Find and Exploit Server-Side Template Injection (SSTI)

แชร์
ฝัง
  • เผยแพร่เมื่อ 9 ก.พ. 2025

ความคิดเห็น • 12

  • @fm0x1
    @fm0x1 ปีที่แล้ว +3

    Great video !!

  • @demotedc0der
    @demotedc0der ปีที่แล้ว +2

    We're looking forward to more streams with tib3rius :)

  • @ksboi29
    @ksboi29 ปีที่แล้ว +1

    First time hearing about SSTI

  • @naimurrahmanjoy4059
    @naimurrahmanjoy4059 ปีที่แล้ว +5

    We want live bug Hunting video . Like choosing program, perform recon and automation then manaual hunting.

    • @TCMSecurityAcademy
      @TCMSecurityAcademy  ปีที่แล้ว +4

      We'll keep this in mind for future live sessions. Have you looked at Alex's Bug Bounty playlist here for additional content on methodologies, reporting writing, and tips?: th-cam.com/play/PLLKT__MCUeixlBvUYIH1yQaxShVB2F03N.html&si=Oo8O5OPbC_ZC7pY-

  • @thepentesterguyofficial
    @thepentesterguyofficial 10 หลายเดือนก่อน

    Feedback: You have added a lot of base with the mic setting please change to make the vocal a little bit clear like Eth Adams, I saw in most the videos the same issue, it sounds better with earphones/headphones but most of the time people listen on speakers internal/external

  • @dieselryder78
    @dieselryder78 ปีที่แล้ว

    When are you guys putting out a web app cert?

  • @Boolap1337
    @Boolap1337 ปีที่แล้ว +1

    I know how SSTI works but how do we know when we should the effort testing it? How can we tell that a webapp is using a template like Mustache etc?

    • @Suto_Ko
      @Suto_Ko ปีที่แล้ว +2

      It's a good practice to test for Server-Side Template Injection (SSTI) vulnerabilities in web applications that use templating engines like Mustache. Look for signs like dynamic rendering of user input or the presence of template tags/expressions. Conducting security testing, including input fuzzing and boundary testing, can help identify potential SSTI vulnerabilities. Remember, it's always better to be proactive and ensure the security of your web applications.

  • @taijulofficial7320
    @taijulofficial7320 ปีที่แล้ว

    Ivan se we have

  • @taijulofficial7320
    @taijulofficial7320 ปีที่แล้ว +1

    I am not understand your language 😔😔😔

    • @fm0x1
      @fm0x1 ปีที่แล้ว

      Turn on subtitles, on the right bottom of the video, check settings button and enable it in your language