Advanced server-side template exploitation with RCE everywhere -Alex Brumen - Ekoparty 2024

Описание к видео Advanced server-side template exploitation with RCE everywhere -Alex Brumen - Ekoparty 2024

This talk will explains some novel techniques for exploiting server-side template injections (SSTIs) with complex, unique payloads that leverage default methods and syntax from various template engines. Even better, we will show how to do so without needing any quotation marks or extra plugins within the templates. We will go into details on how the payloads were discovered and how each payload was able to archive Remote Code Execution (RCE) despite all the limitations.

Ekoparty 2024 - Bug Bounty Argentina
--

Seguinos en la redes:

X:   / ekoparty  
LinkedIn:   / 1053378  
Instagram:   / ekoparty  
Facebook: https://www.facebook/ekopartyconference
Twitch:   / ekoparty  

Visitá nuestra web: https://www.ekoparty.org/

Комментарии

Информация по комментариям в разработке