webPromedium

Lab 244 — ChatDesk — SSRF in SMS Webhook Media Processing

hackadvisor

Task: ChatDesk team communication platform with SMS webhook that fetches media URLs server-side without validation. Solution: Exploit SSRF in SMS webhook media processing to access internal metrics service on localhost:3001/flag.

$ ls tags/ techniques/
ssrf_via_webhookinternal_service_discoverytwilio_webhook_exploitationlocalhost_bypass

🔒

Permission denied (requires tier.pro)

Sign in to access full writeups

Sign in with GitHub to continue. No email required.

$sign in

$ grep --similar

Similar writeups