← all labs
Advanced
WEB+SSH
★★★☆☆

Template Injection

Execute code through template engines

/start ssti
35
Total Solves
7m 5s
Avg Solve Time
1
First Blood Claimed
13s
Record Time

// FIRST BLOOD

cracked in 4m 49s

// TOP 10 FASTEST

#1 khan 13s
#2 User 0755 47s
#3 r 1m 4s
#4 harpy 1m 17s
#5 iamunknown77 1m 22s
#6 narraio_ 1m 55s
#7 F03ever 2m 48s
#8 privalman 2m 55s
#9 Keeko 3m 25s
#10 shinytomixs 3m 42s

// RELATED · Advanced TIER

Token Forger
WEB+SSH Forge authentication tokens
★★★☆☆
Root Access
SSH Escalate from user to root via SUID
★★★☆☆
Internal Access
WEB+SSH Access internal services through SSRF
★★★☆☆
Hash Cracker
WEB+SSH Crack weak password hashes from an exposed database
★★★☆☆
Blind Injection
WEB+SSH Extract data through boolean-based blind SQL injection
★★★☆☆
Race the Clock
WEB Exploit a race condition to bypass purchase limits
★★★☆☆

Spawn this box.
Capture the flag.

Join the Discord and type /start ssti to spin up your own container.