Forum Discussion
QuickSloth
Bronze III
3 months agoStuck on “Server-Side Template Injection: Ep.2 – Identifying SSTI Vulnerabilities”
None of the three apps are “breaking” for me. For example the input of {{ dump(_SERVER) }} should return server information in at least one example. But nope.
QuickSloth
Bronze III
3 months ago> I just took the sample payload from the briefing
Sorry, which payload is that?
netcat
Silver III
3 months agoThis one: {{$<%=(*`|.'#-%>;}}
- QuickSloth3 months ago
Bronze III
All three apps just echo back that same input.
- netcat3 months ago
Silver III
Just one more click.
- QuickSloth3 months ago
Bronze III
Sorry, but what do you mean by "one more click"?