4 :80 chiv login + SSTI

# got creds chiv:ch1VW4sHERE7331
# can use creds to login to spider.htb/login as chiv
Welcome to the admin panel, chiv.
| can submit new message
| view Messages
| View Support

http://spider.htb/view?check=messages
Staff of ID: '1' posted on: 2020-04-24 15:02:41
Fix the /a1836bb97e5f4ce6b3e8f25693c1a16c.unfinished.supportportal portal!

http://spider.htb/a1836bb97e5f4ce6b3e8f25693c1a16c.unfinished.supportportal
Submit a support ticket!
Welcome to the support portal!
| Contact # or Email:
| Message

SSTI (again)

  • injecting in both fields at http://spider.htb/a1836bb97e5f4ce6b3e8f25693c1a16c.unfinished.supportportal

  • checking reponse at http://spider.htb/view?check=support

Using https://github.com/swisskyrepo/PayloadsAllTheThings/tree/master/Server%20Side%20Template%20Injection#jinja2---filter-bypass

Using https://hackmd.io/@Chivato/HyWsJ31dI

Using https://www.webforefront.com/django/usebuiltinjinjastatements.html

SSH User key

Last updated