Pentesting General | SSTI Exploitation | MeteSploit | Vulnhub Tempus Fugit 3

Опубликовано: 12 Октябрь 2024
на канале: Junhua Wong
70
4

Uses Tempus Fugit 3 on Vulnhub as TARGET.

The two techniques are being demonstrated in the video:

1. Detect SSTI (Server Side Template Engine) and Exploit SSTI.
Use BurpSuite to find right payload to get reverse shell.
https://exploit-notes.hdks.org/exploi...

2. When no wget or curl on the target machine, how to upgrade the normal shell to Metepreter.