About
In this module of the Web Security Researcher learning path, Advanced WAPT Capstone follows Applied Web Research. That lab stole service tokens through a partner gateway on port 8080. This lab is a different compose stack: a public partner portal at `partner.ciberbots.local:8000` that Kali can reach, plus an internal operations API Kali cannot route to. The portal preview helper fetches HTTP documents for review. That helper runs on the portal, so it can reach the internal API. The internal API trusts a static partner-service header the portal always attaches. Telemetry on that API prints the HMAC signing key. A forged research-admin JWT then unlocks the internal research export. Scope stays on this HTTP trust chain. There is no sandbox escape, reverse shell, or directory service in this lab. Upon completion of the module, students will be able to: - Abuse a partner preview helper as a non-blind SSRF oracle to an internal API. - Recognize implicit trust based on a static proxy header. - Recover JWT signing material from an overshared telemetry endpoint. - Forge an HS256 token with the required issuer and role claims and replay it through the same preview helper. - Map each finding to a concrete OWASP ASVS control and WSTG identifier for enterprise reporting. For inquiries, please write us at https://www.darkrelay.com/cybersecurity-course-inquiry
Overview
Acceptable Usage Policy
.1 step
Lab Access
.1 step
Partner Preview SSRF
.5 steps