← LibraryTechnique entry
W-SSRF-INTERNALLateral Movement
SSRF → Internal Service Exploit
Reach Redis (FLUSHALL / config rewrite), Elasticsearch, Kibana, Consul, Memcached — often unauthenticated internally.
§ Where this technique fits
W-SSRF-INTERNAL is catalogued under the Lateral Movement tactic of the offensive-security kill-chain. It appears in 1 approved dossier in the registry, typically at step 2 on average.
§ Dossiers chaining this technique
§ What commonly comes next
- 01Redis Unauth → RCE via CONFIGseen 1×DB-REDIS-RCE · Execution