Fixing the Unfixable: Story of a Google Cloud SSRF
bugs.xdavidhu.me
bugs.xdavidhu.me
Ouch. Surely this is a violation of Google's own privacy policy and possibly GDPR? How did this make it to prod?
Someone might want to refer Google to one of the data protection authorities here...
Validating the URL at the app layer is difficult because a redirect could happen to an attacker URL, or DNS rebinding attack, etc, proxying via Smokescreen seems the most reliable if you’re dealing with user controlled arbitrary URLs.
Smokescreen sits between your app server and the destination URL that was requested, as a proxy server, that has ACLs/rules about what URLs and domains it allows to talk to on behalf of the app server.
You define allowed or blocked domains/routes in Smokescreen, and it’s the one that decides to access the remote URL or not.
So in the above example, the app server would still have been tricked to request the attackers URL with its auth token included, but smokescreen would have realised that server/domain isn’t in its allow list, and blocked the app server attempt to access the attackers sever with the auth token by refusing to even attempt to connect to the attackers server in the first place (and returns a HTTP error back to the app server).