SSRF Workshop

Goal: find a string like flag{[a-zA-Z0-9_!]+} and submit it here.

🚩Task 1 "Key for babushka"

Legend: Granny makes screenshots of pages that she visits, so that she remembers where she was. On the page whatever resource you request, you get it's screenshot in response

Exploitation: Granny lost her rsa key somewhere. You need to figure out how to request rsa key and return it to Granny

🚩Task 2 "Z00m for dedushka"

Legend: Grandpa's sight is rather poor, so he uses a service-lens. You can request any resource with this service and you will get a content in a large scale in response

Exploitation: Grandpa wants to solve some memory issues. You need to find a way to access profiler and metrics

Note: When you find the flag inspect carefully other data that you get. This will help you with the 3rd task

🚩Task 3 "Big Data for vnuchok"

Legend: Grandson with his grandpa run a start-up, that works involving big data. You can request an arbitrary URI, in response you’ll get the level of its redisification.

Exploitation: somewhere on the intranet there is a database of a redisificator. You need to find a way to access this data

Note: ask Grandpa how to find redisificator on the intranet