<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/">
  <channel>
    <title>Application Security on Raghunath Gopinath</title>
    <link>https://raghu.io/categories/application-security/</link>
    <description>Recent content in Application Security on Raghunath Gopinath</description>
    <generator>Hugo</generator>
    <language>en</language>
    <lastBuildDate>Thu, 30 Apr 2026 20:36:05 +0530</lastBuildDate>
    <atom:link href="https://raghu.io/categories/application-security/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>How to Install and Configure Shield Security: Step-by-step guide</title>
      <link>https://raghu.io/how-to-install-and-configure-shield-security-step-by-step-guide/</link>
      <pubDate>Tue, 07 May 2024 05:15:32 +0000</pubDate>
      <guid>https://raghu.io/how-to-install-and-configure-shield-security-step-by-step-guide/</guid>
      <description>This step-by-step guide on how to install and configure the Shield Security plugin will enable the standard recommended security settings for your WordPress website quickly and keep it safe from potential threats.</description>
      <content:encoded><![CDATA[<p>Looking to improve the security of your WordPress website? This
step-by-step guide will walk you through how to install the Shield
Security security plugin for WordPress. One of the tools to secure your
WordPress site from potential threats.</p>
<h2 id="what-is-shield-security">What is Shield Security?</h2>
<p>Shield Security is an Intrusion Detection and Prevention security plugin
for WordPress that helps secure your website from malicious traffic. It
has malicious traffic monitoring capability, Blocks spam bots and
content, Disable anonymous REST API access, 2FA support, and many other
features designed to keep your website safe and secure.</p>
<h3 id="key-features-and-benefits">Key features and benefits</h3>
<ul>
<li><strong>Automatic IP Blocking</strong>: The website owner can check and set the
offence count in the settings. After reaching the count, the website
will automatically block all malicious traffic</li>
<li><strong>Site Traffic Monitoring</strong>: Continuously monitor all site activity
and get security insights into your WordPress website in real time.</li>
<li><strong>Malware Scanner</strong>: The plugin scans your website for known malware
and helps keep your website free from viruses. (pro feature)</li>
<li><strong>Brute Force and Spam Protection</strong>: SecureShield helps protect your
website from brute force attacks by rate-limiting attempts and
enforcing strong protection.</li>
<li><strong>Two-Factor Authentication</strong>: The plugin also offers two-factor
authentication, an extra layer of security for admin user accounts.</li>
</ul>
<p>You can learn more about the complete features of
<a href="https://getshieldsecurity.com/features/">ShieldSecurity</a>
on their website.</p>
<h2 id="pre-installation-steps">Pre-Installation Steps</h2>
<p>Before installing the ShieldSecurity WordPress plugin, taking a few
pre-installation steps is important to ensure a smooth and safe process.</p>
<p>In this article, we will focus only on the free version of
ShieldSecurity.</p>
<h3 id="backup-your-wordpress-website">Backup your WordPress website</h3>
<p>It&rsquo;s always a good practice to create a backup of your WordPress website
before installing any new plugins. This ensures that you can restore
your website to its previous state in case anything goes wrong during
installation.</p>
<h3 id="update-wordpress-and-all-plugins">Update WordPress and all plugins</h3>
<p>Ensure your WordPress core installation and all other plugins are up to
date. Running the latest versions of WordPress and plugins helps ensure
compatibility and security.</p>
<h2 id="installing-shield-security-plugin">Installing Shield Security Plugin</h2>
<p>Log into your WordPress admin account, navigate to &ldquo;<strong>Plugins</strong>&rdquo; -&gt;
&ldquo;<strong>Add Plugins</strong>&rdquo;, and search for &ldquo;<strong>Shield Security</strong>&rdquo;.</p>
<figure class="mx-auto block text-center">
    <img loading="lazy" src="Search-Install-Shield-Security-WordPress-Plugin.webp"
         alt="Figure 1: Install Shield Security Plugin"/> <figcaption>
            <p>Figure 1: Install Shield Security Plugin</p>
        </figcaption>
</figure>

<p>Once you find the &ldquo;<strong>Shield Security</strong>&rdquo; plugin, click the &ldquo;<strong>Install
Now</strong>&rdquo; button.</p>
<figure class="mx-auto block text-center">
    <img loading="lazy" src="Shield-Security-Activate.webp"
         alt="Figure 2: Activate Shield Security WordPress Plugin"/> <figcaption>
            <p>Figure 2: Activate Shield Security WordPress Plugin</p>
        </figcaption>
</figure>

