Skip to content

Source code examples for the Lightning Talk: Fun With Templates

Notifications You must be signed in to change notification settings

nickelaway/FunWithTemplates

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

2 Commits
 
 
 
 
 
 
 
 

Repository files navigation

FunWithTemplates

Source code examples for the Lightning Talk: Fun With Templates

These are some simple examples of using Apache Velocity Templates, including an example of using template injection for remote code execution.

These examples are for an internal lightning talk given at LMAX demonstrating the research presented by James Kettle of PortSwigger Security at BlackHat USA 2015.

For more details on his research, see http://blog.portswigger.net/2015/08/server-side-template-injection.html

About

Source code examples for the Lightning Talk: Fun With Templates

Resources

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published

Languages