SSTImap

pinkman

BOSS
Staff member
ADMIN
LEGEND
ULTIMATE
SUPREME
MEMBER
BFD Legacy
Joined
Feb 3, 2025
Messages
2,253
Reaction score
19,020
Deposit
0$
SSTImap is a penetration testing software that can test websites for server-side code injection and template vulnerabilities and exploit them by providing access to the operating system itself.

Features

Interactive mode (-i) allowing for easier exploitation and detection
Simple evaluation payloads as response markers in case of payload reflection
Added new payloads for generic templates, as well as a way to speed up detection using --skip-generic
Base language eval()-like shell (-x) or single command (-X) execution
Added new payload for Smarty without enabled {php}{/php}. Old payload is available as Smarty_unsecure.
Added new payload for newer versions of Twig. Payload for older version is available as Twig_v1.
User-Agent can be randomly selected from a list of desktop browser agents using -A
SSL verification can now be enabled using --verify-ssl
Short versions added to many arguments
Some old command line arguments were changed, check -h for help
Code is changed to use newer python features
Burp Suite extension temporarily removed, as Jython doesn't support Python3
download:
 
SSTImap is a penetration testing software that can test websites for server-side code injection and template vulnerabilities and exploit them by providing access to the operating system itself.

Features

Interactive mode (-i) allowing for easier exploitation and detection
Simple evaluation payloads as response markers in case of payload reflection
Added new payloads for generic templates, as well as a way to speed up detection using --skip-generic
Base language eval()-like shell (-x) or single command (-X) execution
Added new payload for Smarty without enabled {php}{/php}. Old payload is available as Smarty_unsecure.
Added new payload for newer versions of Twig. Payload for older version is available as Twig_v1.
User-Agent can be randomly selected from a list of desktop browser agents using -A
SSL verification can now be enabled using --verify-ssl
Short versions added to many arguments
Some old command line arguments were changed, check -h for help
Code is changed to use newer python features
Burp Suite extension temporarily removed, as Jython doesn't support Python3
download: *** Hidden text: cannot be quoted. ***
woah
 
SSTImap is a penetration testing software that can test websites for server-side code injection and template vulnerabilities and exploit them by providing access to the operating system itself.

Features

Interactive mode (-i) allowing for easier exploitation and detection
Simple evaluation payloads as response markers in case of payload reflection
Added new payloads for generic templates, as well as a way to speed up detection using --skip-generic
Base language eval()-like shell (-x) or single command (-X) execution
Added new payload for Smarty without enabled {php}{/php}. Old payload is available as Smarty_unsecure.
Added new payload for newer versions of Twig. Payload for older version is available as Twig_v1.
User-Agent can be randomly selected from a list of desktop browser agents using -A
SSL verification can now be enabled using --verify-ssl
Short versions added to many arguments
Some old command line arguments were changed, check -h for help
Code is changed to use newer python features
Burp Suite extension temporarily removed, as Jython doesn't support Python3
download: *** Hidden text: cannot be quoted. ***
 
Top Bottom