
Episode 13: How to Find a Good BBP + Acropalypse + ZDI
Critical Thinking - Bug Bounty Podcast
00:00
SSRF Filter Bypass in Node Requests Library
The SRS that Doyn Suck found was pretty gnarly. If you know your companies have in patch for this this very well may still be out there. This is also probably going to have As a cell verification, so it's not like you can just spin up like a temp as a cell certificate or anything. So definitely something to be keeping in mind and test with get, you know a full HTTPS set up on your on your you know testing callback server and do a redirect from HTTPS to HTTP.
Transcript
Play full episode