<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/the-server-that-talked-back-a-deep-dive-into-ssrfs---sofia-lindqvist---ndc-security-2026-qxaad1awo" -->

---
title: The server that talked back: a deep dive into SSRFs -...
description: This talk was recorded at NDC Security in Oslo, Norway. #ndcsecurity  #ndcconferences  #security  #developer   #softwaredeveloper    

Attend the next NDC...
canonical: https://daily.dev/posts/the-server-that-talked-back-a-deep-dive-into-ssrfs---sofia-lindqvist---ndc-security-2026-qxaad1awo
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: The server that talked back: a deep dive into SSRFs - Sofia Lindqvist - NDC Security 2026 | daily.dev
og:description: This talk was recorded at NDC Security in Oslo, Norway. #ndcsecurity  #ndcconferences  #security  #developer   #softwaredeveloper    

Attend the next NDC...
og:url: https://daily.dev/posts/the-server-that-talked-back-a-deep-dive-into-ssrfs---sofia-lindqvist---ndc-security-2026-qxaad1awo
og:image: https://api.daily.dev/og/posts/qxAAD1aWo.png
og:image:alt: The server that talked back: a deep dive into SSRFs - Sofia Lindqvist - NDC Security 2026
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# The server that talked back: a deep dive into SSRFs - Sofia Lindqvist - NDC Security 2026

**[NDC Conferences](https://daily.dev/sources/ndc)** · 53 min read · 0 upvotes · 0 comments

## Summary

This talk was recorded at NDC Security in Oslo, Norway. #ndcsecurity  #ndcconferences  #security  #developer   #softwaredeveloper    

Attend the next NDC conference near you: 
https://ndcconferences.com
https://ndc-security.com/

Subscribe to our YouTube channel and learn every day:  @NDC 

Follow our Social Media!

https://www.facebook.com/ndcconferences
https://twitter.com/NDC_Conferences
https://www.instagram.com/ndc_conferences

#hacker #owasp #azure 

Server-Side Request Forgery (SSRF) is a web application vulnerability where an attacker forces a web server to make a request to a URL of the attackers choosing. SSRFs can be used for instance to bypass access controls, access hidden internal resources or access cloud credentials. These vulnerabilities are nothing new. In fact the term SSRF has been in use for nearly twenty years, and since 2021 SSRF has been a part of the OWASP top 10 list. Even though the bug class has been around "forever", SSRF vulnerabilities still keep turning up, and applications keep failing to properly protect against them.

In this talk we'll start with the most basic example of an SSRF, and then work our way to increasingly more interesting cases. There will be real world examples of bugs found during engagements and in the wild in products like Azure, as well as examples of bypasses of the mitigations made by the vendors.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://www.youtube.com/watch?v=FHR1bLf7JUU>

## Similar posts on daily.dev

- [Don’t just attend KubeCon \+ CloudNativeCon, Merge Forward your experience\!](https://daily.dev/posts/don-t-just-attend-kubecon-cloudnativecon-merge-forward-your-experience--l0rpp73x8) · CNCF · 1 upvotes · 0 comments
- [Announcing H2 2026 KCDs](https://daily.dev/posts/announcing-h2-2026-kcds-m96goajm1) · CNCF · 1 upvotes · 0 comments
- [Two months of Open Community Groups](https://daily.dev/posts/two-months-of-open-community-groups-asf52zhbs) · CNCF · 0 upvotes · 0 comments

---

Tags: [#security](https://daily.dev/tags/security), [#azure](https://daily.dev/tags/azure)

[View this post on daily.dev](https://daily.dev/posts/the-server-that-talked-back-a-deep-dive-into-ssrfs---sofia-lindqvist---ndc-security-2026-qxaad1awo)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"The server that talked back: a deep dive into SSRFs - Sofia Lindqvist - NDC Security 2026","url":"https://daily.dev/posts/the-server-that-talked-back-a-deep-dive-into-ssrfs---sofia-lindqvist---ndc-security-2026-qxaad1awo","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/the-server-that-talked-back-a-deep-dive-into-ssrfs---sofia-lindqvist---ndc-security-2026-qxaad1awo"},"datePublished":"2026-03-19T13:51:57.500Z","dateModified":"2026-03-19T15:38:55.101Z","description":"This talk was recorded at NDC Security in Oslo, Norway. #ndcsecurity  #ndcconferences  #security  #developer   #softwaredeveloper    \n\nAttend the next NDC...","image":"https://i.ytimg.com/vi/FHR1bLf7JUU/sddefault.jpg","thumbnailUrl":"https://i.ytimg.com/vi/FHR1bLf7JUU/sddefault.jpg","isAccessibleForFree":true,"articleSection":"NDC Conferences","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"NDC Conferences","logo":"https://media.daily.dev/image/upload/s--SiIyojEj--/f_auto/v1748760369/logos/ndc","url":"https://daily.dev/sources/ndc"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/the-server-that-talked-back-a-deep-dive-into-ssrfs---sofia-lindqvist---ndc-security-2026-qxaad1awo","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":0},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"security,azure","timeRequired":"PT53M","video":{"@type":"VideoObject","name":"The server that talked back: a deep dive into SSRFs - Sofia Lindqvist - NDC Security 2026","description":"This talk was recorded at NDC Security in Oslo, Norway. #ndcsecurity  #ndcconferences  #security  #developer   #softwaredeveloper    \n\nAttend the next NDC...","thumbnailUrl":"https://i.ytimg.com/vi/FHR1bLf7JUU/sddefault.jpg","uploadDate":"2026-03-19T13:51:57.500Z","duration":"PT53M","url":"https://api.daily.dev/r/qxAAD1aWo","embedUrl":"https://www.youtube.com/embed/FHR1bLf7JUU"}}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"NDC Conferences","item":"https://daily.dev/sources/ndc"},{"@type":"ListItem","position":3,"name":"The server that talked back: a deep dive into SSRFs - Sofia Lindqvist - NDC Security 2026"}]}
```

