Skip to main content

ssti

Hunt server-side template injection across Jinja2/Twig/Freemarker/Velocity/Handlebars and validate progression from expression injection to code execution.

Zur Installation springen

Quellinformationen

Repository
BitterSecurity/Decepticon
Letzte Quellaktivität
2. Juni 2026 um 17:42
Erkannte Sprache von SKILL.md
Englisch
Sterne
5.611
Forks
1.061

Installationsoptionen

Standardmäßig ist der Prompt ausgewählt, der zuerst die Quelle prüft. Sie können zu einem direkten Befehl wechseln oder eine lokale Kopie herunterladen.

Quelldateien prüfen

Lesen Sie SKILL.md und alle von SkillsMP angezeigten Begleitdateien, bevor Sie sich für eine Installation entscheiden.

SKILL.md wird angezeigt

SKILL.md
Quellanweisungen · Schreibgeschützte Vorschau
name
ssti
description
Hunt server-side template injection across Jinja2/Twig/Freemarker/Velocity/Handlebars and validate progression from expression injection to code execution.
metadata
{"subdomain":"web-exploitation","when_to_use":"ssti server side template injection jinja2 twig freemarker velocity handlebars expression code execution"}
# SSTI Playbook ## High-signal checks - Look for template rendering with user input in `render_template_string`, `Template(...)`, `twig->createTemplate`, `Freemarker Template.process`. - Confirm user-controlled payload reaches a template context key or template source string. ## Fast probes - Jinja2: `{{7*7}}`, `{{config}}`, `{{request}}` - Twig: `{{7*7}}`, `{{_self}}` - Freemarker: `${7*7}` - Velocity: `#set($x=7*7)$x` ## Escalation path 1. Detect expression evaluation. 2. Enumerate available objects and filters. 3. Attempt file read / env leak. 4. Attempt command execution via framework-specific gadget chain. ## Validation Use `validate_finding` with a positive execution signal and a benign negative control.
Auf GitHub ansehen