<p>After installation, click the &ldquo;<strong>Activate</strong>&rdquo; button to enable the
plugin.</p>
<h2 id="configure-shield-security">Configure Shield Security</h2>
<p>A plugin configuration wizard is loaded, which will quickly help you
navigate and set up the required features.</p>
<figure class="mx-auto block text-center">
    <img loading="lazy" src="Shield-Security-Getting-Started.webp"
         alt="Figure 3: Shield Security - Getting Started"/> <figcaption>
            <p>Figure 3: Shield Security - Getting Started</p>
        </figcaption>
</figure>

<ol>
<li>A Shield Security menu will be displayed. Using the WordPress
dashboard, you can Navigate to the Shield Security Plugin.</li>
<li>A Dedicated menu to manage all &ldquo;Shield Security&rdquo; plugin features.</li>
<li>Click on the &ldquo;Next Step&rdquo; to go ahead and quickly enable the security
features needed.</li>
</ol>
<blockquote>
<p><strong>Warning:</strong> Note the setup wizard options may change</p>
</blockquote>
<h3 id="subscribing-to-newsletter">Subscribing to Newsletter</h3>
<p>The first step involves subscribing to a newsletter. You can sign up or
click on &ldquo;Next Step.&rdquo;</p>
<h3 id="activate-license">Activate License:</h3>
<figure class="mx-auto block text-center">
    <img loading="lazy" src="Shield-Security-Activate-License.webp"
         alt="Figure 4: Activate Your License"/> <figcaption>
            <p>Figure 4: Activate Your License</p>
        </figcaption>
</figure>

<p>The next step prompts activating the &ldquo;ShieldPRO&rdquo; license. As this
article only focuses on the free version, I will skip it and click
&ldquo;<strong>Next Step</strong>.&rdquo;</p>
<h3 id="choose-a-initial-security-profile">Choose a Initial Security Profile</h3>
<p>If you&rsquo;re a first-time user or just want a quick setup, the &ldquo;Shield
Security&rdquo; plugin provides multiple profiles to choose from.</p>
<figure class="mx-auto block text-center">
    <img loading="lazy" src="Shield-Security-Profile-Choose.webp"
         alt="Figure 5: Choose a Shield Security Profile"/> <figcaption>
            <p>Figure 5: Choose a Shield Security Profile</p>
        </figcaption>
</figure>

<p>I recommend reviewing the options that each profile enables or disables
before you select one. It&rsquo;s often best to get started with the
&ldquo;<strong>Light</strong>&rdquo; or &ldquo;<strong>Medium</strong>&rdquo; profile, as you can change this setting at
any time.</p>
<p>Sometimes, stricter security features can conflict with or &ldquo;break&rdquo; other
functionality on your site. Therefore, it&rsquo;s safer to start with the
&ldquo;Light&rdquo; or &ldquo;Medium&rdquo; profile, test your site to ensure everything works,
and then move toward implementing a more robust security profile.</p>
<h3 id="setting-up-shield-admin-pin">Setting up Shield Admin PIN</h3>
<figure class="mx-auto block text-center">
    <img loading="lazy" src="Shield-Security-Admin-Pin.webp"
         alt="Figure 6: Setup Admin PIN"/> <figcaption>
            <p>Figure 6: Setup Admin PIN</p>
        </figcaption>
</figure>

<p>The application displays the form to set up a plugin PIN in the
&ldquo;Security Admin&rdquo; section. This would be an added layer of protection for
admins, ensuring only the authorized person can access or modify the
security setting.</p>
<p>Key in the PIN, Confirm the PIN, and click on &ldquo;<strong>Turn On Security
Admin</strong>.&rdquo; A message stating that the PIN has been successfully set will
be displayed, and you will be taken to Bot Settings.</p>
<h3 id="bot-blocking">Bot Blocking</h3>
<figure class="mx-auto block text-center">
    <img loading="lazy" src="Secure-Shield-Bot-Blocking.webp"
         alt="Figure 7: Bot Blocking Wizard"/> <figcaption>
            <p>Figure 7: Bot Blocking Wizard</p>
        </figcaption>
</figure>

