# Server-side template injection checklist

Distinguish server-side template evaluation from simple reflection, identify the engine, and navigate engine-specific objects toward file or command execution.

## Recognition

- [ ] Arithmetic or expression syntax evaluates inside generated pages, emails, previews, names, themes, CMS content, or translation features.
- [ ] Errors mention template syntax, filters, classes, engine names, undefined variables, or sandbox restrictions.
- [ ] The same value renders differently in preview and saved output.

## Manual workflow

- [ ] Use harmless arithmetic probes in multiple syntaxes and compare evaluated output with literal reflection.
- [ ] Fingerprint Twig, Jinja, FreeMarker, Pug, Mustache, or Handlebars through syntax collisions and error language.
- [ ] Map the rendering context, available variables, filters, functions, objects, and sandbox behavior.
- [ ] Consult the exact engine/version documentation and construct the shortest engine-specific path.
- [ ] Confirm low-impact server-side access before invoking operating-system commands.
- [ ] Select a shell payload compatible with the server runtime and network reachability.
- [ ] Record each object or function transition; template-engine payloads are brittle without context.

## Escalation

- [ ] Read configuration or environment values exposed to the template.
- [ ] Reach language runtime objects, process APIs, or command helpers when the engine exposes them.
- [ ] Write a web shell or obtain a callback shell, then capture proof.txt.

## Pitfalls

- [ ] Assuming {{7*7}} uniquely identifies Jinja or Twig.
- [ ] Using payloads from a different engine, version, sandbox, or framework integration.
- [ ] Confusing client-side templates with server-side evaluation.
- [ ] Skipping intermediate confirmation and debugging only the final reverse shell.

## Evidence

- [ ] Literal-versus-evaluated proof
- [ ] Engine fingerprint
- [ ] Accessible object/function
- [ ] Command output or callback
- [ ] proof.txt from original location

## Tools

- [ ] Burp/ZAP resend
- [ ] SSTI fingerprint workbench
- [ ] Tplmap after manual confirmation
- [ ] Engine documentation

## Online references

- [PortSwigger SSTI guide and labs](<https://portswigger.net/web-security/server-side-template-injection>)
- [PayloadsAllTheThings SSTI](<https://github.com/swisskyrepo/PayloadsAllTheThings/tree/master/Server%20Side%20Template%20Injection>)

> Do you want to live curiously?
