Chaining SSRF to SSTI for Instant RCE

Опубликовано: 02 Июнь 2026
на канале: MRE Security
744
39

🔔 Stay ahead of cybersecurity insights – Subscribe & turn on notifications!

In this video, we explore the Sunshine Capture The Flag (CTF) 2025, focusing on various web security challenges. We cover techniques for exploiting vulnerabilities, including SQL injection, Server-Side Request Forgery (SSRF), and Server-Side Template Injection (SSTI). The conversation covers practical approaches to solving challenges, including the use of fuzzing tools and understanding client-side authentication issues.

Takeaways:
The Sunshine CTF 2025 focuses on web security challenges.
Client-side authentication can lead to vulnerabilities.
Understanding SSRF is crucial for web security.
SQL injection can be exploited through error messages.
Fuzzing tools like Fuff are essential for testing.
DNS rebinding can bypass certain security measures.
Server-side template injection can lead to remote code execution.
Always check source code for hidden vulnerabilities.
Using the right payloads is key to successful exploitation.
Continuous testing and iteration are necessary for success.

Chapters:
00:00 Lunar Auth (Client-Side Authentication Vulnerability)
02:43 Intergalactic Webhook Service (SSRF DNS Rebinding)
07:36 Lunar Shop (SQL Injection)
10:42 Web Forge (Chaining SSRF to SSTI Leads to RCE)

🎥 What Makes You Different Podcast:    • What Makes You Different Podcast  

Follow us everywhere:
🌐 Website: https://mresecurity.com
🔗 LinkedIn:   / mresecurity  
📘 Facebook:   / mresecure  
📸 Instagram:   / mresecurity  

Republic of Hackers Discord:   / discord  

Disclaimer: This video is for educational purposes only. It demonstrates ethical hacking techniques to improve cybersecurity, and MRE Security is not responsible for how viewers choose to use this information.

#cybersecurity #penetrationtesters #networksecurity #vulnerabilities #certifications #infosec #pentesting #certifications #cyber #security