1. Web Security Academy
  2. SSRF
  3. Lab

Lab: Basic SSRF against another back-end system

This lab has a stock check feature which fetches data from an internal system.

To solve the lab, use the stock check functionality to scan the internal 192.168.0.X range for an admin interface on port 8080, then use it to delete the user carlos.

Want to track your progress and have a more personalized learning experience? (It's free!)

Sign up Login