đŸ”Ĩ Server Side Template Injection (SSTI) - Complete Red Team Guide

📋 Table of Contents

  1. 🧠 Core Theory & Concepts
  2. đŸŽ¯ Hacker's Strategy & Mindset
  3. 🧭 Target Mapping & Attack Surface Discovery
  4. âš’ī¸ Tools + Manual Approach Combo
  5. 🚀 Step-by-Step Exploitation
  6. đŸ§Ē Bypass + WAF Evasion
  7. 🎭 Authentication/Session Abuse
  8. đŸ›Ąī¸ Blue Team View
  9. 📝 Reporting Like a Pro
  10. 🧰 Learning Resources & Labs
  11. 🧠 Red Team Extra Knowledge
  12. đŸŽ¯ CTF/Interview Ready Section

1. 🧠 Core Theory & Concepts {#core-theory}

Vulnerability āϟāĻž āφāϏāϞ⧇ āϕ⧀?

Server Side Template Injection (SSTI) āĻšāϞ⧋ āĻāĻ•āϟāĻŋ critical vulnerability āϝ⧇āĻ–āĻžāύ⧇ attacker server-side template engine-āĻ malicious code inject āĻ•āϰāϤ⧇ āĻĒāĻžāϰ⧇āĨ¤ āĻāϟāĻŋ āϘāĻŸā§‡ āϝāĻ–āύ user input āϏāϰāĻžāϏāϰāĻŋ template engine-āĻ pass āĻšāϝāĻŧ āϕ⧋āύ proper validation āĻ›āĻžāĻĄāĻŧāĻžāχāĨ¤

āϏāĻšāϜ āĻ•āĻĨāĻžāϝāĻŧ: Web application āϝāĻ–āύ dynamic content generate āĻ•āϰāĻžāϰ āϜāĻ¨ā§āϝ template engine āĻŦā§āϝāĻŦāĻšāĻžāϰ āĻ•āϰ⧇ (āϝ⧇āĻŽāύ Jinja2, Twig, Freemarker), āĻāĻŦāĻ‚ user input āϏ⧇āχ template-āĻ directly embed āĻšāϝāĻŧ⧇ āϝāĻžāϝāĻŧ, āϤāĻ–āύ SSTI vulnerability āϤ⧈āϰāĻŋ āĻšāϝāĻŧāĨ¤

āĻāϟāĻž āĻ•āĻŋāĻ­āĻžāĻŦ⧇ āĻ•āĻžāϜ āĻ•āϰ⧇?