• (๑>؂•̀๑)
  • Home
  • Blog
  • Tags
  • Categories
  • Projects
  • Search ﹒◌﹒✦

Search

SSTI

Found 2 related articles

Back to Tags
  • 2024-11-06

    Whiterose - IDOR, EJS SSTI (CVE-2022-29078), and Sudoedit Bypass (CVE-2023-22809)


    Technical writeup detailing the compromise of the Whiterose machine. Initial access involves subdomain enumeration via wFuzz and exploiting an IDOR vulnerability to retrieve privileged user credentials. This leads to a Server-Side Template Injection (SSTI) RCE via CVE-2022-29078 (EJS Template Engine vulnerability). Privilege escalation is achieved by exploiting the Sudoedit vulnerability CVE-2023-22809 to gain root access via modifying the /etc/sudoers file.

    TryHackMe IDOR wFuzz BurpSuite SSTI CVE-2022-29078 EJS-Template Reverse-Shell Sudoedit-Bypass CVE-2023-22809 Linux-Exploitation
  • 2024-10-25

    Verdejo - SSTI Exploitation and Base64 SUID Privesc Chain


    Technical writeup detailing the compromise of the 'Verdejo' challenge. Initial access is gained by exploiting a Server-Side Template Injection (SSTI) vulnerability via Jinja2 to obtain a reverse shell. Privilege escalation is achieved by exploiting NOPASSWD SUID on '/usr/bin/base64' to read the root SSH private key, which is then cracked using ssh2john and JohnTheRipper for final root access.

    DockerLabs SSTI Server-Side-Template-Injection Jinja2 Reverse-Shell SUID-Privilege-Escalation base64-Exploit SSH2John JohnTheRipper