> For the complete documentation index, see [llms.txt](https://0xten.gitbook.io/public/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://0xten.gitbook.io/public/clearsale-ctf/2021/esse-esse-erre-effe.md).

# Esse Esse Erre Effe

## Approaching the app

![](/files/-MfU0bJzfxVW-d0vfneu)

The application allows the user to input a url to a website and returns the response inside a json afterwards.

![](/files/-MfU0vfRAKycOUPgN79s)

If we try to access the api ip directly the app denies to retrieve the data.

![](/files/-MfU2CB5Mm2f1BhJEQKu)

## The exploit

We can try to retrieve data by making the server send us a request and then redirect it to cloud api via an http Location header.

![](/files/-MfU2jvuMOJ1m68A45qX)

One could simply server the following php code:

```php
<?php
header("Location: http://169.254.169.254/metadata/v1.json");
```

And point the ssrf request to the controled server, to retrieve the metadata.

![](/files/-MfU3A-YpvSZWy2cW9TP)

And the flag is retrieved among the metadata :0
