100% Free Forever
AI-Powered Learning
Industry Expert Content
Certificates & Badges
Learn At Your Own Pace
Web Application Security
25 minintermediate

Server-Side Template Injection (SSTI) Basics

Server-Side Template Injection occurs when user input is embedded into a server-side template that is then evaluated by the template engine. Because template engines can execute expressions, and in many cases reach powerful language features, treating user input as part of the template rather than as data passed to it can lead to remote code execution on the server. It is injection with unusually severe consequences.

Analogy🏏Cricket
🍳 Think of it like cooking: A recipe can look flawless on paper, but a head chef only truly judges the dish by tasting the finished plate, because heat, timing, and the actual oven reveal problems the written method never shows. Just as tasting the cooked result catches what reading the recipe cannot, DAST probes the running application and catches the misconfigurations and runtime behaviour that reading the source cannot. This reveals DAST's stance: it judges the dish as it is actually served, not the recipe as it was merely written.

The subtlety is that SSTI looks like ordinary output at first glance, and is easily confused with XSS. The distinction is decisive: XSS runs in the victim's browser, while SSTI runs on your server. This lesson explains how the flaw arises, how the engine evaluates the injected expression, and why the fix is to render data through the template rather than into it.

Analogy🏏Cricket
💰 Think of it like finance: A real audit that actually attempts a sample transaction proves beyond doubt whether a control can be bypassed, with little room for a false alarm, but it can only test the accounts and processes the auditors actually reach. Just as a hands-on audit yields high-confidence, low-false-positive results yet is bounded by what it examines, DAST yields high-confidence findings about real exploitability yet is bounded by the surface it can reach. This reveals its trade-off: what it confirms is solid, but it only confirms what it manages to touch.
Lesson 11 of 35
0% complete