url-parser

1 article
sort: new top best
clear filter
0 7/10

A detailed writeup of discovering and exploiting an SSRF vulnerability through a proxy endpoint, highlighting the methodical approach to bypassing domain whitelists by discovering that the filter was *company.com instead of *.company.com, enabling exploitation via attacker-controlled AWS infrastructure.

Burp Collaborator Findomain httprobe Waybackurls AWS S3 EC2 Flask neemacompany.com
medium.com · devanshbatham/Awesome-Bugbounty-Writeups · 17 hours ago · details