Skip to content
UdemyHackingPaid courseAll LevelsCertificate

Mastering Server-Side Request Forgery (SSRF) Vulnerabilities (Udemy.com)

How to Find, Exploit and Defend Against SSRF Vulnerabilities. For Ethical Hackers, Developers & Pentesters

Created by: Experts with David Bombal

Last updated January 2024

icon
What you will learn

  • Learn how to find SSRF vulnerabilities from a black box and white box perspective.
  • Gain hands-on experience exploiting SSRF vulnerabilities using Burp Suite Community and Professional editions.
  • Learn secure coding practices to prevent and mitigate SSRF vulnerabilities.
  • Learn how to exploit SSRF vulnerabilities of varying difficulty levels.
  • Learn how to automate attacks in Python.

icon
Quality Score

No CourseDuck member has rated this course yet. Taken it? Give each part a thumbs up or down.

Content Quality
/
Video Quality
/
Qualified Instructor
/
Course Pace
/
Course Depth & Coverage
/

Overall Score : 94 / 100

icon
Course Description

Server-Side Request Forgery (SSRF) is a vulnerability that allows an attacker to coerce the application into making requests to unintended locations. SSRF attacks are typically used to establish connections with internal services, which are safeguarded by firewalls within an organization's infrastructure. This could result in sensitive data exposure, denial of service attacks, and in the most severe cases, remote code execution.


SSRF is ranked as the 10th most critical security risk facing web applications today according to the OWASP Top 10 list. Therefore, mastering the ability to identify and exploit SSRF vulnerabilities has become an essential and foundational skill.


In this course, we dive into the technical details behind SSRF vulnerabilities. We explore methods for detecting these vulnerabilities from both black-box and white-box perspectives, along with various techniques for exploiting them. Moreover, we provide insights into preventive and mitigative measures to safeguard against SSRF attacks.


This course goes beyond the basics, offering a well-balanced blend of theoretical knowledge and practical experience! It contains seven hands-on lab exercises of varying complexity levels, guiding you through the process of manually exploiting the vulnerability and then scripting and automating your exploits using Python.


By the end of this course, you'll not only have a solid understanding of SSRF vulnerabilities, but also the ability to identify and exploit these vulnerabilities in real-world applications. We've designed the course content to be beginner-friendly, so you'll never feel overwhelmed.


Whether you are a penetration tester, an application security specialist, a bug bounty hunter, a software developer, an ethical hacker, or simply someone intrigued by web application security, this course is for you!

icon
Udemy Discount

The discount is applied through our link. Open the course from here and Udemy's current promotional price is applied at checkout on most courses, no code to type.

Some courses are excluded from Udemy's promotions. If the price does not drop, clear your browser cookies and use the button again.

icon
Instructor Details

Experts with David Bombal

David Bombal, together with some of the best minds in the industry is offering courses on a wide range of topics including networking, programming and software development. Our team has decades of experience teaching students from all over the world. 

Together we can do more!

David Bombal (CCIE #11023 Emeritus) passed his Cisco Certified Internetwork Expert Routing and Switching exam in January 2003 and is one of a small percentage of Cisco Engineers that pass their CCIE labs on their first attempt.

David qualified as a Cisco Certified Systems Instructor (CCSI #22787) many years ago! He has been training Cisco courses for over 15 years and has delivered instructor led courses in various countries around the world covering a wide range of Cisco topics from CCNA to CCIE.

He has also personally developed Cisco engineer utilities such as the VPN Config Generator, software, training materials, EBooks, videos and other products which are used throughout the world.

David has designed, implemented and managed networks ranging from single sites to those that span 50 countries.



icon
More courses by Experts with David Bombal

$109.99

$74.99

$79.99

$84.99

$79.99

Free

icon
More Hacking courses

$109.99

$189.99

$84.99

$84.99

$109.99

$49.99

icon
Reviews

4.7

118 ratings on Udemy

Select a bar to show only those reviews.Select the bar again to show every rating.

By Anonymized User on 1/3/2026

I am very happy to be able to take advantage of Rana's videos. Absolutely amazing and clear explanations of each topic.

By Shivani Sripada on 11/7/2025

The video is cut at few places. Please fix it.

By Vishal Kumar on 7/1/2025

excellent lectures to understand ssrf vulnerability

By Gideon Cole on 5/20/2025

very informative and well structured

By Alon Lichtenfeld on 2/18/2025

This is a great course, I think it could be better if you made and test real it on real target like from bug bounty target. and not only on the academy. But overall its a nice course.

By Abdul Wahab on 8/22/2024

It is best course to understand SSRF vulnerability!

By Gultekin Butun on 6/28/2024

I wanted to give a full rating but I couldn't. Rana's knowledge is great, examples are great but the problem I would say is when explaining or commenting the situation. It sounds like she is lecturing a 5 years old child and therefore it is annoying in its way. Alway sounds like this; ninini niiiii ninini niiii. Otherwise a great course and I was following her since she showed up with David.

By Katende Musa on 2/27/2024

The course was good i really love it and enjoy it. if possible Rana Khalil should do more of SSRF Tutorials

By Ali Abdelmalek on 2/18/2024

this an awesome course from Rana with awesome explanation thank you.

By Tassere Dianda on 2/1/2024

Honestly it’s very nice and helpful to continue of watching that amazing course

Showing all 10 reviews on CourseDuck

Read all 118 reviews on Udemy