Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Could you possibly share writeup? #1

Open
punitdarji opened this issue Jan 5, 2021 · 6 comments
Open

Could you possibly share writeup? #1

punitdarji opened this issue Jan 5, 2021 · 6 comments

Comments

@punitdarji
Copy link

Hi Captain!
I am creating lab for SSRF. COuld you possibly share writeup for your tasks?
Thank you

@Captain-K-101
Copy link
Owner

Captain-K-101 commented Jan 6, 2021 via email

@dycyber
Copy link

dycyber commented Dec 20, 2021

Hi Captain,I think you forgot. I take the liberty to ask you for a writeup.
Thanks!

@sahilabbasi
Copy link

Can we fetch forbidden file using fopen() in php

@Captain-K-101
Copy link
Owner

Hey @dycyber, sorry for the late response, but for writeup, i am currently swarmed with work so might not be able to make a writeup for this in the upcoming future but once free will definitely get on this .
The attacks are pretty simple to exploit basic understanding of SSRF should be enough for exploitation
for any reference materials or stuff u can ping me on twitter @Captainkay11

@Captain-K-101
Copy link
Owner

@sahilabbasi if u do have control over the fopen name parameter being passed it's possible to read files using basic lfi, but again there would be certain criteria too ,ie adequate permissions be there to read etc...

@sahilabbasi
Copy link

Bro i ask it that can we fetch forbidden file (flag.php ) using ssrf Vulernbility because when I try to fetch it it's only give me a forbidden error :(

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

4 participants