webProeasy

Lab 273 — AuthForge — SSRF via OAuth Dynamic Client Registration

hackadvisor

Task: OAuth 2.0 identity platform with Dynamic Client Registration (RFC 7591) where logo_uri is fetched server-side without SSRF protections. Solution: Registered OAuth client with logo_uri pointing to localhost:3001 internal metadata service, then accessed the logo endpoint to exfiltrate secrets including the flag.

$ ls tags/ techniques/
ssrf_via_logo_urioauth_dynamic_client_registration_abuseinternal_metadata_service_accesslocalhost_ssrf

🔒

Permission denied (requires tier.pro)

Sign in to access full writeups

Sign in with GitHub to continue. No email required.

$sign in

$ grep --similar

Similar writeups