daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

index.md (12499B)


      1 ---
      2 title: "Server Side Template Injection"
      3 topic: "Server Side Template Injection"
      4 topicSlug: "server-side-template-injection"
      5 sourcePath: "Server Side Template Injection/README.md"
      6 sourceUrl: "https://github.com/swisskyrepo/PayloadsAllTheThings/blob/3ac27901c711/Server%20Side%20Template%20Injection/README.md"
      7 sha: "3ac27901c711"
      8 isReadme: true
      9 ---
     10 
     11 # Server Side Template Injection
     12 
     13 > Template injection allows an attacker to include template code into an existing (or not) template. A template engine makes designing HTML pages easier by using static template files which at runtime replaces variables/placeholders with actual values in the HTML pages.
     14 
     15 ## Summary
     16 
     17 - [Tools](#tools)
     18 - [Methodology](#methodology)
     19     - [Detection and Exploitation Techniques](#detection-and-exploitation-techniques)
     20         - [Rendered](#rendered)
     21         - [Error-Based](#error-based)
     22         - [Boolean-Based](#boolean-based)
     23         - [Time-Based](#time-based)
     24         - [Out of Bounds](#out-of-bounds)
     25         - [Polyglot-Based](#polyglot-based)
     26     - [Universal Detection Payloads](#universal-detection-payloads)
     27     - [Manual Detection and Exploitation](#manual-detection-and-exploitation)
     28         - [Identify the Vulnerable Input Field](#identify-the-vulnerable-input-field)
     29         - [Inject Template Syntax](#inject-template-syntax)
     30         - [Enumerate the Template Engine](#enumerate-the-template-engine)
     31         - [Escalate to Code Execution](#escalate-to-code-execution)
     32 - [Labs](#labs)
     33 - [References](#references)
     34 
     35 ## Tools
     36 
     37 - [Hackmanit/TInjA](https://github.com/Hackmanit/TInjA) - An efficient SSTI + CSTI scanner which utilizes novel polyglots
     38 
     39   ```bash
     40   tinja url -u "http://example.com/?name=Kirlia" -H "Authentication: Bearer ey..."
     41   tinja url -u "http://example.com/" -d "username=Kirlia"  -c "PHPSESSID=ABC123..."
     42   ```
     43 
     44 - [epinna/tplmap](https://github.com/epinna/tplmap) - Server-Side Template Injection and Code Injection Detection and Exploitation Tool
     45 
     46   ```powershell
     47   python2.7 ./tplmap.py -u 'http://www.target.com/page?name=John*' --os-shell
     48   python2.7 ./tplmap.py -u "http://192.168.56.101:3000/ti?user=*&comment=supercomment&link"
     49   python2.7 ./tplmap.py -u "http://192.168.56.101:3000/ti?user=InjectHere*&comment=A&link" --level 5 -e jade
     50   ```
     51 
     52 - [vladko312/SSTImap](https://github.com/vladko312/SSTImap) - Automatic SSTI detection tool with interactive interface based on [epinna/tplmap](https://github.com/epinna/tplmap)
     53 
     54   ```bash
     55   python3 ./sstimap.py -u 'https://example.com/page?name=John' -s
     56   python3 ./sstimap.py -i -u 'https://example.com/page?name=Vulnerable*&message=My_message' -l 5 -e jade
     57   python3 ./sstimap.py -i -A -m POST -l 5 -H 'Authorization: Basic bG9naW46c2VjcmV0X3Bhc3N3b3Jk'
     58   ```
     59 
     60 ## Methodology
     61 
     62 ### Detection and Exploitation Techniques
     63 
     64 Original research:
     65 
     66 - Rendered, Time-Based: [Server-Side Template Injection: RCE For The Modern Web App - James Kettle - August 05, 2015](https://portswigger.net/knowledgebase/papers/serversidetemplateinjection.pdf)
     67 - Polyglot-Based: [Improving the Detection and Identification of Template Engines for Large-Scale Template Injection Scanning - Maximilian Hildebrand - September 19, 2023](https://www.hackmanit.de/images/download/thesis/Improving-the-Detection-and-Identification-of-Template-Engines-for-Large-Scale-Template-Injection-Scanning-Maximilian-Hildebrand-Master-Thesis-Hackmanit.pdf)
     68 - Error-Based, Boolean-Based: [Successful Errors: New Code Injection and SSTI Techniques - Vladislav Korchagin - January 03, 2026](https://github.com/vladko312/Research_Successful_Errors/blob/main/README.md)
     69 
     70 #### Rendered
     71 
     72 ![Rendered technique workflow](https://raw.githubusercontent.com/swisskyrepo/PayloadsAllTheThings/3ac27901c711/Server%20Side%20Template%20Injection/Images/technique_Rendered.png)
     73 
     74 > Applicability: detection, exploitation
     75 
     76 When the rendered template is displayed to the attacker, Rendered technique can be used to include the results of the injected code on the page.
