This document summarizes vulnerabilities related to content delivery networks (CDNs) and server-side request forgery (SSRF). It discusses how CDNs are used to deliver content for many popular websites, and the security risks if a vulnerability is found in a CDN provider. It also explains how SSRF allows attackers to perform requests from a web server to internal systems and networks. Tools for DNS reconnaissance and exploiting SSRF are presented. The document further explores how Flash can be used to bypass the same-origin policy by loading content from other domains using vulnerabilities in plugins like FlowPlayer.