$ cat writeup.md…
$ cat writeup.md…
hackadvisor
Task: PingRadar webhook test delivery makes server-side HTTP requests to arbitrary URLs with no SSRF protection; delivery logs expose response headers but not body (blind SSRF). Solution: port-scan localhost to find internal monitoring-aggregator on port 3001, leak x-internal-token from /health response headers via delivery log API, inject Bearer token via webhook custom headers to access /admin/export, which writes report containing flag to shared filesystem rendered on the delivery logs page.
Permission denied (requires tier.pro)
Sign in with GitHub, Discord, or Google to continue. No email required.
$sign in$ grep --similar