     77 
     78 #### Error-Based
     79 
     80 ![Error-Based technique workflow](https://raw.githubusercontent.com/swisskyrepo/PayloadsAllTheThings/3ac27901c711/Server%20Side%20Template%20Injection/Images/technique_Error-Based.png)
     81 
     82 > Applicability: detection, exploitation
     83 
     84 When the errors are verbosely displayed to the attacker, Error-Based technique can be used to trigger the error message containing the results of the injected code.
     85 
     86 #### Boolean-Based
     87 
     88 ![Boolean-Based technique workflow](https://raw.githubusercontent.com/swisskyrepo/PayloadsAllTheThings/3ac27901c711/Server%20Side%20Template%20Injection/Images/technique_Boolean-Based.png)
     89 
     90 > Applicability: detection, blind exploitation, blind data exfiltration
     91 
     92 Boolean-Based technique can be used to conditionally trigger an error to indicate success or failure of the injected code.
     93 
     94 #### Time-Based
     95 
     96 ![Time-Based technique workflow](https://raw.githubusercontent.com/swisskyrepo/PayloadsAllTheThings/3ac27901c711/Server%20Side%20Template%20Injection/Images/technique_Time-Based.png)
     97 
     98 > Applicability: limited detection, blind exploitation, blind data exfiltration
     99 
    100 Time-Based technique can be used to conditionally trigger the delay to indicate success or failure of the injected code.
    101 
    102 Triggering the delay often requires guessing payloads for code evaluation or OS command execution.
    103 
    104 #### Out of Bounds
    105 
    106 > Applicability: limited detection, exploitation
    107 
    108 Out of Bounds technique can be used to expose results of the injected code through other channels (e.g. by connecting to an attacker-controlled server).
    109 
    110 This technique often requires guessing payloads for code evaluation or OS command execution.
    111 
    112 #### Polyglot-Based
    113 
    114 ![Polyglot-Based technique workflow](https://raw.githubusercontent.com/swisskyrepo/PayloadsAllTheThings/3ac27901c711/Server%20Side%20Template%20Injection/Images/technique_Polyglot-Based.png)
    115 
    116 > Applicability: detection
    117 
    118 Polyglot-Based technique can be used to quickly determine the template engine by checking how it transforms different payloads.
    119 
    120 ### Universal Detection Payloads
    121 
    122 Polyglot to trigger an error in presence of SSTI vulnerability:
    123 
    124 ```ps1
    125 ${{<%[%'"}}%\.
    126 ```
    127 
    128 Common tags to test for SSTI with code evaluation:
    129 
    130 ```powershell
    131 {{ ... }}
    132 ${ ... }
    133 #{ ... }
    134 <%= ... %>
    135 { ... }
    136 {{= ... }}
    137 {= ... }
    138 \n= ... \n
    139 *{ ... }
    140 @{ ... }
    141 @( ... )
    142 ```
    143 
    144 Rendered SSTI can be checked by using mathematical expressions inside the tags:
    145 
    146 ```powershell
    147 7 * 7
    148 ```
    149 
    150 Error-Based SSTI can be checked by using this payload inside the tags:
    151 
    152 ```powershell
    153 (1/0).zxy.zxy
    154 ```
    155 
    156 If the error caused by that payload is displayed verbosely, it can be checked to guess the language used for code evaluation:
    157 
    158 | Error                         | Language          |
    159 |-------------------------------|-------------------|
    160 | ZeroDivisionError             | Python            |
    161 | java.lang.ArithmeticException | Java              |
    162 | ReferenceError                | NodeJS            |
    163 | TypeError                     | NodeJS            |
    164 | Division by zero              | PHP               |
    165 | DivisionByZeroError           | PHP               |
    166 | divided by 0                  | Ruby              |
    167 | Arithmetic operation failed   | Freemarker (Java) |
    168 
    169 To test for blind injections using Boolean-Based technique, the attacker can test pairs of similar payloads wrapped in tags, where one payload evaluates mathematical expression, while the other triggers syntax error:
    170 
    171 | test | ok              | error           |
    172 |------|-----------------|-----------------|
    173 | 1    | `(3*4/2)`       | `3*)2(/4`       |
    174 | 2    | `((7*8)/(2*4))` | `7)(*)8)(2/(*4` |
    175 
    176 Using at least two pairs of payloads avoids false positives caused by external interference.
    177 
    178 ### Manual Detection and Exploitation
    179 
    180 #### Identify the Vulnerable Input Field
    181 
    182 The attacker first locates an input field, URL parameter, or any user-controllable part of the application that is passed into a server-side template without proper sanitization or escaping.
    183 
    184 For example, the attacker might identify a web form, search bar, or template preview functionality that seems to return results based on dynamic user input.
