SSTI Complete Lab Breakdown: Basic server-side template injection

Опубликовано: 04 Апрель 2022
на канале: Seven Seas Security
27,859
428

▹ Watch me Live on Twitch every Monday and Thursday! -   / garr_7  

Portswigger Web Security Academy Server-Side Template Injection (SSTI) Lab: Basic server-side template injection - https://portswigger.net/web-security/...

Additional References for Further Exploration:

HackTricks SSTI Cheat Sheet - https://book.hacktricks.xyz/pentestin...
Awesome SSTI Vuln Breakdown by PwnFunction -    • Server-Side Template Injections Explained  
Rails Mailer Template Example - https://guides.rubyonrails.org/action...

------------------------------------------------------------------------------
In this series, we take a look at Web Security Academy's Server-Side Template Injection (SSTI) labs and break them down. The goal is to break down the concepts to not only get to the solution, but talk about methodology and the mental steps we take in order to discover these vulnerabilities in the wild.

Timestamps:
0:00​ Intro
0:12​ What are Templates?
1:24 A few examples of template usage
2:03 Simple explanation of SSTI
3:24 SSTI Discovery Steps
4:44 Lab Start: Basic SSTI
7:34 Recap
8:10 Outro

------------------------------------------------------------------------------

Music:

“Lovely City”
Produced by Calum Bowen
   • Lovely City  

“Morning Tea”
Produced by Jeff Kaale
   • Jeff Kaale - Morning Tea  

“Snickers”
Produced by Epidemic Sound / Damma Beatz
   • Damma Beatz - Snickers (Royalty Free Music)  

“Ikebaby”
Produced by Robotprins
   • Ikebaby (feat. @rymdkraft )  


На этой странице сайта вы можете посмотреть видео онлайн SSTI Complete Lab Breakdown: Basic server-side template injection длительностью часов минут секунд в хорошем качестве, которое загрузил пользователь Seven Seas Security 04 Апрель 2022, поделитесь ссылкой с друзьями и знакомыми, на youtube это видео уже посмотрели 27,859 раз и оно понравилось 428 зрителям. Приятного просмотра!