All challenges
CH-03 Medium

Server-Side Request Forgery

The fetch service retrieves any URL you hand it — from the server's own network position. Loop it back on itself and read the endpoints that were never meant to leave localhost.

Objective

Turn the server's own HTTP client against it.

Fetch tester

Live client for the vulnerable fetcher. Responses are the raw server-side result.

GET /api/fetch?url=… GET
Starting points
Response

Hints

Hint 1 — Think about where the request originates
Your browser can't reach 127.0.0.1:3000 on the target — but the target can. Any URL you pass is fetched by the server, from the server.
Hint 2 — Enumerate like an attacker
You know the port. Now think like a directory bruteforcer: what would an internal-only endpoint be called? Config files, internal tools, status pages — try the obvious names in the obvious places.
Hint 3 — Configs love JSON
Developers stash runtime config in predictable spots. If there were an /internal/ prefix, what filename would hold configuration? Whatever it returns needs no decoding — if you're staring at a private key, you're done.

Claim the bounty

No submission form. No judging. The chain is the referee.

STEP 1

Pivot internally

Reach the internal config endpoint through the fetcher and read the plaintext key.

STEP 2

Import it

Load the base58 secret into any Solana wallet — Phantom, Solflare, or CLI.

STEP 3

Sweep the balance

Move the full 1 SOL to your own address. The scoreboard confirms on-chain.