<p>The next setting is about how to handle the Bots and Malicious traffic.
Identifying the malicious traffic patterns and bad bot behaviour ruleset
is already taken care of by the plugin vendor.</p>
<p>As a website owner, based on your site traffic and user patterns, decide
after how many offences you would like to block the IP. The default
offence limit is 10. I have set the offence limit to 5 for strict
security and the Block duration to 1 week.</p>
<p>To activate it, click on &ldquo;<strong>Set IP Blocking Options</strong>&rdquo;. After 5
malicious attempts, the IP address will be blocked for 1 Week.</p>
<p>The Whitelist option is also available, where admins&rsquo; and security
researchers&rsquo; IPs can be whitelisted as needed.</p>
<p>The option &ldquo;<strong>Use CrowdSec Blocklists</strong>&rdquo; is also an added benefit.</p>
<p>If an attacker&rsquo;s IP is flagged on your site for offences, it is shared
with CrowdSec, and similarly, other websites&rsquo; flagged IP addresses are
shared with your site. This helps to block malicious attempts at early
stages proactively.</p>
<h3 id="brute-force-login-protection">Brute Force Login Protection</h3>
<figure class="mx-auto block text-center">
    <img loading="lazy" src="Secure-Shield-Login-Attacks.webp"
         alt="Figure 8: Brute Force Login Protection"/> <figcaption>
            <p>Figure 8: Brute Force Login Protection</p>
        </figcaption>
</figure>

<p>One of the most common attacks on a WordPress website is the automated
Brute Force attack. The attacker tries to find the valid credentials
that match a known user name or by blindly trying with a huge list of
usernames and passwords. This happens continuously each and every day.</p>
<p>Shield Security Brute Force Login Protection will detect automated
attacks and block them from exploitation.</p>
<p>Make sure to &ldquo;<strong>Turn On - Protect my WordPress login from automated
attacks</strong>&rdquo;, click on &ldquo;Set Login Protection&rdquo;.</p>
<blockquote>
<p>Sometimes, the admin may not be able to log in. Don&rsquo;t forget to
whitelist the admin IP address.</p>
</blockquote>
<h3 id="block-spam-comments">Block Spam Comments</h3>
<figure class="mx-auto block text-center">
    <img loading="lazy" src="Shield-Security-Comments-Spam.webp"
         alt="Figure 9: Block Spam Comments"/> <figcaption>
            <p>Figure 9: Block Spam Comments</p>
        </figcaption>
</figure>

<p>Spam comments are another common problem among WordPress sites. The free
version also covers this.</p>
<p>Please check on &ldquo;<strong>Turn On - Block automated SPAM comments</strong>&rdquo; and click
on &ldquo;<strong>Set Comment SPAM Protection</strong>&rdquo; to enable.</p>
<p>Click &ldquo;<strong>Go to Shield Overview</strong>&rdquo; on the final thank you page.</p>
<h3 id="shield-security-dashboard">Shield Security Dashboard</h3>
<figure class="mx-auto block text-center">
    <img loading="lazy" src="Shield-Security-Dashboard.webp"
         alt="Figure 10: Shield Security Dashboard"/> <figcaption>
            <p>Figure 10: Shield Security Dashboard</p>
        </figcaption>
</figure>

<p>The &ldquo;<strong>Security Overview</strong>&rdquo; dashboard is a place where you can see all
the info about security happenings on your site.</p>
<p>The top graph displays total number of Login Blocks, Bot Detection,
Offenses, Connection Killed, IP Blocked etc in past 7 days. Additionally
the security summary of our website.</p>
<p>One of the major reason I found to useful about this plugin compared to
WordFence is for real-time threat protection and less memory usage
compared to it.</p>
<h3 id="enable-auto-updates">Enable Auto Updates</h3>
<p>Just make sure to enable the &ldquo;<strong>auto-updates</strong>&rdquo; for Shield Security
plugin, so you don&rsquo;t need to update every time manually. I have been
using it for more than couple of years and haven&rsquo;t see any breakages so
far.</p>
<p>I hope the above information helps secure your site. The above
configuration can quickly help to secure your WordPress site from good
number of attacks. In future articles will be posting about the detailed
hardening steps using Shield Security plugin soon.</p>
<h3 id="shield-security-help">Shield Security Help</h3>
<p>Check out the <a href="https://getshieldsecurity.com/getting-started-guide/">Shield Security -Getting Started
Guide</a>
for more help information.</p>
<h2 id="conclusion">Conclusion</h2>
<p>Securing the WordPress website is an important factor for website
owners. With the increasing attacks on WordPress, proactive measures
like this help secure your online assets.</p>
<p>Secure Shield is a free, real-time WordPress security plugin that
enhances your website&rsquo;s security. It provides many features, such as
blocking malicious comments, bots, attackers, firewall protection, and
Two-Factor Authentication.</p>
<p>Don&rsquo;t wait until it&rsquo;s too late; enable it now to reduce security
attacks.</p>
]]></content:encoded>
    </item>
    <item>
      <title>Security Threats of Nulled WordPress Plugins and Themes: Uncovering the Hidden Dangers</title>
      <link>https://raghu.io/security-threats-of-nulled-wordpress-plugins-and-themes-uncovering-the-hidden-dangers/</link>
      <pubDate>Fri, 12 Apr 2024 04:23:30 +0000</pubDate>
      <guid>https://raghu.io/security-threats-of-nulled-wordpress-plugins-and-themes-uncovering-the-hidden-dangers/</guid>
      <description>Discover the security threats behind seemingly harmless, nulled WordPress plugins and themes. Learn about hidden dangers that can compromise your website&amp;#39;s security and steps to secure your site.</description>
      <content:encoded><![CDATA[<p>In today&rsquo;s digital world, WordPress is one of the most widely used
Content Management Systems (CMS) for quickly creating websites or blogs.
WordPress powers more than 10 million websites across the internet. One
of the core reasons behind its popularity is the availability of
numerous plugins that extend its functionality and make it
user-friendly.</p>
<p>Below are statistics on security vulnerabilities based on WordPress
components by
<a href="https://wpscan.com/statistics/?ref=raghu.io">wpscan</a>.</p>
<figure class="mx-auto block text-center">
    <img loading="lazy" src="Wordpress-Vulnerable-Components-Statistics.png"
         alt="Figure 1: WordPress Vulnerable Components Source: WPScan"/> <figcaption>
            <p>Figure 1: WordPress Vulnerable Components Source: WPScan</p>
        </figcaption>
</figure>

