Surfer
SSRF Exploitation
Writeup
Only 2 ports was open -
HTTP
andSSH
Disallowed Entry:
/backup/chat.txt
Which confirms the credentials to be
admin:admin
Logging in, we find an
export2pdf
functionalityNoticed in Burp, fetches contents from an
internal server
Bruteforcing directory
/internal
->/admin.php
Visiting that, it says
This page can only be accessed locally
Modifying the POST data via Burp from
url=http://127.0.0.1/service-info.php
tourl=http://127.0.0.1/internal/admin.php
Gives us the flag !
Last updated