← All labs
PractitionerServer-side request forgery (SSRF)

An image importer aimed inward

25 points · about 45 minutes · flag format DC{...}
Server-Side RequestsAPI Security

Brief

Server-side request forgery is coercing a server into making a request on your behalf. When a feature fetches a URL you supply — a webhook, an image importer, a link preview — and does not constrain where it may go, you can point it at internal services the network trusts and reach things the internet cannot.

This lab: An image importer aimed inward. Make the server fetch a URL of your choosing, from inside its network.

Work it against your own copy of the target. When you have the flag, submit it below.

Objective

Find a feature that fetches a URL you control, and turn it toward something it was never meant to reach. Capture the flag the internal endpoint returns.

Sign in and join the Academy to submit a flag, take hints and track your progress.

Sign in

Walkthrough

Locked until you solve it — or reveal it above, which forfeits the points. 3 hints available before then.