Server-Side Template Injection: RCE For The Modern Web App

แชร์
ฝัง
  • เผยแพร่เมื่อ 2 ก.พ. 2025

ความคิดเห็น • 14

  • @chasejensen88
    @chasejensen88 3 ปีที่แล้ว +3

    Listening to him present his research keeps me on the edge of my seat every time. Thanks for all your hard work man

    • @malcolmwinston3097
      @malcolmwinston3097 3 ปีที่แล้ว

      i know im asking randomly but does someone know a way to log back into an instagram account..?
      I stupidly forgot the password. I appreciate any help you can offer me!

  • @siddharthchhetry4218
    @siddharthchhetry4218 3 ปีที่แล้ว +6

    This guy is genius . Huge respect to him :)

  • @abutalibhussain8142
    @abutalibhussain8142 ปีที่แล้ว

    Another level

  • @ЮрийШпорхун
    @ЮрийШпорхун 3 ปีที่แล้ว

    He's brilliant.

  • @tcmatg
    @tcmatg ปีที่แล้ว

    legend

  • @cair0_
    @cair0_ 3 ปีที่แล้ว

    that's how MAFIA works

  • @the_gacker_hub
    @the_gacker_hub 7 ปีที่แล้ว

    But Why the Developers use templates? What benefits can templates gave us? Anyone, thats my only doubt related to SSTI

    • @DelowarHossain
      @DelowarHossain 5 ปีที่แล้ว +4

      It saves time. So, they can concentrate on other things.

    • @bencesarosi7718
      @bencesarosi7718 4 ปีที่แล้ว +3

      - Professional
      - Partially or fully reusable
      - Quicker to edit and read
      - Purpose oriented, concise with minimal footprint
      - Efficient at decoupling the content from the rendering logic (Also, higher level of abstraction, thus usually cleaner, than writing output data directly to the output medium)
      - Implemented and used correctly, they can handle arbitrary output media (e.g. HTTP, E-mail, Documents)
      - etc.
      When an application (especially web) is complex enough, there's just no reason not to use a template engine, really.

    • @theteenengineer7589
      @theteenengineer7589 4 ปีที่แล้ว

      I already encountered using templates, it is to not waste time on repeating the same code over and over again.

    • @ko-Daegu
      @ko-Daegu 4 ปีที่แล้ว

      @@theteenengineer7589
      Then you didn’t build a real web big web app
      They all use it
      Also you need to automate stuff for example building something like a social media app how would you do it without a template ???

  • @tekken-pakistan2718
    @tekken-pakistan2718 4 ปีที่แล้ว

    Thank you very much, the most detailed introduction and exploitation!