Lab: SSRF with filter bypass via open redirection vulnerability
This lab has a stock check feature which fetches data from an internal system.
To solve the lab, change the stock check URL to access the admin interface at
http://192.168.0.12:8080/admin and delete the user
The stock checker has been restricted to only access the local application, so you will need to find an open redirect affecting the application first.
- Visit a product, click "Check stock", intercept the request in Burp Suite, and send it to Burp Repeater.
Try tampering with the
stockApiparameter and observe that it isn't possible to make the server issue the request directly to a different host.
Click "next product" and observe that the
pathparameter is placed into the Location header of a redirection response, resulting in an open redirection.
Create a URL that exploits the open redirection vulnerability, and redirects to the admin interface, and feed this into the
stockApiparameter on the stock checker:
The stock checker should follow the redirection and show you the admin page. You can then amend the path to delete the target user: