Forum Discussion
QuickSloth Bronze III
Bronze III
6 months agoStuck on “Server-Side Template Injection: Ep.2 – Identifying SSTI Vulnerabilities”
 None of the three apps are “breaking” for me.  For example the input of {{ dump(_SERVER) }} should return server information in at least one example.  But nope.  
- 6 months agoI just took the sample payload from the briefing, and it works on the first app, causing an error. 
 I think there's only one app using twig, where the above string would trigger.
 SSTI...not my favorite.
netcat Silver III
Silver III
6 months agoI just took the sample payload from the briefing, and it works on the first app, causing an error.
I think there's only one app using twig, where the above string would trigger.
SSTI...not my favorite.
QuickSloth Bronze III
Bronze III
6 months ago> I just took the sample payload from the briefing
Sorry, which payload is that?
- netcat6 months agoSilver III This one: {{$<%=(*`|.'#-%>;}} - QuickSloth6 months agoBronze III All three apps just echo back that same input. - netcat6 months agoSilver III Just one more click.