webProeasy
Lab 58 — ReportForge — SSRF via PDF Export Logo URL
hackadvisor
Task: ReportForge business analytics platform with PDF export and company logo URL branding setting — SSRF via server-side logo fetch. Solution: set logo URL to http://localhost:3001/ to discover internal endpoints, then http://localhost:3001/flag to extract the flag embedded in the exported PDF content stream.
$ ls tags/ techniques/
internal_service_enumerationdecoy_flag_avoidancessrf_via_pdf_logo_urlpdf_content_stream_glyph_decoding
🔒
Permission denied (requires tier.pro)
Sign in to access full writeups
Sign in with GitHub to continue. No email required.
$sign in$ grep --similar
Similar writeups
- [web][Pro]Lab 116 — InsightForge — IDOR via Undocumented Internal API— hackadvisor
- [web][Pro]BillForge— hackadvisor
- [web][Pro]Lab 205 — DockForge — SSRF in Webhook Test Endpoint— hackadvisor
- [web][Pro]Lab 345 — PrintForge — RCE via Ghostscript Command Injection— hackadvisor
- [web][free]Blueprint Heist— hackthebox