Skip to main content

ssti

Hunt server-side template injection across Jinja2/Twig/Freemarker/Velocity/Handlebars and validate progression from expression injection to code execution.

インストールへ移動

ソース情報

リポジトリ
BitterSecurity/Decepticon
ソースの最終更新活動
2026年6月2日 17:42
検出された SKILL.md の言語
英語
スター
5,611
フォーク
1,061

インストール方法

デフォルトでは、最初にソースを確認する Prompt が選択されています。直接コマンドに切り替えるか、ローカルコピーをダウンロードすることもできます。

ソースファイルを確認

インストールを決める前に、SKILL.md と SkillsMP に表示されている付属ファイルをお読みください。

SKILL.md を表示中

SKILL.md
ソースの指示 · 読み取り専用プレビュー
name
ssti
description
Hunt server-side template injection across Jinja2/Twig/Freemarker/Velocity/Handlebars and validate progression from expression injection to code execution.
metadata
{"subdomain":"web-exploitation","when_to_use":"ssti server side template injection jinja2 twig freemarker velocity handlebars expression code execution"}
# SSTI Playbook ## High-signal checks - Look for template rendering with user input in `render_template_string`, `Template(...)`, `twig->createTemplate`, `Freemarker Template.process`. - Confirm user-controlled payload reaches a template context key or template source string. ## Fast probes - Jinja2: `{{7*7}}`, `{{config}}`, `{{request}}` - Twig: `{{7*7}}`, `{{_self}}` - Freemarker: `${7*7}` - Velocity: `#set($x=7*7)$x` ## Escalation path 1. Detect expression evaluation. 2. Enumerate available objects and filters. 3. Attempt file read / env leak. 4. Attempt command execution via framework-specific gadget chain. ## Validation Use `validate_finding` with a positive execution signal and a benign negative control.
GitHubで見る