webPromedium
Lab 244 — ChatDesk — SSRF in SMS Webhook Media Processing
hackadvisor
Task: ChatDesk team communication platform with SMS webhook that fetches media URLs server-side without validation. Solution: Exploit SSRF in SMS webhook media processing to access internal metrics service on localhost:3001/flag.
$ ls tags/ techniques/
ssrf_via_webhookinternal_service_discoverytwilio_webhook_exploitationlocalhost_bypass
🔒
Permission denied (requires tier.pro)
Sign in to access full writeups
Sign in with GitHub to continue. No email required.
$sign in$ grep --similar
Similar writeups
- [web][Pro]Lab 226 — LiveDesk — SQL Injection via WebSocket Message Search— hackadvisor
- [web][Pro]Lab 92 — EventPulse — SSRF via IPv6 Bypass in Webhook Verification— hackadvisor
- [web][Pro]Lab 340 — PingRelay — Blind SSRF via Webhook Test— hackadvisor
- [web][Pro]Lab 204 — PayLoom — SSRF via Webhook Testing to Cloud Metadata— hackadvisor
- [web][Pro]Lab 247 — PulseGuard — SSTI in Webhook Notification Templates— hackadvisor