ssrf
The Great Escape
· ☕ 14 min read · ✍️ M4t35Z
robots --> backup --> dev api --> command injection --> injection --> git log --> port knocking --> docker -H

Oouch
· ☕ 13 min read · ✍️ M4t35Z
Oouch writeup. A hard(I think it was insane) box. OAuth -> SSRF -> user -> docker -> uwsgi -> dbus -> root