Study. uk . com
  1. Home
  2. All questions
  3. Question 162

CompTIA Security+ study material · question 162 of 611

An application fetches a URL supplied by the user to generate a link preview. Why is this dangerous?

  1. The fetch may exhaust the user's browser memory
  2. The preview may contain cross-site scripting
  3. The server can be made to reach internal addresses the attacker cannot reach directly
  4. The URL will be logged in plaintext
Show the answer

Answer: C. The server can be made to reach internal addresses the attacker cannot reach directly

Server-side request forgery is dangerous because the server sits inside the trusted network and cloud metadata endpoints.

Source: OWASP Top 10 (OWASP) — OWASP Top Ten › Server-Side Request Forgery

Challenge yourself on this topic → Study as cards