In this video i have explained what is server side template injection, how to detect SSTI, what can be achieved by SSTI, XSS & HTML injection By SSTI, How to automate Exploitation using bash, How can an attacker achieve remote code execution by SSTI & SSTI prevention & mitigation.
TimeStamps of the topics covered in this video are below:
[00:00] - Intro
[00:06] - Contents
[01:04] - Server Side Template Injection
[01:35] - Why SSTI arises in web applications
[02:48] - How SSTI is different from XSS
[03:31] - Demonstration of the Attack (SSTI)
[05:20] - Detection of SSTI
[06:24] - Detection of SSTI by automation in Bash Scripting
[09:40] - Exploitation of SSTI by automation in Bash Scripting
[10:13] - Cross-Site Scripting & HTML Injection By SSTI
[11:33] - Remote Code Execution By SSTI
[11:55] - Reverse Shell by exploiting SSTI
Resources Link:
Blizzardwrap Tool: https://github.com/prodigiousMind/bli...
XVWA Web Application: https://github.com/s4n7h0/xvwa
PayloadsAllTheThings: https://github.com/swisskyrepo/Payloa...
Thanks For Watching This Video.
Like & Subscribe