xsspresso
xsspresso
Tags/ SSRF

SSRF

9 writeups tagged with SSRF

WebMedium

Wiz Bug Bounty

Bug bounty masterclass covering exposed databases, SSRF, subdomain takeover, blind XSS, GitHub secret leaks, Spring Boot heapdump, and session confusion ATO.

#Bug Bounty#SSRF#Subdomain Takeover
Jan 24, 2026Wiz Bug Bounty
WebMediumLinux

HTB — Imagery

ImageMagick policy bypass enables SSRF and local file read to steal credentials. Sudo misconfiguration grants root access.

#ImageMagick#SSRF#File Read
Oct 4, 2025HackTheBox
WebEasyLinux

HTB — Planning

Grafana SSRF pivots to an internal Grafana instance. Credential reuse for SSH, then environment variable injection via root cron.

#Grafana#SSRF#Cron
May 31, 2025HackTheBox
WebHardLinux

HTB — Checker

TeamCity authentication bypass combined with Bookstack SSRF to read internal files and chain into remote code execution.

#TeamCity#SSRF#Bookstack
Feb 22, 2025HackTheBox
WebMediumLinux

HTB — BigBang

WordPress BuddyForms plugin SSRF for local file read. Grafana SQLite injection for credentials. Telescope log viewer arbitrary file read for root key.

#WordPress#SSRF#Grafana
Jan 26, 2025HackTheBox
WebEasyLinux

HTB — Analytics

Metabase pre-auth RCE CVE-2023-38646 via setup token SSRF for shell. Ubuntu OverlayFS CVE-2023-2640 local privilege escalation for root.

#Metabase#CVE-2023-38646#OverlayFS
Jan 18, 2025HackTheBox
WebEasyWindows

HTB — Love

SSRF on a voting system bypasses firewall to reach internal file analysis service. PHP file upload for RCE, AlwaysInstallElevated for SYSTEM.

#SSRF#File Upload#AlwaysInstallElevated
Jan 16, 2025HackTheBox
WebEasyLinux

HTB — Alert

Markdown XSS for stored cross-site scripting. SSRF via file:// to leak local web app source code, exposed internal site with writable path for root.

#XSS#SSRF#Markdown
Jan 10, 2025HackTheBox
WebEasyLinux

HTB — Sau

Maltrail 0.53 SSRF on a request-basket service. CVE-2023-27163 chained to unauthenticated OS command injection for initial access, sudo privesc.

#SSRF#Command Injection#CVE-2023-27163
Nov 19, 2024HackTheBox