webPromedium

Lab 90 — InsightDash — SSRF via Avatar Proxy Endpoint

hackadvisor

Task: Node.js/Express monitoring platform with avatar proxy endpoint forwarding to internal Gravatar-compatible service. Solution: Double URL-encoding to inject Gravatar d= parameter, causing internal service to fetch /admin/config and return sensitive configuration with the flag.

$ ls tags/ techniques/
internal_service_enumerationdouble_url_encoding_bypassquery_parameter_injectionssrf_via_proxygravatar_default_parameter_abuse

🔒

Permission denied (requires tier.pro)

Sign in to access full writeups

Sign in with GitHub to continue. No email required.

$sign in

$ grep --similar

Similar writeups