|
|
|
|
|
by holyjaw
2842 days ago
|
|
I'm a bit confused by this: > The challenge has kubernetes logo on the bottom of the page like the screenshot below, and the IP is 35.241.245.36. > I immediately realized that is a GCP machine, so I tested the backend server by sending HTTP request to my server to see if it is also on GCP, and it is. What about the IP address or k8s logo made you realize it was a GCP machine? |
|
Comment: * The IP addresses under this Org-ID are in use by Google Cloud customers *
He then uses the SSRF to issue a request to his own server after which he likely realizes that the IP address belonging to the backend service also runs on GCP.