Advanced Server-Side Template Exploitation with RCE Everywhere - 2024
Ekoparty Security Conference via YouTube
Learn the Skills Netflix, Meta, and Capital One Actually Hire For
Google Data Analytics, IBM AI & Meta Marketing — All in One Subscription
Overview
Google, IBM & Meta Certificates — All 10,000+ Courses at 40% Off
One annual plan covers every course and certificate on Coursera. 40% off for a limited time.
Get Full Access
Explore novel techniques for exploiting server-side template injections (SSTIs) in this 32-minute conference talk from Ekoparty Security Conference 2024. Discover complex and unique payload development methods that leverage default template engine functionality without requiring quotation marks or additional plugins. Learn the detailed process behind payload discovery and understand how to achieve Remote Code Execution (RCE) while working within strict template limitations. Gain insights into advanced exploitation techniques as demonstrated by security researcher Alex Brumen, who breaks down the methodology for identifying and executing these sophisticated template injection attacks.
Syllabus
Advanced server-side template exploitation with RCE everywhere -Alex Brumen - Ekoparty 2024
Taught by
Ekoparty Security Conference