Server Site Template Injection(SSTI)

H4C ์›Œ๊ฒŒ์ž„์„ ํ’€๋‹ค๊ฐ€ SSTI์—์„œ ๋ง‰ํ˜€๋ฒ„๋ ธ๋‹ค. SSTI์— ๋Œ€ํ•ด์„œ๋Š” ์ž˜ ์•ˆ๋‹ค๊ณ  ์ƒ๊ฐํ–ˆ๋Š”๋ฐ, ๋ฌธ์ œ ์ถœ์ œ์ž๊ฐ€ ๊ฑฐ์˜ ๋ชจ๋“  ํ‚ค์›Œ๋“œ๋ฅผ ํ•„ํ„ฐ๋ง ํ•ด ๋†“์•„์„œ.. ์–ด๋–ป๊ฒŒ ์ ‘๊ทผํ•ด์•ผํ• ์ง€ ๊ฐ์ด ์•ˆ์˜จ๋‹ค.. Jinjja๋ผ๋Š” ๋ฌธ์ œ์ธ๋ฐ.. https://h4ckingga.me/challenges#Season1%20:%20Jinjja-33 ๊ทธ๋ž˜์„œ SSTI์— ๋Œ€ํ•ด์„œ ๋‹ค์‹œ ๊ณต๋ถ€ํ•ด๋ณผ๊ฒธ ๊ฒธ์‚ฌ๊ฒธ์‚ฌ ์ •๋ฆฌ๋ฅผ ํ•œ๋ฒˆ ํ•ด๋ณผ๋ ค๊ณ ํ•œ๋‹ค. 1. Server Side Template Injection(SSTI) ๋ž€ ๋ฌด์—‡์ธ๊ฐ€? ์–ด๋А ๊ณต๋ถ€๋ฅผ ํ•˜๋“  ๊ฐ™๊ฒ ์ง€๋งŒ, ์ง€๊ธˆ ๋‚ด๊ฐ€ ์•Œ๊ณ ์ž ํ•˜๋Š” ๊ฒƒ์ด ๋ฌด์—‡์ธ์ง€ ๋ช…ํ™•ํ•˜๊ฒŒ ์•„๋Š”๊ฒƒ์ด ๊ฐ€์žฅ ์ค‘์š”ํ•˜๋‹ค. SSTI๋ฅผ ๋ฒˆ์—ญํ•ด๋ณด์ž๋ฉด, ์„œ๋ฒ„์—์„œ ๋ฐœ์ƒํ•˜๋Š” ํ…œํ”Œ๋ฆฟ ์ธ์ ์…˜ ๊ณต๊ฒฉ์ด๋‹ค. ๊ทธ๊ฒŒ ๋ญ”์†Œ๋ฆฐ๊ฐ€ ์‹ถ์„ ์ˆ˜ ์žˆ๋‹ค. CSRF์™€ ์œ ์‚ฌํ•˜๋‹ค๊ณ  ์ƒ๊ฐํ•ด๋ณผ์ˆ˜๋„ ์žˆ๋‹ค. ...

November 12, 2025 ยท 9 min ยท 1735 words ยท quasitiger