Perfection HTB

preview_player
Показать описание
Exploiting Sever-Side-Template Injection

Big thanks for watching! If you loved it, don't forget to subscribe, like, and share. Your support keeps the content coming! 🙌🎥
Рекомендации по теме
Комментарии
Автор

This was amazing. I enjoyed every step and got both flags correct.

ayubmetah
Автор

Thanks for the video - how did you know to add the newline character at 13:49?

angelnumber
Автор

This was super informative! Without running linpeas would there be any other clues that would have led to checking the mail directoty?

ap
Автор

I tried my payload here <%= `ls+-lh` %> but it prints the same ls -lh in the response but not the output of that..since 5*5 payload is working and getting 25 in response but this payload <%= `ls+-lh` %> does not work for me..but why?

AkilanK-tx
Автор

19:11 When im typing tcpdump it did not work nothing is showing up only those two lines (i am doing exactly the same thing as it shows on video)

Dandelionq
Автор

yo, i have a question about their TOS. Can i make video of non retired machines without showing flags? Im also thinking about making this kind of videos but in my native language.

casualcaspero
Автор

how did you managed to understand that you should search for ssti payload? what are the hints?

planetfall
Автор

how do you know port number? or random?

swpsns
Автор

<%25%3d+'ls+-lh'+%25> hi im stuck at the place (18.17), my output shows as Your total grade is 27%<p>maths
ls -lh: 25%, pls help

btarasu
Автор

Very good video explanation, I like it. Why is this 9 ?d, I don't understand

kril-bqxr
join shbcf.ru