<p>From the above screenshot, we can see that <strong>94%</strong> of Vulnerabilities
are found in WordPress plugins. Using nulled plugins is one among them.
Nulled WordPress plugins/themes can expose your website to significant
security risks and vulnerabilities.</p>
<p>This article will provide a comprehensive understanding of what nulled
plugins and themes are, their security risks, the alternatives, when you
can use them, etc.</p>
<h2 id="-what-are-nulled-plugins-and-nulled-themes">📖 What are Nulled Plugins and Nulled Themes?</h2>
<p>A Nulled plugin is a modified version of open-source or premium
WordPress plugins distributed for free or at a negligible cost over the
Internet through unofficial channels that anyone can download and use.</p>
<blockquote>
<p>Security threats apply to both WordPress plugins and themes.</p>
</blockquote>
<p>For premium plugins, the original code is altered, and all license
limitations will be nullified, so you can freely use all the premium
capabilities without paying any extra money.</p>
<p>In the case of open-source plugins, additional features not part of the
official plugin are added to attract users to download and use.</p>
<h2 id="-why-are-nulled-pluginsthemes-so-attractive">🧲 Why are nulled plugins/themes so attractive?</h2>
<p>The WordPress ecosystem is a huge market, and you might need to decide
which plugin suits your requirements. Most free plugins are good for
getting started, but as you progress, you might see limitations and
require additional features.</p>
<p>The above requirements might make you consider premium plugins an
option. But again, you might need to get a premium plugin for a theme, a
premium plugin for forms, etc., as the requirements keep going.</p>
<p>Considering the Hosting, Plugins, Themes, Development, Official Support,
etc. It might look expensive, and as humans, we normally look for ways
to cut costs or get discounts.</p>
<h3 id="cost-effective">Cost Effective:</h3>
<p>Nulled plugins sound like a good deal for small website owners who want
to <strong>get their site up and running without spending a lot of money</strong>.</p>
<h3 id="selected-features">Selected Features</h3>
<ul>
<li>Users might <strong>need only a few essential features</strong> rather than paying
for all options.</li>
</ul>
<h3 id="one-subscription---access-to-many-premium-plugins">One Subscription - Access to Many Premium Plugins</h3>
<ul>
<li>There are a few unofficial sources on the internet, where you can
<strong>pay once and access multiple premium nulled plugins</strong> without paying
individually for each plugin.</li>
</ul>
<h3 id="challenging-experiences">Challenging Experiences</h3>
<ul>
<li>Users might have faced <strong>frustrating experiences</strong> with unresponsive
support.</li>
<li><strong>Issues due to account lockouts</strong> or inability to register valid user
accounts.</li>
<li>License <strong>activation problems, payment-related issues</strong>, etc.</li>
</ul>
<h3 id="assumed-time-saving">Assumed Time Saving</h3>
<ul>
<li>Used might believe it can cut the development efforts and build the
website faster.</li>
</ul>
<p>Overall, Nulled plugins might seem like a good deal for free, but
remember they may contain malware, a backdoor or other security
vulnerabilities bundled inside them, which can harm your website with
various security threats.</p>
<h2 id="-security-threats-associated-with-nulled-plugins">🔓 Security Threats Associated with Nulled Plugins</h2>
<p>In this section will dig further and understand the security risks
associated with the nulled plugins:</p>
<h3 id="outdated-security-patches">Outdated Security Patches</h3>
<p>Official plugin developers patch security loopholes when they receive
them. <strong>You will miss the patching updates</strong>. Missing security patches
can leave your website unprotected, and attackers use this opportunity
to compromise the site with known security vulnerabilities.</p>
<h3 id="malicious-code-injection">Malicious Code Injection</h3>
<p>One of the major threats associated with nulled WordPress plugins or
themes is the possibility of injecting malware inside the code.</p>
<ul>
<li><strong><a href="https://en.wikipedia.org/wiki/Backdoor_%28computing%29?ref=raghu.io">Backdoor
Access</a></strong>:
The malicious code is injected and can silently provide access to your
website for attackers. Attackers can use it to execute Remote Code
Execution (RCE) and completely control your website.</li>
</ul>
<blockquote>
<p>The single most common type of backdoor belonged to a PHP backdoor
uploader found on 8.68% of remediated websites, while the most
persistent backdoor (removed from more than 180,000 files last year)
was WordPress specific and concealed within nulled themes. Its ability
to self-replicate once it has established a footprint and layers of
obfuscation makes it especially challenging to pinpoint and remove.</p>
<p><a href="https://www.sucuri.net/reports/2022-hacked-website-report/?ref=raghu.io">From Sucuri - Hacked Website
Report</a></p>
</blockquote>
<ul>
<li><strong>Open Redirection Attack (Redirection Hack)</strong>: Whenever users visit
your website, the injected code redirects them to a malicious website,
with or without clicking any link. This is called an open-redirection
attack.</li>
<li><strong>Ransomware Attack</strong>: The malicious code injected inside the
application will encrypt all files on the server and/or database. To
regain access to those encrypted files, you must pay the attacker a
ransom to obtain the decryption key.</li>
<li><strong>Spread Virus</strong>: Infected sites can spread the virus as well, and
some advanced malware can even self-replicate and use your site as a
medium to compromise other systems.</li>
<li><strong>Denial of Service (DOS) Attacks</strong>: The infected website can be used
by attackers to launch a denial-of-service attack against other sites,
which can even lead to blacklisting or marking your domain as spam.
etc.</li>
</ul>
<h3 id="data-breach">Data Breach</h3>
<p>Another major issue with the nulled plugin is the theft of your website
data. An attacker might steal sensitive information such as usernames,
passwords, payment-related details (if you are using e-commerce), etc.</p>
<ul>
<li>Data Breaches can cost you a lot when you need to deal with <strong>legal
consequences</strong> and damages. This would also impact your business
reputation and trust.</li>
<li>Sometimes, it can also lead to <strong>privacy issues</strong>. <strong>Malware can
silently harvest your users</strong>&rsquo; data and sell it to third-party
vendors.</li>
</ul>
<h2 id="️-case-study-criyasoft">🛡️ Case Study - Criyasoft</h2>
<p>Criyasoft is one of the client&rsquo;s educational websites. It is used to
demonstrate the functionalities development in WordPress and is always
kept online for students&rsquo; reference.</p>
<p>Recently, it became the victim of an open-redirection attack. After 4
levels of redirections, it will take genuine users to a casino website.</p>
<h3 id="what-is-the-impact">What is the Impact?</h3>
<p>The &ldquo;<strong>About</strong>&rdquo; page link is tampered with, and whenever a visitor
clicks it, it will redirected multiple times and take the user to a
casino website</p>
<figure class="mx-auto block text-center">
    <img loading="lazy" src="Taking-Web-Hosts.png"
         alt="Figure 2: A Blocked - First Level Redirection Attempt"/> <figcaption>
            <p>Figure 2: A Blocked - First Level Redirection Attempt</p>
        </figcaption>
</figure>