    185 
    186 **TIP**: Generated PDF files, invoices and emails usually use a template.
    187 
    188 #### Inject Template Syntax
    189 
    190 The attacker tests the identified input field by injecting template syntax specific to the template engine in use. Different web frameworks use different template engines (e.g., Jinja2 for Python, Twig for PHP, or FreeMarker for Java).
    191 
    192 Common template expressions:
    193 
    194 - `{{7*7}}` for Jinja2 (Python).
    195 - `#{7*7}` for Thymeleaf (Java).
    196 
    197 Find more template expressions in the page dedicated to the technology (PHP, Python, etc).
    198 
    199 ![SSTI cheatsheet workflow](https://raw.githubusercontent.com/swisskyrepo/PayloadsAllTheThings/3ac27901c711/Server%20Side%20Template%20Injection/Images/serverside.png)
    200 
    201 In most cases, this polyglot payload will trigger an error in presence of a SSTI vulnerability:
    202 
    203 ```ps1
    204 ${{<%[%'"}}%\.
    205 ```
    206 
    207 The [Hackmanit/Template Injection Table](https://github.com/Hackmanit/template-injection-table) is an interactive table containing the most efficient template injection polyglots along with the expected responses of the 44 most important template engines.
    208 
    209 #### Enumerate the Template Engine
    210 
    211 Based on the successful response, the attacker determines which template engine is being used. This step is critical because different template engines have different syntax, features, and potential for exploitation. The attacker may try different payloads to see which one executes, thereby identifying the engine.
    212 
    213 - **Python**: Django, Jinja2, Mako, ...
    214 - **Java**: Freemarker, Jinjava, Velocity, ...
    215 - **Ruby**: ERB, Slim, ...
    216 
    217 [The post "template-engines-injection-101" from @0xAwali](https://medium.com/@0xAwali/template-engines-injection-101-4f2fe59e5756) summarize the syntax and detection method for most of the template engines for JavaScript, Python, Ruby, Java and PHP and how to differentiate between engines that use the same syntax.
    218 
    219 #### Escalate to Code Execution
    220 
    221 Once the template engine is identified, the attacker injects more complex expressions, aiming to execute server-side commands or arbitrary code.
    222 
    223 ## Labs
    224 
    225 - [Root Me - Java - Server-side Template Injection](https://www.root-me.org/en/Challenges/Web-Server/Java-Server-side-Template-Injection)
    226 - [Root Me - Python - Server-side Template Injection Introduction](https://www.root-me.org/en/Challenges/Web-Server/Python-Server-side-Template-Injection-Introduction)
    227 - [Root Me - Python - Blind SSTI Filters Bypass](https://www.root-me.org/en/Challenges/Web-Server/Python-Blind-SSTI-Filters-Bypass)
    228 
    229 ## References
    230 
    231 - [Server-Side Template Injection: RCE For The Modern Web App - James Kettle - August 05, 2015](https://web.archive.org/web/20160311193057/https://portswigger.net/knowledgebase/papers/ServerSideTemplateInjection.pdf)
    232 - [Improving the Detection and Identification of Template Engines for Large-Scale Template Injection Scanning - Maximilian Hildebrand - September 19, 2023](https://web.archive.org/web/20231210014226/https://www.hackmanit.de/images/download/thesis/Improving-the-Detection-and-Identification-of-Template-Engines-for-Large-Scale-Template-Injection-Scanning-Maximilian-Hildebrand-Master-Thesis-Hackmanit.pdf)
    233 - [Successful Errors: New Code Injection and SSTI Techniques - Vladislav Korchagin - January 3, 2026](https://github.com/vladko312/Research_Successful_Errors/blob/main/README.md)
    234 - [A Pentester's Guide to Server Side Template Injection (SSTI) - Busra Demir - December 24, 2020](https://web.archive.org/web/20260111213449/https://www.cobalt.io/blog/a-pentesters-guide-to-server-side-template-injection-ssti)
    235 - [Gaining Shell using Server Side Template Injection (SSTI) - David Valles - August 22, 2018](https://web.archive.org/web/20180928123607/https://medium.com/@david.valles/gaining-shell-using-server-side-template-injection-ssti-81e29bb8e0f9)
    236 - [Template Engines Injection 101 - Mahmoud M. Awali - November 1, 2024](https://web.archive.org/web/20251104003639/https://medium.com/@0xAwali/template-engines-injection-101-4f2fe59e5756)
    237 - [Template Injection On Hardened Targets - Lucas 'BitK' Philippe - September 28, 2022](https://web.archive.org/web/20230314135020/https://youtu.be/M0b_KA0OMFw)
    238 - [Limitations are just an illusion – advanced server-side template exploitation with RCE everywhere - YesWeHack, Brumens - March 24, 2025](https://web.archive.org/web/20240906203847/https://www.yeswehack.com/learn-bug-bounty/server-side-template-injection-exploitation)