Phying News
Curated security research, vulnerabilities, advisories and tools for practitioners.

Dojo challenge #53 Hacker Club solution

Summary

The official writeup for YesWeHack Dojo challenge #53: the target is vulnerable to SSTI if a hunter can bypass the email regex and mail-parser quirks to smuggle ERB template syntax into the Ruby interpolation path, reaching the full runtime to exfiltrate the flag.

Why it matters

This technical writeup demonstrates practical payload crafting for Ruby ERB template injection vulnerabilities.
Published
Collected

original ↗

Related coverage

back