Saturday, June 7, 2014

Web Pen Test Terminology



Terminologies that seem to be always asked during interviews.  But the problem is that my memory  operates in a first in first out (FIFO) sort of way.  Which befits the definition; a method that relates to the organization and manipulation of data according to time and prioritization.  

Without further to do, the terminologies as I understand them:

Cross-Site Request Forgery (XSRF or CSRF) 

Def 

When the credentials used to access the targeted systems is sent from another application or system

Layman 

The same login can be used by another application can be used to login by another application

Example

  • Reusing the session token or cookie to login in as the current user from a different system/application
  • The login of the application can be used to login into Facebook, and Facebook uses the same login

Cause

The GET method is allowed to perform other operations besides the retrieval of data

Fix 

Unique and random session token for each GET request

How to test 

Cross-Site Tracing (XST) aka TRACE method 

Def 

Basically echoes back the http data

Example

Retrieval of the target's cookies which contain either the authentication credentials or the means to bypass access controls

Cause 

The TRACE method is enabled on the production system

Based on RFC 2616 which allows the GET method to conditionally retrieve information

Fix 

Turn off HTTP TRACE support

If your using apache then you need to install the mod_rewrite engine. Add the following lines to your httpd.conf file.

RewriteEngine On
RewriteCond %{REQUEST_METHOD} ^TRACE
RewriteRule .* - [F]

If your using IIS then you need to filter out everything but GET, POST, and HEAD with urlScan

How to test 

Open Burp and choose repeater. Change the request to something similar to:

TRACE / HTTP/1.0
Header1: <script>alert(document.cookie);</script>

The reply should look like this if TRACE is enabled:

HTTP/1.1 200 OK
Date: Sun, 23 Sep 2007 02:48:05 GMT
Server: Apache/1.3.34 (Ubuntu) mod_perl/1.29
Connection: close
Content-Type: message/http

TRACE / HTTP/1.0
Header1: <script>alert(document.cookie);</script>

SOAP 

Simple Object Access Protocol (SOAP) standard an XML language defining a message architecture and message formats, is used by Web services it contain a description of the operations. WSDL is an XML-based language for describing Web services and how to access them. will run on SMTP,HTTP,FTP etc. 
  • Requires middleware support
  • Returns XML based data

REST 

REST Representational State Transfer (RESTful) web services. they are second generation Web Services. RESTful web services, communicate via HTTP and do not require XML messages or WSDL service-API definitions. 

  • REST no middleware is required
  • REST can return XML, plain text, JSON, HTML, etc.

Sunday, May 4, 2014

Perl Tid Bits

Dynamic Array

This will dynamically create a table with unlimited number of rows and definable columns across

#!/bin/perl
my $limit = 0;
my $max = scalar(@array)+1;

my $i = 0;
my $j = 0;
my $k = $limit;

do {
@{"$i"} = @array[$j..$k];

  foreach $line (@{"$i"}) {
    print "$line\n" unless $seen{$line}++;
  }

$j = (($i * $limit) +$i);
$k = ($j + $limit);
$i++;

} until ( "$i" eq "$max" );

Difference | intersection | union of two Arrays

Reference: Perl Cookbook 2nd Edition, Page 128 -130, Section 4.9 - Indirect solution

#!/bin/perl
# Read in the entire directory into the first array
opendir(DIR, "$path") || "Can't open: $!\n";
@fArray=grep(!/^\.\.?$/, sort {-M $b <=> -M $a} readdir(DIR));
closedir(DIR );

# the first array
# create an array with specific files of interest
foreach $pattern(@fArray){
if($pattern =~ /^n[0-9]*\.tmp/) {
$pattern =~ s/n//;
$pattern =~ s/\.tmp//g;
push(@nArray,$pattern);
}
}

# the second array
my @sArray = ($start .. $stop);

# clear the arrays and hash
@union = @intersection = @difference = ();
%count = ();

# create an hash of all the elements in both arrays
foreach $element (@sArray, @nArray) { $count{$element}++ }

# cycle through each element in the hash
foreach $element (keys %count) {
        # create an array with elements of both arrays
push @union, $element;
        # create an array with unique element that are in both arrays (intersection)
        # create an array with elements that in the FIRST array (difference)
push @{ $count{$element} > 1 ? \@intersection : \@difference }, $element;
}

# sort the array numerically
@difference = sort {$a <=> $b} (@difference);

Difference between two arrays

Reference: Perl Cookbook 2nd Edition, Page 126 -128, Section 4.8 - Loopless version

#!/bin/perl
opendir(DIR, "$path") || "Can't open: $!\n";
@fArray=grep(!/^\.\.?$/, sort {-M $b <=> -M $a} readdir(DIR));
closedir(DIR );

foreach $pattern(@fArray){
if($pattern =~ /^n[0-9]*\.tmp/) {
$pattern =~ s/n//;
$pattern =~ s/\.tmp//g;
push(@nArray,$pattern);
}
}

my @sArray = ($start .. $stop);

my %seen;
my @notseen;

# create a hash with the keys set to the elements of @sArray
@seen{@sArray} = ();

# remove any element from the hash %seen with any element that matches in @nArray 
delete @seen{@nArray};

# create an array with elements not found in @nArray
my @notseen = keys %seen;

Regular Expression

Email Address

#!/bin/perl
if($line !~ /[@][a-z0-9A-Z]*\.[a-z0-9A-Z]/) {

Copyrights

#!/bin/perl
if($line !~ m/(copyright +(©|\(c\)|©) +\d{4})( *[-,] *\d{4})*/) {

Perl function equivalent of PHP's AddSlashes()

Here is a perl equivalent of PHP's AddSlashes() function. It's a quick an dirty way to clean up text to insert into a database. There are better ways to do this. It should exactly mimic PHP's function. It adds slashes before single quotes('), double-quotes(”), backslashes(\), and NULL bytes (\0).

#!/bin/perl
sub AddSlashes {
    $text = shift;
    ## Make sure to do the backslash first!
    $text =~ s/\\/\\\\/g;
    $text =~ s/'/\\'/g;
    $text =~ s/"/\\"/g;
    $text =~ s/\0/\\\0/g;
    return $text;
}

Installed modules

Find all installed modules

perl -MCPAN -e 'print CPAN::Shell->r '

Saturday, March 15, 2014

PWN Win7+ w/o admin or tools

Want to look like an awesome hacker type. Okay, maybe more like you know a trick or two, but its still cool for demonstration purposes. Remember this is for educational purposes only.

This type of "attack" requires that you have physical access to the target computer.

  1. Restart the targeted computer
  2. At Splash screen kill the power
  3. Turn the computer back on
  4. Click on the Launch Repair
  5. At prompt to restore click on CANCEL
  6. When prompt to send click on “View problem details”
  7. Scroll to the bottom
  8. Click on the link at the
  9. Notepad should come up
  10. Goto File > Open > Computer > Local Disk (C:)
  11. Change file type to all files
  12. Goto Windows > System32
  13. Rename file called Sethc to Sethc.org
  14. Copy cmd.exe, scroll to the bottom of the screen, click on a blank spot, right-click and paste it
  15. Rename “cmd.exe copy” to Sethc
  16. Click Cancel
  17. Click “Don't send”
  18. You should now be back in the login screen
  19. Click on Shift x5
  20. A terminal should now come up
  21. Recon for an user name by typing in: net users
  22. Provide a new password for the targeted user name - net user <NAME> <PASSWD>
  23. If successful close the terminal, otherwise try again or another user
  24. Attempt to login as the user you change the password for
  25. You should now be successfully logged as the use