White-box penetration testing: Debugging for Python vulnerabilities
ID: b60cca60-b585-5e67-ba4c-554d208bb325
STIX ID: report--b60cca60-b585-5e67-ba4c-554d208bb325
Feed Name: YesWeHack Blog
Threat Score
This article demonstrates a white‑box penetration test against a Dockerized Python Flask application vulnerable to server‑side template injection (SSTI). It covers setting up debugpy and VS Code remote debugging, includes the vulnerable application and Docker configuration, shows PoC Jinja2 payloads that yield RCE despite HTML escaping (including techniques to construct strings without quotes), and discusses related CWE categories and testing takeaways.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
