Server Side Template Injection Strings

 Original Source: [Sigma source]
Title: Server Side Template Injection Strings
Status: test
Description:Detects SSTI attempts sent via GET requests in access logs
References:
  -https://book.hacktricks.xyz/pentesting-web/ssti-server-side-template-injection
  -https://github.com/payloadbox/ssti-payloads
Author: Nasreddine Bencherchali (Nextron Systems)
Date: 2022-06-14
modified:None
Tags:
  • -'attack.stealth'
  • -'attack.t1221'
Logsource:
  • category: webserver
Detection:
  select_method:
    cs-method: 'GET'
  keywords:
    - '={{'
    - '=%7B%7B'
    - '=${'
    - '=$%7B'
    - '=<%='
    - '=%3C%25='
    - '=@('
    - 'freemarker.template.utility.Execute'
    - '.getClass().forName('javax.script.ScriptEngineManager')'
    - 'T(org.apache.commons.io.IOUtils)'
  filter:
    sc-status: '404'
  condition:select_method and keywords and not filter
Falsepositives:
  -User searches in search boxes of the respective website
  -Internal vulnerability scanners can cause some serious FPs when used, if you experience a lot of FPs due to this think of adding more filters such as "User Agent" strings and more response codes
Level: high