webProeasy

Lab 341 — KeyVault2FA — SSRF via OTP Account Import

hackadvisor

Task: KeyVault2FA 2FA management platform with OTP account import that fetches icon URLs server-side without validation. Solution: Exploit SSRF via image parameter in otpauth:// URI to access internal config service on localhost:3001/flag, with non-image response body leaked in body_preview field.

$ ls tags/ techniques/
internal_service_enumerationdecoy_flag_avoidancessrf_via_otpauth_image_parameternon_image_response_body_leak

🔒

Permission denied (requires tier.pro)

Sign in to access full writeups

Sign in with GitHub to continue. No email required.

$sign in

$ grep --similar

Similar writeups