> ## Documentation Index
> Fetch the complete documentation index at: https://rootea.es/llms.txt
> Use this file to discover all available pages before exploring further.

# SSTI (Server-Side Template Injection)

> Recursos cross-platform para SSTI (Server-Side Template Injection): máquinas HTB, labs PortSwigger y rooms TryHackMe curados, con writeups validados y skills relacionadas.

# SSTI (Server-Side Template Injection)

Esta página agrega los **recursos para practicar SSTI (Server-Side Template Injection)** de forma cross-platform: máquinas retiradas de Hack The Box, labs de PortSwigger Web Security Academy y rooms de TryHackMe, más recursos curados (HackTricks, PortSwigger, etc.) y skills relacionadas.

## Recursos curados

| Fuente      | Enlace                                                                                                                                     |
| ----------- | ------------------------------------------------------------------------------------------------------------------------------------------ |
| PortSwigger | [https://portswigger.net/web-security/server-side-template-injection](https://portswigger.net/web-security/server-side-template-injection) |

## Máquinas HTB que practican SSTI (Server-Side Template Injection) (12)

| Máquina                                              | SO      | Dificultad                                           |
| ---------------------------------------------------- | ------- | ---------------------------------------------------- |
| [Anubis](/htb/machines/windows/insano/anubis)        | Windows | <span className="dbadge dbadge-insane">INSANE</span> |
| [Bolt](/htb/machines/linux/medio/bolt)               | Linux   | <span className="dbadge dbadge-medium">MEDIUM</span> |
| [Catch](/htb/machines/linux/medio/catch)             | Linux   | <span className="dbadge dbadge-medium">MEDIUM</span> |
| [Doctor](/htb/machines/linux/facil/doctor)           | Linux   | <span className="dbadge dbadge-easy">EASY</span>     |
| [Epsilon](/htb/machines/linux/medio/epsilon)         | Linux   | <span className="dbadge dbadge-medium">MEDIUM</span> |
| [Flustered](/htb/machines/linux/medio/flustered)     | Linux   | <span className="dbadge dbadge-medium">MEDIUM</span> |
| [GoodGames](/htb/machines/linux/facil/goodgames)     | Linux   | <span className="dbadge dbadge-easy">EASY</span>     |
| [Hancliffe](/htb/machines/windows/dificil/hancliffe) | Windows | <span className="dbadge dbadge-hard">HARD</span>     |
| [Late](/htb/machines/linux/facil/late)               | Linux   | <span className="dbadge dbadge-easy">EASY</span>     |
| [Noter](/htb/machines/linux/medio/noter)             | Linux   | <span className="dbadge dbadge-medium">MEDIUM</span> |
| [NunChucks](/htb/machines/linux/facil/nunchucks)     | Linux   | <span className="dbadge dbadge-easy">EASY</span>     |
| [Oz](/htb/machines/linux/dificil/oz)                 | Linux   | <span className="dbadge dbadge-hard">HARD</span>     |

## Labs PortSwigger que practican SSTI (Server-Side Template Injection) (7)

| Lab                                                                                                                                                                                                                                      | Dificultad                                                 | Topic                                 | Oficial                                                                                                                                                                          |
| ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------- | ------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| [Server-side template injection in a sandboxed environment](/portswigger/labs/server-side-template-injection/exploiting-server-side-template-injection-in-a-sandboxed-environment)                                                       | <span className="dbadge dbadge-easy">APPRENTICE</span>     | Server-Side Template Injection (SSTI) | [Abrir](https://portswigger.net/web-security/server-side-template-injection/exploiting/lab-server-side-template-injection-in-a-sandboxed-environment)                            |
| [Server-side template injection with a custom exploit](/portswigger/labs/server-side-template-injection/exploiting-server-side-template-injection-with-a-custom-exploit)                                                                 | <span className="dbadge dbadge-easy">APPRENTICE</span>     | Server-Side Template Injection (SSTI) | [Abrir](https://portswigger.net/web-security/server-side-template-injection/exploiting/lab-server-side-template-injection-with-a-custom-exploit)                                 |
| [Basic server-side template injection](/portswigger/labs/server-side-template-injection/exploiting-server-side-template-injection-basic)                                                                                                 | <span className="dbadge dbadge-medium">PRACTITIONER</span> | Server-Side Template Injection (SSTI) | [Abrir](https://portswigger.net/web-security/server-side-template-injection/exploiting/lab-server-side-template-injection-basic)                                                 |
| [Basic server-side template injection (code context)](/portswigger/labs/server-side-template-injection/exploiting-server-side-template-injection-basic-code-context)                                                                     | <span className="dbadge dbadge-medium">PRACTITIONER</span> | Server-Side Template Injection (SSTI) | [Abrir](https://portswigger.net/web-security/server-side-template-injection/exploiting/lab-server-side-template-injection-basic-code-context)                                    |
| [Server-side template injection in an unknown language with a documented exploit](/portswigger/labs/server-side-template-injection/exploiting-server-side-template-injection-in-an-unknown-language-with-a-documented-exploit)           | <span className="dbadge dbadge-medium">PRACTITIONER</span> | Server-Side Template Injection (SSTI) | [Abrir](https://portswigger.net/web-security/server-side-template-injection/exploiting/lab-server-side-template-injection-in-an-unknown-language-with-a-documented-exploit)      |
| [Server-side template injection using documentation](/portswigger/labs/server-side-template-injection/exploiting-server-side-template-injection-using-documentation)                                                                     | <span className="dbadge dbadge-medium">PRACTITIONER</span> | Server-Side Template Injection (SSTI) | [Abrir](https://portswigger.net/web-security/server-side-template-injection/exploiting/lab-server-side-template-injection-using-documentation)                                   |
| [Server-side template injection with information disclosure via user-supplied objects](/portswigger/labs/server-side-template-injection/exploiting-server-side-template-injection-with-information-disclosure-via-user-supplied-objects) | <span className="dbadge dbadge-medium">PRACTITIONER</span> | Server-Side Template Injection (SSTI) | [Abrir](https://portswigger.net/web-security/server-side-template-injection/exploiting/lab-server-side-template-injection-with-information-disclosure-via-user-supplied-objects) |

