RatFetch pulls remote assets on your behalf: paste a URL and the server fetches it. Three features do this — each is a candidate SSRF sink.
Objective: reach things the app never meant to expose. Method: map the sinks → confirm reachability (in-band body, or out-of-band with the collector for blind cases) → pivot to localhost / internal services / cloud metadata / file:// / alternate schemes → defeat naive host filters.
127.0.0.1:8099. It is NOT reachable directly and is NOT served through the /m06/ proxy — the only way to read it is to make a sink fetch it for you.