Server-side Attacks/Exploiting SSRF Gopherus

Hello everyone, stuck on the Exploiting SSRF section, found open port 3306 and tried to exploit it through gopherus, received a 500 response from the server, tried to make a gopherus request myself, but that didn’t work either

Then I got to Skills Assessment and came across the exact same vulnerability that requires gopher for mysql. and it didn’t work either

Can anyone tell me if I missed something or if I’m doing something wrong?

Hello. Do you still need help?

Gopherus isn’t needed for the module’s exercise nor the Skill Assessment, btw.

You just need to fuzz for available endpoints and then access it using ssrf.

1 Like