/BlindSSTIScanner

Burp Suite extension that enhances Burp Active Scan by adding template engine specific SSTI payloads.

Primary LanguageJava

Blind SSTI Scanner for Burp Suite

This extension enchances Burp Suite's Active Scan by adding template engine specific payloads to detect remote code execution via server-side template injection. The extension utilizes polyglot payloads and code context escaping for efficient and accurate detection.

Usage

Run an Active Scan against the target. Identified vulnerabilities will be reported as scanner issues.

Installation

To install the extension, download the jar file from the releases page, and add it to Burp Suite from Extensions > Add.

Configuration options

Detection and Efficiency Template Engines Polling