@0xlevi_87 Try DNS rebinding or try to find a True/False behavior like you would do with SQL injection. If this isn’t possible, it may be well hardened on server side
@evsc33 I found a crazy escalation from a blind SSRF to full database compromise (CVSS 9.9). Try to understand which services are running on open ports and if you can interact with them, sometimes there are big surprises waiting