
  <rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
    <channel>
      <title>mfkrypt&#39;s blog</title>
      <link>https://mfkrypt.github.io/blog</link>
      <description>Recent Posts</description>
      <language>en-us</language>
      <managingEditor>ammarsuper21@gmail.com (mfkrypt)</managingEditor>
      <webMaster>ammarsuper21@gmail.com (mfkrypt)</webMaster>
      <lastBuildDate>Thu, 10 Sep 2026 00:00:00 GMT</lastBuildDate>
      <atom:link href="https://mfkrypt.github.io/tags/laravel/feed.xml" rel="self" type="application/rss+xml"/>
      
  <item>
    <guid>https://mfkrypt.github.io/blog/htb/challenges/web/screencrack</guid>
    <title>The syntax was destroying my sanity, so I made a tool</title>
    <link>https://mfkrypt.github.io/blog/htb/challenges/web/screencrack</link>
    <description>This challenge has an application that restricts literal IPv4 and local addresses but has a flaw in validating the resolved address was a loopback. Thus, resulting in SSRF talking to the Redis backend using the Gopher protocol. The next step was to leverage Laravel Queues to exploit a command injection vulnerability leading to insecure deserialization</description>
    <pubDate>Thu, 10 Sep 2026 00:00:00 GMT</pubDate>
    <author>ammarsuper21@gmail.com (mfkrypt)</author>
    <category>challenges</category><category>SSRF</category><category>laravel</category><category>laravel-queues</category><category>redis</category><category>command-injection</category><category>Insecure-deserialization</category>
  </item>

    </channel>
  </rss>
