SSTI Complete Lab Breakdown: Server-side template injection with a custom exploit

แชร์
ฝัง
  • เผยแพร่เมื่อ 31 ธ.ค. 2024

ความคิดเห็น • 20

  • @aaryan1143
    @aaryan1143 ปีที่แล้ว +4

    The explanation was so precise, I never even thought about generating an error at the File Upload section, thank you soo much!

    • @nishantdalvi9470
      @nishantdalvi9470 10 หลายเดือนก่อน

      Hey brother i just have a little doubt over here, Why didn't we simply tried copy pasting RCE payloads in the context to Twig from HackTricks in this lab as we did in all the previous labs ?

  • @ishajoshi4599
    @ishajoshi4599 2 ปีที่แล้ว +6

    Amazing series!!! You must make more walkthroughs like this, you were concise and clear and it made all the difference!

    • @7SeasSecurity
      @7SeasSecurity  ปีที่แล้ว +1

      Really appreciate that Isha! We really do plan to make more videos for more of the Web Security Academy labs. We felt it was important to break these concepts down in a digestible format, but also practical enough to take away a working methodology on discovering cool vulnerabilities. Appreciate your time and glad to hear you’re enjoying the content!

  • @TheWorstGamerToLive
    @TheWorstGamerToLive 2 ปีที่แล้ว +3

    These videos are so helpful, I refer to them very often

    • @7SeasSecurity
      @7SeasSecurity  2 ปีที่แล้ว

      That’s great to hear! I really appreciate you checking out the video!

  • @gopikanna_
    @gopikanna_ ปีที่แล้ว

    Thanks man for the amazing explanations...♥

  • @TShad0w-Sec
    @TShad0w-Sec ปีที่แล้ว

    Brilliant work!

  • @jaywandery9269
    @jaywandery9269 11 หลายเดือนก่อน

    This was a beautiful lab

  • @z1ro_zb
    @z1ro_zb 7 หลายเดือนก่อน

    great explanation!, you should make more portswigger videos🙌

  • @acronproject
    @acronproject ปีที่แล้ว

    Very good. Thank you MR.

  • @cair0_
    @cair0_ 2 ปีที่แล้ว +1

    that was 🔥

    • @7SeasSecurity
      @7SeasSecurity  2 ปีที่แล้ว

      Thanks so much. I hope the video was helpful!

  • @nishantdalvi9470
    @nishantdalvi9470 10 หลายเดือนก่อน

    In the error message (which gets triggered when we try to upload non image file) we can see that "User->setAvatar" the class name 'User' itself is used in order to call the setAvatar method doesn't it makes the setAvatar a static method. If it is a static method how are we able to access it with the help of an object instance user.setAvatar?

  • @mrvDn
    @mrvDn 2 ปีที่แล้ว +1

    amazing video man..

    • @7SeasSecurity
      @7SeasSecurity  2 ปีที่แล้ว

      I really appreciate that! I hope it was helpful. More to come soon. Thanks so much for checking out the video!

  • @Aftab700
    @Aftab700 2 ปีที่แล้ว +1

    great work

    • @7SeasSecurity
      @7SeasSecurity  2 ปีที่แล้ว

      Thank you! Hope it was helpful. Appreciate you checking out the video!

  • @cair0_
    @cair0_ 2 ปีที่แล้ว +1

    I can't see the live 😥

    • @7SeasSecurity
      @7SeasSecurity  2 ปีที่แล้ว +1

      Thanks for the heads up! I have the vod saved so I’ll have to upload that and fix the link. Appreciate you! I’ll let you know when I fix that.