Dashboard

RatFetch asset importer

RatFetch pulls remote assets on your behalf: paste a URL and the server fetches it. Three features do this — each is a candidate SSRF sink.

Objective: reach things the app never meant to expose. Method: map the sinks → confirm reachability (in-band body, or out-of-band with the collector for blind cases) → pivot to localhost / internal services / cloud metadata / file:// / alternate schemes → defeat naive host filters.

Note: there is an internal admin service bound to 127.0.0.1:8099. It is NOT reachable directly and is NOT served through the /m06/ proxy — the only way to read it is to make a sink fetch it for you.