Title:
Server Side Template Injection Strings
Status:
test
Description:Detects SSTI attempts sent via GET requests in access logs
References:
-https://book.hacktricks.xyz/pentesting-web/ssti-server-side-template-injection
-https://github.com/payloadbox/ssti-payloads
Author: Nasreddine Bencherchali (Nextron Systems)
Date: 2022-06-14
modified:None
Tags:
- -'attack.stealth'
- -'attack.t1221'
Logsource:
Detection:
select_method:
cs-method:
'GET'
keywords:
- '={{'
- '=%7B%7B'
- '=${'
- '=$%7B'
- '=<%='
- '=%3C%25='
- '=@('
- 'freemarker.template.utility.Execute'
- '.getClass().forName('javax.script.ScriptEngineManager')'
- 'T(org.apache.commons.io.IOUtils)'
filter:
sc-status:
'404'
condition:
select_method and keywords and not filter
Falsepositives:
-User searches in search boxes of the respective website
-Internal vulnerability scanners can cause some serious FPs when used, if you experience a lot of FPs due to this think of adding more filters such as "User Agent" strings and more response codes
Level:
high