Перейти к содержимому

Stop Ignoring SSTI and SSRF: Exploiting 'Templated' and 'HauntMart' on HTB #HTB #CTF #CyberSecurity

00xCanelo

0:00 / 0:00

Stop Ignoring SSTI and SSRF: Exploiting 'Templated' and 'HauntMart' on HTB #HTB #CTF #CyberSecurity

95 просмотров · 3 месяца назад
00xCanelo
143 подписчика
95 просмотров · 3 месяца назад
Join us for a complete walkthrough of the Hack The Box 'Templated' challenge! In this video, we'll demonstrate how to identify and exploit Server-Side Template Injection (SSTI) vulnerabilities, specifically focusing on applications built with Flask and Jinja2. Key Learnings: Understanding SSTI in Flask/Jinja2 applications Identifying Jinja2 template engine errors Using `PayloadsAllTheThings` for SSTI payloads Extracting configuration details and achieving remote code execution Timestamps: 00:00 Introduction 00:25 Challenge 1 - Templated Overview 01:30 Identifying the SSTI Vulnerability 02:00 Crafting the SSTI Payload 03:00 Achieving RCE & Capturing the Flag 04:01 Challenge 2 - HauntMart Overview 04:46 Source Code Analysis 06:57 Exploring the Application 08:12 Exploiting the SSRF Vulnerability 10:41 Investigating the make_admin API 12:47 Privilege Escalation to Admin 14:55 Challenge Complete & Outro Don't forget to like, comment, and subscribe for more cybersecurity walkthroughs and tutorials! #HackTheBox #SSTI #Jinja2 #Flask #Cybersecurity #WebHacking #Pentesting #TemplateInjection #ExploitDevelopment #CTF #HackingTutorial #00xcanelo #Mont5ab_El2hwa