> ## Documentation Index
> Fetch the complete documentation index at: https://rootea.es/llms.txt
> Use this file to discover all available pages before exploring further.

# Blind SSRF with Shellshock exploitation

> PortSwigger Web Security Academy lab: Blind SSRF with Shellshock exploitation. Topic: SSRF (Server-Side Request Forgery).

# Blind SSRF with Shellshock exploitation

<p className="machine-summary"><span className="prompt"><code>\$ tldr</code></span> PortSwigger · SSRF (Server-Side Request Forgery)</p>

<div className="machine-meta">
  | ·            | ·                                                                                   |
  | ------------ | ----------------------------------------------------------------------------------- |
  | Platform     | PortSwigger Web Security Academy                                                    |
  | Topic        | SSRF (Server-Side Request Forgery)                                                  |
  | Difficulty   | <span className="dbadge dbadge-easy">APPRENTICE</span>                              |
  | Official lab | [Open](https://portswigger.net/web-security/ssrf/blind/lab-shellshock-exploitation) |
</div>

## Solve the lab

| Language | Author          | Format | Link                                                                                |
| -------- | --------------- | ------ | ----------------------------------------------------------------------------------- |
| 🇬🇧 EN  | **PortSwigger** | Texto  | [Open](https://portswigger.net/web-security/ssrf/blind/lab-shellshock-exploitation) |

## Resources by skill

| Skill                       | Source     | Link                                                                                                                                                              |
| --------------------------- | ---------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Shellshock (CVE-2014-6271)  | HackTricks | [Open](https://book.hacktricks.wiki/en/network-services-pentesting/pentesting-web/php-tricks-esp/php-useful-functions-disable_functions-open_basedir-bypass.html) |
| Shellshock (CVE-2014-6271)  | Exploit-DB | [Open](https://www.exploit-db.com/exploits/34900)                                                                                                                 |
| Server-Side Request Forgery | HackTricks | [Open](https://book.hacktricks.wiki/en/pentesting-web/ssrf-server-side-request-forgery/index.html)                                                                |

## Related skills

[Shellshock (CVE-2014-6271)](/en/skills/shellshock) · [Server-Side Request Forgery](/en/skills/ssrf)

***

## Comments & tips

Solved this lab a different way? Share it here — comments live in [GitHub Discussions](https://github.com/FFuson/HTB_Writeups/discussions).

<div className="rootea-giscus-wrap" data-giscus-term="lab:ssrf-blind-shellshock-exploitation" data-giscus-lang="en" />

*Last updated: 2026-06-07*

<script type="application/ld+json">
  {`{"@context":"https://schema.org","@type":"TechArticle","name":"Blind SSRF with Shellshock exploitation","headline":"Blind SSRF with Shellshock exploitation — PortSwigger lab index","url":"https://rootea.es/en/portswigger/labs/ssrf/blind-shellshock-exploitation","inLanguage":"en","about":[{"@type":"Thing","name":"PortSwigger Web Security Academy"},{"@type":"Thing","name":"SSRF (Server-Side Request Forgery)"}],"isPartOf":{"@type":"WebSite","name":"rootea.es","url":"https://rootea.es"},"author":{"@type":"Organization","name":"rootea.es"}}`}
</script>
