webPromedium

Lab 236 — PulseAlert — Blind SSTI via Notification Template Engine

hackadvisor

Task: Flask/Jinja2 notification platform with template test-send feature that renders user input server-side but doesn't return output (blind SSTI). Solution: Error-based exfiltration using exec('raise Exception(data)') via lipsum.__globals__ to leak flag from environment variable.

$ ls tags/ techniques/
ssti_jinja2decoy_flag_recognitionrce_via_lipsum_globalsblind_ssti_error_exfiltrationrce_via_builtins_exec

🔒

Permission denied (requires tier.pro)

Sign in to access full writeups

Sign in with GitHub to continue. No email required.

$sign in

$ grep --similar

Similar writeups