← All labs
MasterServer-side request forgery (SSRF)

Gopher-smuggling a request to an internal service

100 points · about 180 minutes · flag format DC{...}
Server-Side RequestsAPI Security

Brief

Server-side request forgery is coercing a server into making a request on your behalf. When a feature fetches a URL you supply — a webhook, an image importer, a link preview — and does not constrain where it may go, you can point it at internal services the network trusts and reach things the internet cannot.

This lab: Gopher-smuggling a request to an internal service. Make the server fetch a URL of your choosing, from inside its network.

Work it against your own copy of the target. When you have the flag, submit it below.

Objective

Find a feature that fetches a URL you control, and turn it toward something it was never meant to reach. Capture the flag the internal endpoint returns.

Sign in and join the Academy to submit a flag, take hints and track your progress.

Sign in

Walkthrough

Locked until you solve it — or reveal it above, which forfeits the points. 3 hints available before then.