▹ Watch me Live on Twitch every Monday and Thursday! - / garr_7
Portswigger Web Security Academy Server-Side Template Injection (SSTI) Lab: Basic server-side template injection (code context) - https://portswigger.net/web-security/...
Additional References for Further Exploration:
My SSTI Explanation Vid - • SSTI Complete Lab Breakdown: Basic server-...
HackTricks SSTI Cheat Sheet - https://book.hacktricks.xyz/pentestin...
Awesome In-Depth SSTI Breakdown by PwnFunction - • Server-Side Template Injections Explained
------------------------------------------------------------------------------
In this series, we take a look at Web Security Academy's Server-Side Template Injection (SSTI) labs and break them down. The goal is to break down the concepts to not only get to the solution, but talk about methodology and the mental steps we take in order to discover these vulnerabilities in the wild.
Timestamps:
0:00 Intro
0:12 Lab Start: Mapping the Application
0:58 Using Hacktricks to Fuzz Comments (Failed)
1:48 Two Ways to Enumerate Templating Engine
2:32 Searching Hacktricks for Tornado Payloads
3:44 Fixing the Error In Our Payload
4:34 Final Payload
4:48 Recap & Takeaway
5:11 Outro
------------------------------------------------------------------------------
Music:
“Lovely City”
Produced by Calum Bowen
• Lovely City
“Snickers”
Produced by Epidemic Sound / Damma Beatz
• Damma Beatz - Snickers (Royalty Free Music)
“Ikebaby”
Produced by Robotprins
• Ikebaby (feat. @rymdkraft )
On this page of the site you can watch the video online SSTI Complete Lab Breakdown: Basic server-side template injection (code context) with a duration of hours minute second in good quality, which was uploaded by the user Seven Seas Security 18 April 2022, share the link with friends and acquaintances, this video has already been watched 15,391 times on youtube and it was liked by 183 viewers. Enjoy your viewing!