$ cat writeup.md…
$ cat writeup.md…
hackadvisor
Task: PingRadar webhook platform has a Webhook Tester (SSRF vector) and an unauthenticated Click Tracking open redirect; SSRF blocklist blocks private IPs but not the app's own internal hostname. Solution: Chain the open redirect through the internal hostname to bypass SSRF filter — webhook tester fetches app.pingradar.local:8080/api/track which 302-redirects to localhost:3001 cloud metadata service, leaking IAM credentials containing the flag.
Permission denied (requires tier.pro)
Sign in with GitHub, Discord, or Google to continue. No email required.
$sign in$ grep --similar