you are a penetration tester, an application security specialist, a bug bounty hunter, a software developer, an ethical hacker, or simply someone intrigued by web application security, this course is for you!
Instructor Details
- 4.7 Rating
118 Reviews
Experts with David Bombal
David Bombal, together with some of the best minds in the industry is offering courses on a wide range of topics including networking, programming and software development. Our team has decades of experience teaching students from all over the world.
Together we can do more!
David Bombal (CCIE #11023 Emeritus) passed his Cisco Certified Internetwork Expert Routing and Switching exam in January 2003 and is one of a small percentage of Cisco Engineers that pass their CCIE labs on their first attempt.
David qualified as a Cisco Certified Systems Instructor (CCSI #22787) many years ago! He has been training Cisco courses for over 15 years and has delivered instructor led courses in various countries around the world covering a wide range of Cisco topics from CCNA to CCIE.
He has also personally developed Cisco engineer utilities such as the VPN Config Generator, software, training materials, EBooks, videos and other products which are used throughout the world.
David has designed, implemented and managed networks ranging from single sites to those that span 50 countries.
More courses by Experts with David Bombal
Getting Started with Wireshark: The Ultimate Hands-On Course (2025)
4.8 (12,167 Reviews)
Provider: Udemy
Time: 4.4h
$109.99
Nmap for Ethical Hackers - The Ultimate Hands-On Course (2023)
4.7 (1,776 Reviews)
Provider: Udemy
Time: 3.5h
$74.99
Learn OpenSSL with a real world cheatsheet (2023)
4.6 (1,552 Reviews)
Provider: Udemy
Time: 3.7h
$79.99
OSPF for the Real World - From Zero to Hero (2023)
4.8 (1,173 Reviews)
Provider: Udemy
Time: 6.2h
$84.99
Mastering SQL Injection - The Ultimate Hands-On Course (2023)
4.7 (692 Reviews)
Provider: Udemy
Time: 9.7h
$79.99
More Hacking courses
Getting Started with Wireshark: The Ultimate Hands-On Course (2025)
4.8 (12,167 Reviews)
Provider: Udemy
Time: 4.4h
$109.99
The Ultimate Dark Web, Anonymity, Privacy & Security Course (2025)
4.8 (9,324 Reviews)
Provider: Udemy
Time: 10.3h
$189.99
The World of Computer Networking. Your CCNA starts here (2026)
4.8 (1,993 Reviews)
Provider: Udemy
Time: 15.7h
$84.99
OSPF for the Real World - From Zero to Hero (2023)
4.8 (1,173 Reviews)
Provider: Udemy
Time: 6.2h
$84.99
Ethical Hacking: Network Security & Network Layer Attack (2026)
4.8 (1,107 Reviews)
Provider: Udemy
Time: 6.6h
$109.99
Reviews
By Anonymized User on 1/3/2026
I am very happy to be able to take advantage of Rana's videos. Absolutely amazing and clear explanations of each topic.
By Shivani Sripada on 11/7/2025
The video is cut at few places. Please fix it.
By Vishal Kumar on 7/1/2025
excellent lectures to understand ssrf vulnerability
By Gideon Cole on 5/20/2025
very informative and well structured
By Alon Lichtenfeld on 2/18/2025
This is a great course, I think it could be better if you made and test real it on real target like from bug bounty target. and not only on the academy. But overall its a nice course.
By Abdul Wahab on 8/22/2024
It is best course to understand SSRF vulnerability!
By Gultekin Butun on 6/28/2024
I wanted to give a full rating but I couldn't. Rana's knowledge is great, examples are great but the problem I would say is when explaining or commenting the situation. It sounds like she is lecturing a 5 years old child and therefore it is annoying in its way. Alway sounds like this; ninini niiiii ninini niiii. Otherwise a great course and I was following her since she showed up with David.
By Katende Musa on 2/27/2024
The course was good i really love it and enjoy it. if possible Rana Khalil should do more of SSRF Tutorials
By Ali Abdelmalek on 2/18/2024
this an awesome course from Rana with awesome explanation thank you.
By Tassere Dianda on 2/1/2024
Honestly it’s very nice and helpful to continue of watching that amazing course










