SSRF
Server-side request forgery persuades your own server to make a request on the attacker's behalf.
The point is where the request comes from: inside your network, from a machine other systems trust. It reaches internal services that are not exposed publicly, and in cloud it can reach the metadata endpoint holding credentials. The attacker never connects to any of it; your server does the connecting.
Checked against the primary source.
