Dojo challenge #53 Hacker Club solution
yeswehack.com | blog | #bug-bounty | #rce | #pentesting | #appsec | #ruby | #ctf | #poc | #dojo | #template-injection | #yeswehack | #ssti
Summary
The official writeup for YesWeHack Dojo challenge #53: the target is vulnerable to SSTI if a hunter can bypass the email regex and mail-parser quirks to smuggle ERB template syntax into the Ruby interpolation path, reaching the full runtime to exfiltrate the flag.
Why it matters
This technical writeup demonstrates practical payload crafting for Ruby ERB template injection vulnerabilities.
- Published
- Collected
Skip to content