Skip to content
  • Home
  • Blog
  • LinkedIn
  • Contact
scomurr.com
  • Home
  • Blog
  • LinkedIn
  • Contact
scomurr logo

ssti lab 5 featured image
  • SSTI, Security, Web Attacks

SSTI – Server-side template injection with information disclosure via user-supplied objects

This is the write up for the PortSwigger Web Security Academy 5th lab in the series for Server-Side Template Injection (SSTI). This one is definitely a step up in complexity. This goes beyond identifying the location for the injection and…

  • scomurr
  • 02/25/2025
monkey riding a bike - ssti lab 4 - featured image
  • SSTI, Security, Web Attacks

SSTI – Server-side template injection in an unknown language with a documented exploit

This is the fourth lab from the PortSwigger Web Security Academy on SSTI or Server Side Template Injection. This lab solves in almost exactly the same way as the previous labs – it’s a matter of finding where the vulnerability…

  • scomurr
  • 02/20/2025
SSTI lab 3 - featured image
  • SSTI, Security, Web Attacks

SSTI – Server-side template injection using documentation

This is the third blog post covering server-side template injection and the associated PortSwigger Web Security Academy labs. This one, to me, is a lot like the last one. Like – exactly. That’s ok, though, as practice makes permanent. And…

  • scomurr
  • 02/17/2025
ssti lab 2 - alligator hacking and drinking coffee - featured image
  • SSTI, Security, Web Attacks

SSTI – Basic server-side template injection (code context)

Time for the second blog post as in regards to Server-Side Template Injection. This next lab goes a little deeper than the first. For the first lab, all we had to do was identify where a template may be in…

  • scomurr
  • 02/08/2025
Server Side Template Injection - SSTI - Basic Squirrel Hacking
  • SSTI, Security, Web Attacks

SSTI – Basic server-side template injection

I love hacking. Recently, YesWeHack released a video on YouTube of Brumens’s talk about advanced SSTI techniques from the 2024 Ekoparty conference. This has inspired me to circle back on this topic, redo the Portswigger labs and document. I know…

  • scomurr
  • 02/08/2025
Prev
1 2 3 4 5 … 19
Next
  • claude_with_qwen_featured_image
    Running Claude Code with Local Models via Ollama01/30/2026
  • n8n_429_too_many_requests
    n8n and 429s – Dealing with API Rate Limits01/29/2026
  • cloudflare tunnel for on-prem
    Cloudflare Tunnel Setup for On-Prem Hosting08/31/2025
  • ssti lab 7 - featured image
    SSTI – Server-side template injection with a custom exploit03/11/2025
  • ssti lab 6 - featured image
    SSTI – Server-side template injection in a sandboxed environment03/04/2025

Let's Talk

If your organization is struggling with cybersecurity strategy, compliance, or just figuring out where to start — I'm happy to chat.
No pressure, no pitch - just a conversation to see if I can help.

Reach out directly:

[email protected] | (612) 567-2150 | LinkedIn

Copyright © 2026