top of page
applied web research

Applied Web Research

  • 16 Steps
  • 5 Participants

About

In this module of the Web Security Researcher learning path, Applied Web Research follows Infrastructure & Pipeline Hacking. That lab stayed on one portal and an allowlisted diagnostic. This lab is a multi-tier microservice capstone on the Ciberbots partner platform. You begin on a public partner gateway (`gateway.ciberbots.local:8080`) that fetches remote documents on behalf of integration partners. The gateway is a request-forgery oracle: an attacker-controlled fetch reaches services and diagnostics that should never be exposed, and the gateway attaches its own service credentials to whichever destination you name. You will prove a loopback-only diagnostics endpoint by bypassing the gateway naive host blacklist, capture the bearer token the gateway forwards to attacker-controlled destinations, and replay stolen service tokens against internal APIs to escalate from a partner integration role to full platform administration. This is credential-forwarding SSRF, where the vulnerability is not just reaching internal hosts but making a trusted service hand you its own authentication. Upon completion of the module, students will be able to: - Abuse a partner URL-fetch gateway as an SSRF oracle to reach loopback-only internal diagnostics. - Bypass a string-based loopback blacklist using alternate IP encodings. - Recognize credential-forwarding behavior where a gateway attaches service tokens to outbound requests. - Capture forwarded bearer tokens by pointing the fetcher at an attacker-controlled listener. - Replay stolen service tokens to escalate across microservice trust boundaries. - Map each finding to a concrete OWASP ASVS control and WSTG identifier for enterprise reporting. For inquiries, please write us at https://www.darkrelay.com/cybersecurity-course-inquiry

Overview

Price

Premium, ₹3,699.00

Share

bottom of page