SSRF and command injection: constrain destinations and execution

Control destinations, process invocation and privileges in fetchers, converters and administrative tools.

Contents of this article

Two distinct control boundaries

Fetchers may access user-specified destinations, while converters may launch external processes. Control outbound targets and command structure separately, even when both occur in one feature.

Validate the eventual destination

Restrict schemes, destinations and ports, and revalidate after resolution and redirects. Narrow runtime egress to required services. A plausible hostname does not authorize loopback, internal or cloud-metadata access.

Prefer libraries to shell construction

Prefer library APIs. When a process is necessary, separate executable and arguments and validate argument meaning; escaping alone may leave dangerous options. Use low privileges, restricted directories and time limits without unnecessary credentials.

Test rejection and cleanup

In an isolated test environment, verify denied destinations, timeouts, cleanup and non-sensitive errors. Keep request correlation without logging secrets. Harden process permissions and outbound access alongside perimeter controls.

References

OWASP SSRF prevention

OWASP OS command injection defense

Continue reading

Read related content

Back to industry insights Contact technical support