February 2019
Beginner to intermediate
366 pages
7h 49m
English
SSRF and XSPA vulnerabilities can also be used for other actions, such as extracting information from the servers into the network where the backend is located, or from the server where the application is hosted. Let's analyze the following request:

Here, the filehookURL parameter is vulnerable, so send it to the Repeater tool, using the secondary button of the mouse, and modify the parameter to extract a file, in /etc/passwd, as follows:
action=handleWidgetFiles&type=delete&file=1&filehookURL=file:///etc/passwd
Send it to the application. If it works, the application will show you the ...
Read now
Unlock full access