webProeasy

Lab 204 — PayLoom — SSRF via Webhook Testing to Cloud Metadata

hackadvisor

Task: PayLoom payment gateway with webhook test feature that fetches arbitrary URLs server-side without validation. Solution: Exploit SSRF to reach internal IMDS on localhost:3001 and extract IAM credentials containing the flag in SecretAccessKey.

$ ls tags/ techniques/
localhost_service_discoverymetadata_enumerationssrf_via_webhookiam_credential_extraction

🔒

Permission denied (requires tier.pro)

Sign in to access full writeups

Sign in with GitHub to continue. No email required.

$sign in

$ grep --similar

Similar writeups