webPromedium

Lab 340 — PingRelay — Blind SSRF via Webhook Test

hackadvisor

Task: Flask notification platform with webhook testing feature. Solution: SSRF via webhook URL parameter to access internal admin API on localhost:3001, discovered through robots.txt.

$ ls tags/ techniques/
robots_txt_enumerationssrf_via_webhookinternal_service_discovery

🔒

Permission denied (requires tier.pro)

Sign in to access full writeups

Sign in with GitHub to continue. No email required.

$sign in

$ grep --similar

Similar writeups