webeasy
Bank
spfctf
Task: Bank web app with cashback program. Solution: Exploit GET-based transfer endpoint via CSRF through admin bot ticket system, using internal hostname from API docs to trigger SSRF and transfer funds to unlock cashback with flag.
$ ls tags/ techniques/
admin_bot_exploitationcsrf_via_get_transferssrf_internal_hostname
🔒
Permission denied (requires tier.pro)
Sign in to access full writeups
Create a free account with GitHub, then upgrade to Pro.
$ssh [email protected]