Target Source / Input Vectors
Directives:
Total SSI Tags 4
Critical (RCE) 1
High (File Read) 1
Risk Posture VULN

Stripped and neutralized markup preventing SSI evaluation on Apache, Nginx, and IIS engines.

<!-- Loading sanitized output... -->
Copied to clipboard successfully!

1. Web Server Hardening

Disable Server-Side Includes globally or disallow the #exec directive in Apache/Nginx virtual hosts:

# Apache HTTP Server (httpd.conf or .htaccess)
# Disable SSI execution entirely:
Options -Includes

# OR allow file inclusions but strictly forbid execution of shell commands:
Options +IncludesNOEXEC

# -------------------------------------------------------------
# Nginx (nginx.conf)
# SSI is disabled by default in Nginx unless explicitly turned on.
ssi off;

# If SSI is required for legacy fragments, ensure ssi_silent_errors is off
# and never pass untrusted client parameters into SSI buffers:
ssi_types text/html;

2. ModSecurity WAF Rule (CRS Pattern)

# OWASP ModSecurity Core Rule Set pattern for SSI Injection
SecRule REQUEST_COOKIES|REQUEST_COOKIES_NAMES|REQUEST_FILENAME|ARGS_NAMES|ARGS|XML:/* "@rx <!--\s*#(?:include|exec|echo|config|printenv)\b" \
    "id:942510,\
    phase:2,\
    block,\
    capture,\
    t:none,t:urlDecodeUni,t:normalizePath,t:lowercase,\
    msg:'Server-Side Includes (SSI) Injection Attack Detected',\
    logdata:'Matched Data: %{TX.0} found within %{MATCHED_VAR_NAME}',\
    tag:'application-multi',\
    tag:'language-multi',\
    tag:'platform-multi',\
    tag:'attack-ssi-injection',\
    severity:'CRITICAL'"

SSI Injection Auditing and AST Sanitization

Read the explanation

Web servers parsing server side includes evaluate syntax disguised inside standard markup comments. The inspector scans raw template strings across regular expression boundaries to isolate active directives. Directives are categorized by threat impact. Command execution directives trigger critical status, file inclusion vectors receive high risk classification, and canary probe strings register as reconnaissance markers. Selecting sanitize replaces active instructions with neutralized escape tokens. Upstream web servers will not interpret the modified comments, preventing unauthorized command execution and file disclosure.

Enjoy this tool? Build your own with Super