What we did
Built a multi-stage web chain: a server-side request forgery primitive was used to read internal resources and leak a credential, then a Host-header-driven virtual-host route reached an internal package registry that was not meant to be exposed. Publishing a malicious package to that registry led to code execution on a back-end host — a realistic modern chain, not a single reflected bug.
- SSRF file-read used to leak an internal service token
- Host-header manipulation to reach an internal-only virtual host
- Malicious package publish to an internal registry → server-side execution
- Privilege step to reach the protected objective via a SUID helper pattern
Why it matters to a client
Single findings are cheap; chains are what actually breach a system. This is the exact reasoning applied to client web apps and APIs — assume the first bug is only a foothold and ask what it unlocks. It maps directly to the OWASP Top 10 (SSRF, access control, misconfiguration) and to how real breaches unfold.
← Back to case studies