- Published on
This challenge has an application that restricts literal IPv4 and local addresses but has a flaw in validating the resolved address was a loopback. Thus, resulting in SSRF talking to the Redis backend using the Gopher protocol. The next step was to leverage Laravel Queues to exploit a command injection vulnerability leading to insecure deserialization




