daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

asp.md (1643B)


      1 ---
      2 title: "Server Side Template Injection - ASP.NET"
      3 topic: "Server Side Template Injection"
      4 topicSlug: "server-side-template-injection"
      5 sourcePath: "Server Side Template Injection/ASP.md"
      6 sourceUrl: "https://github.com/swisskyrepo/PayloadsAllTheThings/blob/3ac27901c711/Server%20Side%20Template%20Injection/ASP.md"
      7 sha: "3ac27901c711"
      8 isReadme: false
      9 ---
     10 
     11 # Server Side Template Injection - ASP.NET
     12 
     13 > Server-Side Template Injection (SSTI)  is a class of vulnerabilities where an attacker can inject malicious input into a server-side template, causing the template engine to execute arbitrary code on the server. In the context of ASP.NET, SSTI can occur if user input is directly embedded into a template (such as Razor, ASPX, or other templating engines) without proper sanitization.
     14 
     15 ## Summary
     16 
     17 - [ASP.NET Razor](#aspnet-razor)
     18     - [ASP.NET Razor - Basic Injection](#aspnet-razor---basic-injection)
     19     - [ASP.NET Razor - Command Execution](#aspnet-razor---command-execution)
     20 - [References](#references)
     21 
     22 ## ASP.NET Razor
     23 
     24 [Official website](https://docs.microsoft.com/en-us/aspnet/web-pages/overview/getting-started/introducing-razor-syntax-c)
     25 
     26 > Razor is a markup syntax that lets you embed server-based code (Visual Basic and C#) into web pages.
     27 
     28 ### ASP.NET Razor - Basic Injection
     29 
     30 ```powershell
     31 @(1+2)
     32 ```
     33 
     34 ### ASP.NET Razor - Command Execution
     35 
     36 ```csharp
     37 @{
     38   // C# code
     39 }
     40 ```
     41 
     42 ## References
     43 
     44 - [Server-Side Template Injection (SSTI) in ASP.NET Razor - Clément Notin - April 15, 2020](https://web.archive.org/web/20240905143644/http://clement.notin.org/blog/2020/04/15/Server-Side-Template-Injection-(SSTI)-in-ASP.NET-Razor/)