Class Central is learner-supported. When you buy through links on our site, we may earn an affiliate commission.

YouTube

Advanced Server-Side Template Exploitation with RCE Everywhere - 2024

Ekoparty Security Conference via YouTube

Overview

Explore novel techniques for exploiting server-side template injections (SSTIs) in this 32-minute conference talk from Ekoparty Security Conference 2024. Discover complex and unique payload development methods that leverage default template engine functionality without requiring quotation marks or additional plugins. Learn the detailed process behind payload discovery and understand how to achieve Remote Code Execution (RCE) while working within strict template limitations. Gain insights into advanced exploitation techniques as demonstrated by security researcher Alex Brumen, who breaks down the methodology for identifying and executing these sophisticated template injection attacks.

Syllabus

Advanced server-side template exploitation with RCE everywhere -Alex Brumen - Ekoparty 2024

Taught by

Ekoparty Security Conference

Reviews

Start your review of Advanced Server-Side Template Exploitation with RCE Everywhere - 2024

Never Stop Learning.

Get personalized course recommendations, track subjects and courses with reminders, and more.

Someone learning on their laptop while sitting on the floor.