<h3 id="what-is-the-root-cause">What is the root cause?</h3>
<p>After analyzing the site, I found a couple of main reasons, which are
listed below.</p>
<p><strong>Outdated Plugins and Themes</strong> - Both plugins and themes are not
updated regularly.</p>
<p>During the initial analysis, I discovered that it was just an
ad-tracking link or that it was due to outdated plugins that have known
security vulnerabilities. Updated all the plugins and themes. Ensured
all was fixed, as it was no longer reproducible.</p>
<p>After a few days, the attack pattern started to repeat again, and once
it started impacting other page links, I realized it was some malicious
behaviour impacting navigating menu links.</p>
<p>After thoroughly evaluating each installed plugin and theme, I
discovered that the client installed one of the nulled plugins for quick
educational purposes instead of purchasing one that contained malicious
code.</p>
<p><strong>Novashare nulled plugin is used</strong> - A nulled WordPress social share
plugin is being used.</p>
<p>After cleaning up the nulled plugin files, the site is back to normal,
with continuous security monitoring enabled to prevent further attacks.</p>
<h3 id="how-was-it-fixed">How was it fixed?</h3>
<p>I scanned it with malware-scanning plugins to find the root cause. (Used
Malcare)</p>
<figure class="mx-auto block text-center">
    <img loading="lazy" src="Site-Hacked.png"
         alt="Figure 3: Use Malcare"/> <figcaption>
            <p>Figure 3: Use Malcare</p>
        </figcaption>
</figure>

