Forum Discussion
4 Replies
Sort By
- QuickSloth
Bronze I
> I think there's only one app using twig
I know. And I know which one is running twig. But I try all three for completeness.
I tried this on three different days. And I'm still not able to get anything to return the system information.
(Oops, meant this as a reply to netcat ) - netcat
Silver II
I just took the sample payload from the briefing, and it works on the first app, causing an error.
I think there's only one app using twig, where the above string would trigger.
SSTI...not my favorite.- QuickSloth
Bronze I
> I just took the sample payload from the briefing
Sorry, which payload is that?- netcat
Silver II
This one: {{$<%=(*`|.'#-%>;}}