URL Scheme Enforcement
The API accepts only explicitly permitted URL schemes for the URL-fetching functionality.
Prevent unsupported schemes from being processed by the server-side request mechanism.
Modern web applications and APIs frequently provide URL-fetching functionality for legitimate operations such as retrieving remote resources, processing external content, generating previews, or integrating with third-party services.
However, insecure server-side URL fetching can introduce Server-Side Request Forgery (SSRF) vulnerabilities. If a backend service accepts a user-supplied URL and directly performs the request without validating the destination, an attacker may manipulate the URL so that the server sends requests to unintended internal or restricted destinations.
In this use case, a FastAPI URL-fetching service is deployed as the controlled application and API environment on an Ubuntu virtual machine. The service provides an API endpoint that accepts a URL from the client and performs a server-side HTTP request to retrieve the requested resource.
A controlled SSRF security assessment is performed from Kali Linux. OWASP ZAP is used to intercept and analyze API requests and responses, while command-line HTTP testing tools are used to submit controlled URL values and validate server-side request behavior.
The security assessment focuses on determining whether the FastAPI service validates the destination of outbound requests before contacting external or internal resources.
The proposed defensive mechanism implements server-side outbound request validation and internal network access restriction. The application validates the supplied URL, resolves and evaluates the destination, restricts requests to approved destinations, and prevents access to protected internal network ranges.
After implementing the security controls, the SSRF assessment is repeated to verify that malicious or restricted destinations are rejected while legitimate external URL requests continue to function.
FastAPI URL-Fetching Service is used as the controlled application and API environment for testing server-side outbound-request security weaknesses. The application provides an API endpoint that accepts a URL supplied by the client and performs a server-side request to retrieve content from the specified destination. The URL-fetching functionality therefore creates a security boundary between the client-controlled URL and the server's outbound network access.
SSRF becomes possible when the backend accepts a client-controlled URL and uses it for server-side network communication without sufficiently validating the destination.
The security problem is therefore:
The proposed solution introduces server-side outbound request validation and internal network access restriction so that the FastAPI service can distinguish permitted destinations from restricted network destinations before establishing the outbound connection.
A Server-Side Request Forgery attack attempts to make a server perform a network request to a destination selected or influenced by the attacker.
In this controlled assessment, the attacker identifies a URL-fetching API endpoint that accepts a URL parameter or request-body value. Controlled URLs representing legitimate external resources and restricted destinations are submitted to determine whether the FastAPI service performs server-side requests without sufficiently restricting the destination.
The primary security concept is to validate the requested destination before the backend establishes an outbound network connection.
The application must not trust a client-supplied URL simply because it is syntactically valid or appears to reference an external hostname. It validates the URL structure and scheme, resolves the hostname, evaluates the destination IP address, and applies network access policies before allowing an outbound request.
The secure processing flow is:
The API accepts only explicitly permitted URL schemes for the URL-fetching functionality.
Prevent unsupported schemes from being processed by the server-side request mechanism.
The API validates the hostname supplied by the client before initiating the outbound request.
Prevent unrestricted client-controlled destination selection.
The application resolves the requested hostname and evaluates the resulting IP address before establishing the connection.
Prevent hostnames from resolving to restricted destinations.
The application rejects destinations belonging to configured private and internal IP ranges.
Prevent server-side requests to protected internal networks.
The application blocks requests targeting loopback destinations.
Prevent access to services running on the FastAPI server itself.
The application blocks requests targeting link-local destinations.
Prevent access to services exposed through link-local network addressing.
Where applicable, the application restricts outbound requests to explicitly approved domains or destinations.
Reduce the number of destinations that the server is permitted to contact.
The application validates destinations reached through HTTP redirects rather than automatically trusting the redirected location.
Prevent a permitted initial URL from redirecting the server toward a restricted destination.
The API rejects requests when destination validation fails instead of proceeding with the network connection.
Prevent restricted outbound requests from reaching protected network resources.
Rejected SSRF-related requests and destination-validation failures are recorded by the application.
Support security investigation and detection of repeated SSRF attempts.
OWASP ZAP is used from Kali Linux to intercept and analyze requests sent to the FastAPI URL-fetching endpoint.
cURL is used to submit controlled HTTP requests directly to the FastAPI API.
FastAPI provides the controlled URL-fetching API environment.
Ubuntu hosts the FastAPI application and supporting services.
Kali Linux is used as the controlled security-testing environment.
VirtualBox provides the isolated laboratory environment for the Ubuntu and Kali Linux virtual machines.