Server Side Template Injection Strings
Description
Detects SSTI attempts sent via GET requests in access logs
Query · sigma
select_method:
cs-method: GET
keywords:
- ={{
- =%7B%7B
- =${
- =$%7B
- =<%=
- =%3C%25=
- =@(
- freemarker.template.utility.Execute
- .getClass().forName('javax.script.ScriptEngineManager')
- T(org.apache.commons.io.IOUtils)
filter:
sc-status: 404
condition: select_method and keywords and not filter
Known false positives
- User searches in search boxes of the respective website
- Internal vulnerability scanners can cause some serious FPs when used, if you experience a lot of FPs due to this think of adding more filters such as "User Agent" strings and more response codes