Progress

0 / 5 SSRF primitives proven this session. Everything below is reachable only by abusing one of the mini-lab fetch sinks. The internal admin service is never exposed directly.

⬜ Naked / Basic SSRF - read the internal loopback service in-band (127.0.0.1:8099)
⬜ Naked / Metadata SSRF - retrieve the fake cloud IAM credentials (169.254.169.254)
⬜ Naked / file:// scheme - read a local file through the fetcher
⬜ Naked / Filter bypass - defeat the loopback string blocklist with an alternate IP encoding
⬜ Methodology / Blind pivot - OOB-confirm a blind sink, pivot internal, exfil the admin secret via the collector

← back to the practice pack index