Skip to content

Burp Suite extension that enhances Burp Active Scan by adding template engine specific SSTI payloads.

Notifications You must be signed in to change notification settings

efecankaya/BlindSSTIScanner

Repository files navigation

Blind SSTI Scanner for Burp Suite

This extension enchances Burp Suite's Active Scan by adding template engine specific payloads to detect remote code execution via server-side template injection. The extension utilizes polyglot payloads and code context escaping for efficient and accurate detection.

Usage

Run an Active Scan against the target. Identified vulnerabilities will be reported as scanner issues.

Installation

To install the extension, download the jar file from the releases page, and add it to Burp Suite from Extensions > Add.

Configuration options

Detection and Efficiency Template Engines Polling

About

Burp Suite extension that enhances Burp Active Scan by adding template engine specific SSTI payloads.

Topics

Resources

Stars

Watchers

Forks

Packages

No packages published

Languages