webProeasy
Конвертер (Converter)
hackerlab
Task: ASCII encoder/decoder web app with Flask/Jinja2 backend. Solution: SSTI via ASCII-encoded payload - decoded text is rendered through Jinja2 template engine, allowing RCE via request.application.__globals__.
$ ls tags/ techniques/
Server-Side Template Injection via ASCII decodePayload encoding to bypass input restrictionsRCE via request.application.__globals__
🔒
Permission denied (requires tier.pro)
Sign in to access full writeups
Sign in with GitHub to continue. No email required.
$sign in$ grep --similar
Similar writeups
- [web][Pro]Состояние 0x7F— hackerlab
- [web][Pro]Lucky Ticket (Счастливый билет)— hackerlab
- [web][Pro]Джарвис (Jarvis)— hackerlab
- [web][Pro]Minefield— hackerlab
- [web][Pro]Поздравительное приложение (Greeting App)— hackerlab