Node.js

Dojo #9

drag_indicator
info
drag_indicator
inputs
drag_indicator
inspect

YOU CSHALL NOT PASS (THE COMEBACK) - DOJO #9

Chall

EvilCorp2.0 has received your security reports and has therefore decided to revise its script by adding new SSRF protections. Would you be able to recover the secret?

If you find a way to get (again) the secret using this script, let us know!

Goal

Find a way to bypass all security mechanisms to retrieve the /secret.

BRUTEFORCE IS NOT ALLOWED

drag_indicator
waf
INPUT
OUTPUT
drag_indicator
code
drag_indicator
result