Forum Discussion

djp2891's avatar
djp2891
Icon for Bronze I rankBronze I
21 days ago

Server-Side Request Forgery Q6 & Q7

Hi,

I am looking for some help with the question "Exploit the SSRF vulnerability and read the configuration file of the previously identified service account, running on port 3000. What version number is the bot running?"

I have found the bot name and tried the URL 10.102.160.173/lookup?url=http://localhost:3000/svc-debug/config

However, it doesn't matter which way I try the URL; I can't seem to get it to work. Any Suggestions.

I would think that the help for this would also assist with Q7. 

1 Reply

  • Never mind. Got there in the end! I was looking for the results in the wrong place ;-)