<p>Post confirmation removed the Novoshare nulled plugin completely,
deleted all its files and updated all the themes and plugins. Additional
enabled &ldquo;<strong>auto-updates</strong>&rdquo; for all non-customized plugins and themes.</p>
<p>Lastly, I configured the free
&ldquo;<a href="https://getshieldsecurity.com/">ShieldSecurity</a>&rdquo;
plugin to monitor real-time security alerts and prevent them from
further impacting the website.</p>
<h2 id="-additional-reasons-to-avoid-nulled-plugins">⛔ Additional Reasons to Avoid Nulled Plugins?</h2>
<p>Below are some additional trust concerns you might consider before using
any of the nulled plugins. We don&rsquo;t know what is inside the code, and we
need to be prepared for any unexpected behaviours that can cause the
site to crash or impact its availability.</p>
<h3 id="flagged-by-search-engines---google">Flagged by Search Engines - Google</h3>
<p>If Google finds any malicious behaviour on your website, an additional
flag is displayed below your domain with the message &ldquo;<strong>This site may be
hacked.</strong>&rdquo; This indicates that users should avoid visiting the Website
as malicious activity has been spotted.</p>
<figure class="mx-auto block text-center">
    <img loading="lazy" src="hacked-example.png"
         alt="Figure 4: Google-Flagging Suspicious Website"/> <figcaption>
            <p>Figure 4: Google-Flagging Suspicious Website</p>
        </figcaption>
</figure>

<p>If you believe you are a victim, check out <a href="https://web.dev/articles/how-do-i-know-if-my-site-was-hacked">Google&rsquo;s hacked site
guide</a>
for fixing.</p>
<h3 id="recovering-from-nulled-wordpress-plugin-damage">Recovering from Nulled WordPress Plugin Damage</h3>
<p>Restoring your website after discovering it is hacked or causing
unexpected behaviour is more time-consuming.</p>
<ul>
<li>
<p><strong>Restore Backup</strong>: Maintaining regular backups can help you quickly
restore the existing snapshots by identifying the impacted behaviour
early.</p>
</li>
<li>
<p><strong>Scanning for Malware or Seeking Professional Assistance</strong>: For
hacked websites, it&rsquo;s possible to mitigate the damage and regain
control. You need to set up malware scanning solutions to identify
infected files like &ldquo;Sucuri&rdquo;, &ldquo;WordFence&rdquo;, &ldquo;Malcare&rdquo;, etc.
Additionally, don&rsquo;t hesitate to seek professional assistance if
required.</p>
</li>
<li>
<p><strong>Time-Consuming</strong>: As mentioned earlier, using nulled WordPress
plugins or themes might seem time-saving, but damage control requires
a lot more time and resources to restore the website to normal.</p>
<blockquote>
<p>⚠️Remember, official authors or vendors don&rsquo;t support nulled
plugins. Even if they would like to offer, they might have limited
knowledge.</p>
</blockquote>
</li>
</ul>
<p>I hope the above information can help you to decide and take respective
action with respective to Nulled WordPress plugins or themes.</p>
<h2 id="-best-place-for-plugins-and-themes">👍 Best place for Plugins and Themes</h2>
<p>Finding safe and reliable WordPress plugins is easy. There are many free
and paid premium options for securely accessing your website.</p>
<ul>
<li><a href="https://wordpress.org/plugins/?ref=raghu.io">WordPress
Plugins</a> - All
WordPress Plugins Directory</li>
</ul>
<figure class="mx-auto block text-center">
    <img loading="lazy" src="WordPress-Themes.png"
         alt="Figure 5: WordPress Plugins Directory"/> <figcaption>
            <p>Figure 5: WordPress Plugins Directory</p>
        </figcaption>
</figure>

