webeasy

Bank

spfctf

Task: Bank web app with cashback program. Solution: Exploit GET-based transfer endpoint via CSRF through admin bot ticket system, using internal hostname from API docs to trigger SSRF and transfer funds to unlock cashback with flag.

$ ls tags/ techniques/
admin_bot_exploitationcsrf_via_get_transferssrf_internal_hostname

🔒

Permission denied (requires tier.pro)

Sign in to access full writeups

Create a free account with GitHub, then upgrade to Pro.

$ssh [email protected]