Stop Ignoring SSTI and SSRF: Exploiting 'Templated' and 'HauntMart' on HTB #HTB #CTF #CyberSecurity
00xCanelo
0:00 / 0:00
Stop Ignoring SSTI and SSRF: Exploiting 'Templated' and 'HauntMart' on HTB #HTB #CTF #CyberSecurity
95 просмотров · 3 месяца назад
00xCanelo
143 подписчика
95 просмотров · 3 месяца назад
Join us for a complete walkthrough of the Hack The Box 'Templated' challenge! In this video, we'll demonstrate how to identify and exploit Server-Side Template Injection (SSTI) vulnerabilities, specifically focusing on applications built with Flask and Jinja2.
Key Learnings:
Understanding SSTI in Flask/Jinja2 applications
Identifying Jinja2 template engine errors
Using `PayloadsAllTheThings` for SSTI payloads
Extracting configuration details and achieving remote code execution
Timestamps:
00:00 Introduction
00:25 Challenge 1 - Templated Overview
01:30 Identifying the SSTI Vulnerability
02:00 Crafting the SSTI Payload
03:00 Achieving RCE & Capturing the Flag
04:01 Challenge 2 - HauntMart Overview
04:46 Source Code Analysis
06:57 Exploring the Application
08:12 Exploiting the SSRF Vulnerability
10:41 Investigating the make_admin API
12:47 Privilege Escalation to Admin
14:55 Challenge Complete & Outro
Don't forget to like, comment, and subscribe for more cybersecurity walkthroughs and tutorials!
#HackTheBox #SSTI #Jinja2 #Flask #Cybersecurity #WebHacking #Pentesting #TemplateInjection #ExploitDevelopment #CTF #HackingTutorial #00xcanelo #Mont5ab_El2hwa