Posts

Showing posts with the label ssti

TryHackMe - SSTI (Server-Side Template Injection) - Walkthrough

Image
Introduction Today we're going to be doing a walkthrough for the SSTI (Server-Side Template Injection) room hosted at https://tryhackme.com/room/ learnssti . For this walkthrough, we'll be using two virtual machines (VMs), a Kali Linux VM as our attacking machine, and the deployed SSTI vulnerable VM as the the victim machine. Task 1 - Introduction Questions: Understand all of the above. No answer needed Task 2 - Detection Questions What sequence of characters causes the application to throw an error? Answer contained within Answer format Task 3 - Identification Questions What template engine is being used in this application? Navigate to the following URL in our web browser: http://10.10.6.245:5000/profile/{{7*'7'}} Compare the results to the contents of the URL below: https://portswigger.net/research/server-side-template-injection#Identify   Task 4 - Syntax Questions How do you start a comment in Jinja2? Search within the following URL (search term: “ comment ”) https:...