Forum Discussion

Anonymous's avatar
Anonymous
3 months ago

Server-Side Request Forgery Q6 & Q7

Hi,

I am looking for some help with the question "Exploit the SSRF vulnerability and read the configuration file of the previously identified service account, running on port 3000. What version number is the bot running?"

I have found the bot name and tried the URL 10.102.160.173/lookup?url=http://localhost:3000/svc-debug/config

However, it doesn't matter which way I try the URL; I can't seem to get it to work. Any Suggestions.

I would think that the help for this would also assist with Q7. 

1 Reply

  • Anonymous's avatar
    Anonymous

    Never mind. Got there in the end! I was looking for the results in the wrong place ;-)