<ul>
<li><a href="https://wordpress.org/themes/?ref=raghu.io">WordPress
Themes</a> - All
WordPress Themes Directory</li>
</ul>
<figure>
    <img loading="lazy" src="WordPress-Themes.png"/> 
</figure>

<h3 id="additional-tips">Additional Tips</h3>
<ul>
<li>For each WordPress plugin or theme, check their reviews or visit its
home page, and ensure you are purchasing only from official authors'
sites.</li>
</ul>
<figure class="mx-auto block text-center">
    <img loading="lazy" src="Plugin-Home-Page.png"
         alt="Figure 6: Theme Home Page and Reviews"/> <figcaption>
            <p>Figure 6: Theme Home Page and Reviews</p>
        </figcaption>
</figure>

<ul>
<li><a href="https://elements.envato.com/wordpress?ref=raghu.io">EnvatoElements</a> -
Another common place where you can find WordPlugins and Themes.</li>
</ul>
<h2 id="-still-using-nulled-plugins">🤔 Still Using Nulled Plugins?</h2>
<p>If you use nulled plugins on production websites, the transition steps
below will be helpful, as they can still pose security risks.</p>
<p><strong>Scan for known Vulnerabilities or Malware</strong></p>
<p>Antivirus and antimalware companies work around the clock to find new
malware behaviours and patterns and update their signatures database.</p>
<p>You can leverage the free online malware scans such as
&ldquo;<a href="https://sitecheck.sucuri.net/?ref=raghu.io">Sucuri</a>&rdquo;,&quot;<a href="https://www.wordfence.com/?ref=raghu.io">WordFence</a>&quot;,
&ldquo;<a href="https://www.malcare.com/features/malware-scanner/?ref=raghu.io">Malcare</a>&rdquo;,
&ldquo;<a href="https://www.virustotal.com/gui/home/upload?ref=raghu.io">VirusTotal</a>&rdquo;,
etc., to check the nulled plugins if it does do contain malware.</p>
<div class="highlight"><pre tabindex="0" class="chroma"><code class="language-bash" data-lang="bash"><span class="line"><span class="cl">You could also check out <span class="o">[[</span>./wordpress-scan-for-vulnerabilities-a-comprehensive-guide-for-site-security.org<span class="o">][</span>WordPress Scan <span class="k">for</span> Vulnerabilities a comprehensive guide <span class="k">for</span> site security<span class="o">]]</span> to learn more about scanning your WordPress site <span class="k">for</span> vulnerabilities.
</span></span></code></pre></div><blockquote>
<p>Once you are confident that no malicious patterns are found, proceed
with the next steps of the transition. If any are found, make sure to
clean up before proceeding.</p>
</blockquote>
<h3 id="transition-to-free-or-premium-plugins">Transition to Free or Premium Plugins:</h3>
<p>Transitioning away from nulled plugins is crucial for maintaining the
security and integrity of your WordPress site. The below steps can help
you ensure a smooth migration to premium or free plugins with minimal
disruption.</p>
<ul>
<li><strong>Backup Your Website</strong>: Ensure complete site backup is taken to
prevent potential data loss.</li>
<li>Test and Validate alternate plugins: Ensure all features and
functionalities work as intended with the new plugins.</li>
<li><strong>Remove Nulled Plugins</strong>: After successfully evaluating new plugins,
safely remove the nulled plugins from your website, eliminating any
potential security risks associated with their usage.</li>
<li><strong>Publish Changes</strong>: Push all the updated changes into the production
environment and ensure that all the functionalities are working as
expected.</li>
</ul>
<h2 id="-conclusion">📝 Conclusion</h2>
<p>The WordPress nulled plugins or themes might seem an attractive
alternative to paying for premium features, but it&rsquo;s critical to weigh
the security risks associated with their use. The potential harm they
can cause to your website security is more, including reputational
damage, a drop in your site rankings, a decrease in revenue, etc. Opting
for free or trial versions and ensuring all the plugins and themes are
up-to-date can minimize security threats.</p>
<h2 id="-faqs">🙋 FAQs</h2>
<h3 id="what-are-nulled-wordpress-plugins">What are nulled WordPress Plugins?</h3>
<p>A Nulled plugin is a modified version of open-source or premium
WordPress plugins distributed for free or at a negligible cost over the
Internet through unofficial channels that anyone can download and use.</p>
<h3 id="are-nulled-plugins-safe-to-use">Are nulled plugins safe to use?</h3>
<p>No, and It should never be installed in production environments.</p>
<h3 id="what-are-the-security-risks-associated-with-using-nulled-plugins">What are the security risks associated with using nulled plugins?</h3>
