> ## Documentation Index
> Fetch the complete documentation index at: https://rootea.es/llms.txt
> Use this file to discover all available pages before exploring further.

# SSRF via flawed request parsing

> PortSwigger Web Security Academy lab: SSRF via flawed request parsing. Tema: HTTP Host Header Attacks.

# SSRF via flawed request parsing

<p className="machine-summary"><span className="prompt"><code>\$ tldr</code></span> PortSwigger · HTTP Host Header Attacks</p>

<div className="machine-meta">
  | ·           | ·                                                                                                                    |
  | ----------- | -------------------------------------------------------------------------------------------------------------------- |
  | Plataforma  | PortSwigger Web Security Academy                                                                                     |
  | Tema        | HTTP Host Header Attacks                                                                                             |
  | Dificultad  | <span className="dbadge dbadge-medium">PRACTITIONER</span>                                                           |
  | Lab oficial | [Abrir](https://portswigger.net/web-security/host-header/exploiting/lab-host-header-ssrf-via-flawed-request-parsing) |
</div>

## Resolver el lab

| Idioma  | Autor           | Formato | Enlace                                                                                                               |
| ------- | --------------- | ------- | -------------------------------------------------------------------------------------------------------------------- |
| 🇬🇧 EN | **PortSwigger** | Texto   | [Abrir](https://portswigger.net/web-security/host-header/exploiting/lab-host-header-ssrf-via-flawed-request-parsing) |

## Recursos por skill

| Skill                       | Fuente      | Enlace                                                                                              |
| --------------------------- | ----------- | --------------------------------------------------------------------------------------------------- |
| HTTP Host Header Attacks    | PortSwigger | [Abrir](https://portswigger.net/web-security/host-header)                                           |
| Server-Side Request Forgery | HackTricks  | [Abrir](https://book.hacktricks.wiki/en/pentesting-web/ssrf-server-side-request-forgery/index.html) |

## Skills relacionadas

[HTTP Host Header Attacks](/skills/host-header-attacks) · [Server-Side Request Forgery](/skills/ssrf)

***

## Comentarios y truquillos

¿Has resuelto el lab por una vía distinta? Compártela aquí — los comentarios viven en [GitHub Discussions](https://github.com/FFuson/HTB_Writeups/discussions).

<div className="rootea-giscus-wrap" data-giscus-term="lab:host-header-exploiting-host-header-ssrf-via-flawed-request-parsing" data-giscus-lang="es" />

*Última actualización: 2026-05-08*

<script type="application/ld+json">
  {`{"@context":"https://schema.org","@type":"TechArticle","name":"SSRF via flawed request parsing","headline":"SSRF via flawed request parsing — PortSwigger lab index","url":"https://rootea.es/portswigger/labs/host-header/exploiting-host-header-ssrf-via-flawed-request-parsing","inLanguage":"es","about":[{"@type":"Thing","name":"PortSwigger Web Security Academy"},{"@type":"Thing","name":"HTTP Host Header Attacks"}],"isPartOf":{"@type":"WebSite","name":"rootea.es","url":"https://rootea.es"},"author":{"@type":"Organization","name":"rootea.es"}}`}
</script>
