Simon McCabe

OSCP · OSWP · PWPP · PWPA · PAPA · EnCE · Linux+ · LPIC-1 · Network+ · Security+ · Pentest+ · eJPT · eWPT · BSc · PGCert

Tanuki (SSRF)


Step 1: Register

Register and you’ll land on the following page. Proxy your traffic and click “View Rankings” to see the leaderboard (shocking, I know).

Step 2: SSRF

The POST /api/fetch will go to a localhost URL. Append /admin and you’ll get the flag:

Thanks for reading!

LinkedIn X YouTube GitHub