webProeasy
Lab 256 — UptimeRadar — SSRF via URL Health Check
hackadvisor
Task: UptimeRadar monitoring platform with URL health check feature, no SSRF protection on monitor URLs. Solution: Created monitor pointing to localhost:3001 internal metadata service, extracted cloud service account access_token containing the flag.
$ ls tags/ techniques/
ssrfnodejsnginxexpressdecoy_flaginternal_service_discoverymetadata_servicehealth_checkcloud_credentialsmonitorhoneypot_flag_detection
internal_service_discoveryhoneypot_flag_detectionssrf_via_url_parametercloud_metadata_credential_theftmonitor_creation_ssrf
🔒
Permission denied (requires tier.pro)
Sign in to access full writeups
Sign in with GitHub to continue. No email required.
$sign in$ grep --similar
Similar writeups
- [web][Pro]Lab 97 — UptimePulse — SSRF Chain to RCE via Cloud Metadata— hackadvisor
- [web][Pro]Lab 247 — PulseGuard — SSTI in Webhook Notification Templates— hackadvisor
- [web][Pro]Lab 196 — ZoneDesk — SSRF via Health Monitor URL Check— hackadvisor
- [web][Pro]Lab 47 — PingRadar — Blind SSRF via Webhook Test Delivery— hackadvisor
- [web][Pro]Lab 90 — InsightDash — SSRF via Avatar Proxy Endpoint— hackadvisor