Surfer - SSRF (TryHackMe)
Introduction: Web app with hidden internal pages. The challenge mentions an SSRF vulnerability. Goal: Access restricted admin functionality.
What You Did:
Login with default creds (admin/admin)
Found export2pdf.php endpoint that accepts URLs
Explo...
sharonjebitok.com4 min read