Lab 02: Server-Side Template Injection (SSTI)
Objective
Background
Architecture
Time
Lab Instructions
Step 1: Setup
Step 2: Launch Kali and Detect SSTI
Step 3: Read Server Config and Globals
Step 4: SSTI → RCE via cycler
Step 5: SSTI via Email Preview (POST endpoint)
Step 6: Alternative RCE Payloads
Step 7: Write a Reverse Shell Payload
Step 8: Cleanup
Remediation
Further Reading
Last updated
