Forum Discussion

QuickSloth's avatar
QuickSloth
Icon for Bronze I rankBronze I
4 days ago

Stuck on “Server-Side Template Injection: Ep.2 – Identifying SSTI Vulnerabilities”

None of the three apps are “breaking” for me.  For example the input of {{ dump(_SERVER) }} should return server information in at least one example.  But nope. 

4 Replies

  • > I think there's only one app using twig
    I know.  And I know which one is running twig.  But I try all three for completeness. 
    I tried this on three different days.  And I'm still not able to get anything to return the system information. 
    (Oops, meant this as a reply to netcat​ )

  • I just took the sample payload from the briefing, and it works on the first app, causing an error.
    I think there's only one app using twig, where the above string would trigger.
    SSTI...not my favorite.

    • QuickSloth's avatar
      QuickSloth
      Icon for Bronze I rankBronze I

      > I just took the sample payload from the briefing
      Sorry, which payload is that?