webPromedium

Lab 205 — DockForge — SSRF in Webhook Test Endpoint

hackadvisor

Task: DockForge container registry with webhook test feature that performs server-side HTTP requests without SSRF protection. Solution: Created webhook pointing to internal metadata service (127.0.0.1:3001) disclosed in settings page, triggered test delivery to extract secrets via full-read SSRF.

$ ls tags/ techniques/
ssrf_via_webhookinternal_service_discoverywebhook_test_endpoint_abuseno_url_validationfull_read_ssrf

🔒

Permission denied (requires tier.pro)

Sign in to access full writeups

Sign in with GitHub to continue. No email required.

$sign in

$ grep --similar

Similar writeups