webPromedium
110 - Retro Search (Ретро поиск) - duckerz CTF
duckerz
Task: Retro-styled search engine with URL fetch functionality. Solution: Exploited SSRF via file:// protocol to read source code, discovered WAF blocking internal IPs, bypassed WAF using decimal IP format to access internal admin service.
$ ls tags/ techniques/
source_code_analysisssrffile_protocol_lfidecimal_ip_bypass
🔒
Permission denied (requires tier.pro)
Sign in to access full writeups
Sign in with GitHub to continue. No email required.
$sign in$ grep --similar
Similar writeups
- [web][Pro]Waf— web-kids20
- [web][Pro]Авторизация 2.0 (Authorization 2.0)— hackerlab
- [web][Pro]Квантовый прорыв (Quantum Breakthrough)— hackerlab
- [web][Pro]В поисках капибары — Hackerlab— hackerlab
- [web][Pro]Обычная страница— hackerlab