$ cat writeup.md…
$ cat writeup.md…
hackthebox
Task: Next.js 15 + Express 'Smart City' monitoring app whose endpoint-monitor feature is a full-read SSRF with only a scheme/localhost filter. Solution: use a login-issued loggedIn:false JWT to reach the SSRF sink, absorb the appended /metrics path with a query string, full-range loopback scan to find an unauthenticated CouchDB, and read the FLAG document via SSRF body reflection.
Permission denied (requires tier.pro)
Sign in with GitHub, Discord, or Google to continue. No email required.
$sign in$ grep --similar