In this Stream Recording of Late Hacking Night Day 07 (Sinhala), we explore Server Side Template Injection (SSTI) and Path Traversal Vulnerabilities with practical labs from PortSwigger.
Topics Covered:
What is Server-Side Template Injection (SSTI)?
Identifying a templating engine in a web application
Exploiting SSTI for command execution and local file inclusion
Preventing SSTI vulnerabilities
What is path traversal?
How to identify path traversal parameters
Exploiting path traversal to read internal files
Bypassing SSTI and path traversal defenses
Preventing path traversal
Labs Demonstrated:
Basic server-side template injection
Basic server-side template injection (code context)
Server-side template injection using documentation
Server-side template injection in an unknown language with a documented exploit
Server-side template injection with information disclosure via user-supplied objects
File path traversal, simple case
File path traversal, traversal sequences blocked with absolute path bypass
File path traversal, traversal sequences stripped non-recursively
File path traversal, traversal sequences stripped with superfluous URL-decode
File path traversal, validation of start of path
File path traversal, validation of file extension with null byte bypass
💬 Join Heshan Streams WhatsApp Channel for live notifications and events :
https://bit.ly/heshanpererawhatsapp
🌍 Websites :
Main : https://destinyoo.com
Blog : https://blog.destinyoo.com
Portfolio : https://about.destinyoo.com
🎙️ Daily Streams and Content :
/ @heshankperera
‼️ Disclaimer: This content is for educational purposes only. I do not take responsibility for misuse. All material is freely available for those who love cybersecurity, use responsibly and ethically.
#cybersecurity #webhacking #CTF #portswiggerlabs #sinhala