webPromedium
Lab 90 — InsightDash — SSRF via Avatar Proxy Endpoint
hackadvisor
Task: Node.js/Express monitoring platform with avatar proxy endpoint forwarding to internal Gravatar-compatible service. Solution: Double URL-encoding to inject Gravatar d= parameter, causing internal service to fetch /admin/config and return sensitive configuration with the flag.
$ ls tags/ techniques/
ssrfnodejsnginxexpressinternal_servicegravatardouble_url_encodingavatar_proxyquery_injectionparameter_injection
internal_service_enumerationdouble_url_encoding_bypassquery_parameter_injectionssrf_via_proxygravatar_default_parameter_abuse
🔒
Permission denied (requires tier.pro)
Sign in to access full writeups
Sign in with GitHub to continue. No email required.
$sign in$ grep --similar
Similar writeups
- [web][Pro]Lab 56 — DataPulse — XXE to SSRF via SVG Avatar Upload— hackadvisor
- [web][Pro]Lab 322 — NetPulse — IP Spoofing to RCE via Polling Agent API— hackadvisor
- [web][Pro]Lab 256 — UptimeRadar — SSRF via URL Health Check— hackadvisor
- [web][Pro]Lab 275 — GatewayPulse — Proxy ACL Bypass via Path Case Normalization— hackadvisor
- [web][Pro]Lab 120 — InfraPulse— hackadvisor