## Rooms TryHackMe que practican SSTI (Server-Side Template Injection) (5)

| Room                                                                               | Dificultad                                         | Tipo        | Acceso  | Oficial                                                         |
| ---------------------------------------------------------------------------------- | -------------------------------------------------- | ----------- | ------- | --------------------------------------------------------------- |
| [OWASP Top 10 2025: Insecure Data Handling](/tryhackme/rooms/owasptopten2025three) | <span className="dbadge dbadge-easy">EASY</span>   | Walkthrough | 🟢 Free | [Abrir](https://tryhackme.com/room/owasptopten2025three)        |
| [Hip Flask](/tryhackme/rooms/hipflask)                                             | <span className="dbadge dbadge-easy">MEDIUM</span> | Walkthrough | 🟢 Free | [Abrir](https://tryhackme.com/room/hipflask)                    |
| [NoNameCTF](/tryhackme/rooms/nonamectf)                                            | <span className="dbadge dbadge-easy">MEDIUM</span> | Challenge   | 🔵 VIP  | [Abrir](https://tryhackme.com/room/nonamectf)                   |
| [Server-side Template Injection](/tryhackme/rooms/serversidetemplateinjection)     | <span className="dbadge dbadge-easy">MEDIUM</span> | Walkthrough | 🔵 VIP  | [Abrir](https://tryhackme.com/room/serversidetemplateinjection) |
| [SSTI](/tryhackme/rooms/learnssti)                                                 | <span className="dbadge dbadge-easy">MEDIUM</span> | Walkthrough | 🟢 Free | [Abrir](https://tryhackme.com/room/learnssti)                   |

## Skills relacionadas

* [/skills/rce](/skills/rce)

***

← [Volver al glosario completo](/glosario)

<script type="application/ld+json">
  {`{"@context":"https://schema.org","@type":"DefinedTerm","name":"SSTI (Server-Side Template Injection)","termCode":"ssti","inLanguage":"es","url":"https://rootea.es/skills/ssti","inDefinedTermSet":{"@type":"DefinedTermSet","name":"Glosario táctico de pentesting","url":"https://rootea.es/glosario"}}`}
</script>

<script type="application/ld+json">
  {`{"@context":"https://schema.org","@type":"ItemList","name":"Máquinas HTB que practican SSTI (Server-Side Template Injection)","numberOfItems":12,"itemListElement":[{"@type":"ListItem","position":1,"url":"https://rootea.es/htb/machines/windows/insano/anubis","name":"Anubis"},{"@type":"ListItem","position":2,"url":"https://rootea.es/htb/machines/linux/medio/bolt","name":"Bolt"},{"@type":"ListItem","position":3,"url":"https://rootea.es/htb/machines/linux/medio/catch","name":"Catch"},{"@type":"ListItem","position":4,"url":"https://rootea.es/htb/machines/linux/facil/doctor","name":"Doctor"},{"@type":"ListItem","position":5,"url":"https://rootea.es/htb/machines/linux/medio/epsilon","name":"Epsilon"},{"@type":"ListItem","position":6,"url":"https://rootea.es/htb/machines/linux/medio/flustered","name":"Flustered"},{"@type":"ListItem","position":7,"url":"https://rootea.es/htb/machines/linux/facil/goodgames","name":"GoodGames"},{"@type":"ListItem","position":8,"url":"https://rootea.es/htb/machines/windows/dificil/hancliffe","name":"Hancliffe"},{"@type":"ListItem","position":9,"url":"https://rootea.es/htb/machines/linux/facil/late","name":"Late"},{"@type":"ListItem","position":10,"url":"https://rootea.es/htb/machines/linux/medio/noter","name":"Noter"},{"@type":"ListItem","position":11,"url":"https://rootea.es/htb/machines/linux/facil/nunchucks","name":"NunChucks"},{"@type":"ListItem","position":12,"url":"https://rootea.es/htb/machines/linux/dificil/oz","name":"Oz"}]}`}
</script>

*Última actualización: 2026-06-07*
