About
In this module of the Web Security Researcher learning path, Researchers Sandbox follows Enterprise Web Hacking. You already polluted query parameters and abused GraphQL object-level authorization on a single enterprise API. This lab keeps that research method and moves it onto a Ciberbots document conversion microservice: exact-path reverse-proxy auth, a legacy PhantomJS HTML-to-PDF renderer, then SSRF and local file disclosure into a Redis-backed Celery worker that still accepts pickle. You will bypass a reverse-proxy path guard, upload crafted HTML that forces the renderer to fetch internal HTTP services and local files, recover broker credentials from an application config, authenticate to Redis, and enqueue a malicious Celery message that deserializes into a reverse shell on the worker. Upon completion of the module, students will be able to: - Explain how exact-path reverse-proxy rules diverge from application route matching and turn that mismatch into privileged access. - Abuse a headless HTML-to-PDF engine as an SSRF and file-read primitive, using render diagnostics as an oracle. - Separate service discovery (SSRF) from secret recovery (local file read) when researching multi-tier web apps. - Authenticate to a Redis broker and reason about Celery queue message shape. - Exploit unsafe pickle acceptance in a task worker and document the remediation path for serializers, network ACLs, and least privilege. For inquiries, please write us at https://www.darkrelay.com/cybersecurity-course-inquiry
Overview
Acceptable Usage Policy
.1 step
Lab Access
.1 step
Broken Access Control and URL Canonicalization
.6 steps