Server-Side Request Forgery
The fetch service retrieves any URL you hand it — from the server's own network position. Loop it back on itself and read the endpoints that were never meant to leave localhost.
Objective
Turn the server's own HTTP client against it.
GET /api/fetch?url=<url>fetches whatever you supply — no allowlist, no scheme restrictions.- The application listens on
127.0.0.1:3000internally. Public routes are only half the story. - Something on the internal network holds this stage's key. Map the surface and find it.
Fetch tester
Live client for the vulnerable fetcher. Responses are the raw server-side result.
GET /api/fetch?url=…
GET
Starting points
Response
Hints
Hint 1 — Think about where the request originates
Your browser can't reach
127.0.0.1:3000 on the target — but the target can. Any URL you pass is fetched by the server, from the server.Hint 2 — Enumerate like an attacker
You know the port. Now think like a directory bruteforcer: what would an internal-only endpoint be called? Config files, internal tools, status pages — try the obvious names in the obvious places.
Hint 3 — Configs love JSON
Developers stash runtime config in predictable spots. If there were an
/internal/ prefix, what filename would hold configuration? Whatever it returns needs no decoding — if you're staring at a private key, you're done.Claim the bounty
No submission form. No judging. The chain is the referee.
STEP 1
Pivot internally
Reach the internal config endpoint through the fetcher and read the plaintext key.
STEP 2
Import it
Load the base58 secret into any Solana wallet — Phantom, Solflare, or CLI.
STEP 3
Sweep the balance
Move the full 1 SOL to your own address. The scoreboard confirms on-chain.