webPromedium

110 - Retro Search (Ретро поиск) - duckerz CTF

duckerz

Task: Retro-styled search engine with URL fetch functionality. Solution: Exploited SSRF via file:// protocol to read source code, discovered WAF blocking internal IPs, bypassed WAF using decimal IP format to access internal admin service.

$ ls tags/ techniques/
source_code_analysisssrffile_protocol_lfidecimal_ip_bypass

🔒

Permission denied (requires tier.pro)

Sign in to access full writeups

Sign in with GitHub to continue. No email required.

$sign in

$ grep --similar

Similar writeups