An image importer aimed inward
25 points · about 45 minutes · flag formatDC{...}Brief
Server-side request forgery is coercing a server into making a request on your behalf. When a feature fetches a URL you supply — a webhook, an image importer, a link preview — and does not constrain where it may go, you can point it at internal services the network trusts and reach things the internet cannot.
This lab: An image importer aimed inward. Make the server fetch a URL of your choosing, from inside its network.
Work it against your own copy of the target. When you have the flag, submit it below.
Objective
Find a feature that fetches a URL you control, and turn it toward something it was never meant to reach. Capture the flag the internal endpoint returns.
Sign in and join the Academy to submit a flag, take hints and track your progress.
Sign inWalkthrough
Locked until you solve it — or reveal it above, which forfeits the points. 3 hints available before then.