<p>It can be used as a medium for injecting and spreading malware and
exploiting your website with known security vulnerabilities. It may also
lead to data theft.</p>
<h3 id="how-can-i-avoid-using-nulled-plugins">How can I avoid using nulled plugins?</h3>
<p>Download and install plugins from reputed sources like the WordPress
plugin directory and trusted marketplaces.</p>
<h2 id="-additional-references">🔗 Additional References:</h2>
<ul>
<li><a href="https://kinsta.com/blog/nulled-wordpress-plugins-themes/?ref=raghu.io">Why You Should Stop Using Nulled WordPress Themes and
Plugins</a></li>
<li><a href="https://jetpack.com/blog/why-you-should-avoid-using-nulled-plugins-and-themes/?ref=raghu.io">Why you should avoid using Nulled WordPress themes and
plugins</a></li>
</ul>
]]></content:encoded>
    </item>
    <item>
      <title>Enhancing the Security of WordPress Sites: Best Practices and Tips</title>
      <link>https://raghu.io/enhancing-the-security-of-wordpress-sites-best-practices-and-tips/</link>
      <pubDate>Wed, 20 Mar 2024 15:30:01 +0000</pubDate>
      <guid>https://raghu.io/enhancing-the-security-of-wordpress-sites-best-practices-and-tips/</guid>
      <description>Discover the essential tips and best practices for enhancing the Security of WordPress Sites. Owners can analyze security risks, install recommended plugins, monitor continuously, and tweak configurations, which can help keep your sites safe from potential threats.</description>
      <content:encoded><![CDATA[<p>Discover the essential tips and best practices for enhancing the
Security of WordPress Sites. Owners can analyze security risks, install
recommended plugins, monitor continuously, and tweak configurations,
which can help keep your sites safe from potential threats.</p>
<p>The major focus of this article is to provide detailed and step-by-step
instructions to help website owners take action with easy-to-follow
steps. Even non-technical users would also be able to follow along and
secure your WordPress sites.</p>
<h2 id="understanding-the-importance-of-wordpress-security">Understanding the Importance of WordPress Security</h2>
<p>It is reasonable for users to think that WordPress&rsquo;s security must be
taken care of by the provider itself. Let&rsquo;s understand how the WordPress
ecosystem works.</p>
<h3 id="about-wordpress-software">About WordPress Software</h3>
<p>WordPress is a dynamic open-source content management system that is
freely available to anyone who wants to set up a publishing website.</p>
<p>The <a href="https://wordpress.org/about/security/">WordPress core</a> is
continuously hardened with all the vulnerabilities that have been
identified and reported as part of <a href="https://owasp.org/www-project-top-ten/">OWASP Top
10</a>. Also, the recommended
security best practices are provided for authors developing third-party
plugins and themes.</p>
<p>The WordPress Team&rsquo;s responsibility covers identifying and resolving the
security issues in the core software provided. It&rsquo;s a community project
that is used across 10 million websites on the internet. Any programmer
can create a third-party plugin or theme based on their needs.</p>
<figure class="mx-auto block text-center">
    <img loading="lazy" src="Wordpress-Plugins-Summary.png"
         alt="Figure 1: [[https://wordpress.org/about/security/][WordPress Security]]"/> <figcaption>
            <p>Figure 1: [[https://wordpress.org/about/security/][WordPress Security]]</p>
        </figcaption>
</figure>

<p>From above, even after providing the secure guidelines and getting the
code reviewed by volunteers, sometimes the security bugs can be missed,
or new bugs found need to be updated accordingly.</p>
<p>To proactively mitigate security vulnerabilities before attackers find
them, the WordPress Security team even runs the Bug Bounty program at
<a href="https://hackerone.com/wordpress?type=team">HackerOne</a> as an additional
measure to report any security vulnerabilities identified by security
researchers and make the platform more secure.</p>
<p>WordPress security teams even go beyond to remove the vulnerable plugin
from the directory if the plugin owner doesn&rsquo;t fix or fix it themself in
extreme cases.</p>
<p>Third-party plugins and themes are reviewed for security to a certain
extent. In addition to WordPress software, the security of the
underlying operating system used, configurations, database servers,
secure file transfers, TLS security, and web servers are also equally
important.</p>
<p>The WordPress team is actively working on mitigating security defects in
WordPress Core, