How to solve SSRF capture the flag challenges?

Опубликовано: 11 Июль 2026
на канале: CTF School
7,161
237

In this short video I'm showing how to solve SSRF challenges, explaining how to exploit this vulnerability in SEETF 2022 task named Super Secure Requests Forwarder.

This is not a typical writeup! The priority is to explain in more detail what is this vulnerability and what tools can be used to solve similar tasks.

In this video you can learn how to use Snyk Open Source Advisor to check if libraries used in the challenge are vulnerable, how to write your own exploit with Python and Flask and how to deal with NAT by setting up a local tunnel.

#ssrf #capturetheflak #snyk #python

00:00 Intro
00:32 The Challenge
01:11 Analyzing the Source Code
02:16 SSRF explaination
02:46 First solve attempt
03:33 Advocate
04:03 Snyk Open Source Advisor
04:55 The "Redirect" technique
05:48 Writing exploit with Flask
06:20 Setting up Local Tunnel
07:30 Redirect attack
08:02 Final Fix

Hand Drawn icons created by Freepik - Flaticon

Music:
Goat's Skull - Verified Picasso
El Secreto - Yung Logos