Server-Side Web Attacks

Server-Side Web Attacks. Tackle advanced server-side vulnerabilities including SSRF, XXE, and JWT manipulation. Learn to chain flaws together to read sensitive files and forge administrative tokens.

Cybersecurity EngineerCybersecurity

Introduction

Server-side features can become attack paths when they fetch user-supplied URLs, resolve XML entities, or trust JWT fields without sound verification. This course explores SSRF, XXE, and JWT manipulation through terminal-based exercises against deliberately vulnerable services.

You will move from identifying each server-side behavior to demonstrating its security impact: reaching an internal service, reading local files, changing token claims, and recovering a signing secret. The final challenge chains XXE file disclosure with creation of a valid HS256 administrator token for a protected API.

What You Will Learn

  • Identify a URL-fetching parameter and verify that the server performs the outbound request.
  • Bypass a literal localhost filter with an alternative IP representation and reach an internal admin service.
  • Query a simulated cloud metadata service through SSRF and inspect staged credential data.
  • Confirm XML parsing and entity expansion, then craft an external entity that reads /etc/passwd.
  • Extract a JWT, separate its three parts, and decode Base64Url header and payload claims.
  • Forge an unsigned administrator token against a lab API that incorrectly accepts the none algorithm.
  • Chain XXE disclosure of an application secret with Python-based HS256 signing to access a protected flag.

Who This Course Is For

This intermediate course is for web security learners who understand basic request construction and want to study trust boundaries inside server-side components. It suits aspiring penetration testers, API security learners, and developers who want practical examples of unsafe URL fetching, XML parser configuration, and JWT verification.

Prerequisites: Comfort with a Linux terminal and curl, HTTP methods and headers, basic XML and JSON syntax, shell text processing and Base64 concepts, plus the ability to read a short Python script.

Learning environment: An Ubuntu 22.04 terminal with local vulnerable applications on ports 5000 and 8080, a simulated metadata service at 169.254.169.254:8000, and the Python jwt library. The first SSRF check asks the local application to fetch example.com; later exploitation targets are prepared lab services.

Frequently Asked Questions

Are the cloud metadata credentials real?

No. The metadata endpoint and its IAM-style response are simulations hosted inside the lab on port 8000. They demonstrate the request path and potential impact without using a real cloud account.

Does the XXE lab use Burp Suite or a graphical proxy?

No. You create and edit an XML payload file in the terminal and submit it with curl. The workflow teaches the request structure and parser behavior without a graphical interception tool.

Is decoding a JWT the same as breaking its encryption?

No. JWT headers and payloads are Base64Url-encoded and are normally readable; they are not protected by encryption in these labs. Security depends on correct signature verification and protection of the signing secret.

How do the two JWT attacks differ?

The guided JWT lab exploits a server that wrongly accepts alg: none, so the forged token has no signature. In the final challenge, the server correctly requires HS256; you first disclose its secret through XXE and then generate a genuinely signed administrator token.

Teacher

labby
Labby
Labby is the LabEx teacher.