Це відео не доступне.
Перепрошуємо.

SSTI POC || ycode.com Bug Bounty scam

Поділитися
Вставка
  • Опубліковано 27 чер 2024
  • #hacker #bug #bugbounty

КОМЕНТАРІ • 11

  • @akroidofficial
    @akroidofficial Місяць тому +1

    why you gave title bug bounty scam?

  • @user-mo8uj9vq5u
    @user-mo8uj9vq5u Місяць тому

    yes indeed that math is being evaluated and I can tell this is a legit ssti how that turn out for you and are you open to collab?

    • @A9x-AkhilReddy
      @A9x-AkhilReddy  Місяць тому +1

      @@user-mo8uj9vq5u thanks for the Collab request. I escalate into RCE for jinja2 instances I cut the part and just uploaded. If I got anything I will Collab . Try to drop the social media link to contact you . Any way they scammed me for not getting any response from their side.

    • @user-mo8uj9vq5u
      @user-mo8uj9vq5u Місяць тому

      @@A9x-AkhilReddy u have twitter ill add u

  • @gk_eth
    @gk_eth Місяць тому +1

    did you submitted the impact?

    • @A9x-AkhilReddy
      @A9x-AkhilReddy  Місяць тому

      @@gk_eth I show a simple payload in this poc . I cut the interesting part I escalate into RCE

    • @sukremez1870
      @sukremez1870 Місяць тому

      @@A9x-AkhilReddy if rce, got bounty then? if yes, does this website have bounty program in hackerone/bugcrowd? or no?

  • @sukremez1870
    @sukremez1870 Місяць тому

    how did you find it that the url can do &service?

    • @A9x-AkhilReddy
      @A9x-AkhilReddy  Місяць тому +1

      @@sukremez1870 I got you back . If you test any application you just gather info about the technology they used . Then you are testing like hit and trail . Everything about the website you have to test for different aspects in a different manner .if you don't know where you want to test.you just read the documentation of the website you are testing . It would help you what endpoint and what was the details fetch from backend to front end simple how it is working . And that was the phase where I discovered the first name and second name is vulnerable to SSTI.then I check what was they used template to process the data .then I got to know it was Jinja2 instances template is used . Then I tried a simple payload. And it worked . Then I dig deep to escalate into RCE. I hope I just clear your question

    • @sukremez1870
      @sukremez1870 Місяць тому

      @@A9x-AkhilReddy aight got it