PortSwigger Web Security Academy: turning XXE into SSRF to reach the cloud metadata endpoint and steal the server’s IAM credentials.
Exploiting XXE to Perform SSRF

ls -la posts/
Writeups, tooling notes, and certification experiences, spanning general techniques and tool guides. Jump to the labs section , or the machines section for box walkthroughs.
ls tags/ # browse by topic

PortSwigger Web Security Academy: turning XXE into SSRF to reach the cloud metadata endpoint and steal the server’s IAM credentials.

PortSwigger Web Security Academy: XXE in a stock-check XML endpoint, defining an external entity to read /etc/passwd off the server.

An OffSec Linux box: an OS command injection in a web-based ping tool lands a reverse shell as www-data, and a SUID vim.basic binary hands over root.

PortSwigger Web Security Academy: escaping a sandboxed FreeMarker engine by walking Java reflection from a user-supplied object all the way to an arbitrary file read.

PortSwigger Web Security Academy: leaking Django’s SECRET_KEY through SSTI by using the {% debug %} tag and a reachable settings object, no code execution required.