webProeasy

Lab 256 — UptimeRadar — SSRF via URL Health Check

hackadvisor

Task: UptimeRadar monitoring platform with URL health check feature, no SSRF protection on monitor URLs. Solution: Created monitor pointing to localhost:3001 internal metadata service, extracted cloud service account access_token containing the flag.

$ ls tags/ techniques/
internal_service_discoveryhoneypot_flag_detectionssrf_via_url_parametercloud_metadata_credential_theftmonitor_creation_ssrf

🔒

Permission denied (requires tier.pro)

Sign in to access full writeups

Sign in with GitHub to continue. No email required.

$sign in

$ grep --similar

Similar writeups