πŸ“¨
Notes
search
Ctrlk
  • πŸ‘‹About me.
  • 🚩CTF writeups
    • 2022 CTFschevron-right
    • 2023 CTFschevron-right
    • 2024 CTFschevron-right
    • 2025 CTFschevron-right
  • πŸ“¦Rooms
    • HackTheBoxchevron-right
    • Tryhackmechevron-right
  • APK pentesting
    • ADB Cheatsheet
    • Tools & Get Started
    • Pull & Patch
    • Static analysischevron-right
    • Dynamic Analysischevron-right
  • Web Security
    • File Upload Bypass
    • To remember LoG
    • SSTI
    • Eval bypass
    • HTTP Headerschevron-right
  • Active Directory
    • πŸ–₯️what is? General info
    • LLMNR poisoning
    • Attack list for pentest
  • πŸŽ‘Overview (fundamentals/cheatsheet)chevron-right
  • πŸ†Certifications
    • EJPT v2chevron-right
gitbookPowered by GitBook
block-quoteOn this pagechevron-down
  1. Web Security

SSTI

Server Side Template Injection.

Resources, payloads & CTF Writeups

hashtag
Resources

LogoJinja2 SSTI - HackTricksbook.hacktricks.wikichevron-right
LogoServer Side Template Injection with Jinja2 - OnSecurityOnSecuritychevron-right
LogoMethod Confusion In Go SSTIs Lead To File Read And RCE - OnSecurityOnSecuritychevron-right
PreviousTo remember LoGchevron-leftNextEval bypasschevron-right

Last updated 9 months ago