io.kent Posted May 30, 2013 Report Posted May 30, 2013 SSI-Scan is a basic PoC tool that helps facilitate the discovery of SSI injection vulnerabilities, a fairly rare and underdocumented code injection vulnerability where Server Side Includes directives are executed without proper validation and may lead to a system compromise or complete server enumeration.At this point, SSI-Scan tests for injection by sending a POST request encapsulated with a hardcoded payload or through injecting forms specified by the user with a payload and looking for environment variable matches in the page source.SSI-Scan requires BeautifulSoup4 and mechanize.Example usage: python ssi-scan.py -u http://example.compython ssi-scan.py -u http://example.com –form_uname username –form_passwd passwordFor more information on SSI injection:https://www.owasp.org/index.php/Server-Side_Includes_(SSI)_Injectionhttp://capec.mitre.org/data/definitions/101.htmlSSI-Scan will be receiving more updates to its functionality.TnX && Credit: fnordbgsursa: SSI-Scan [sSI injection scanner] | CyberPunk Quote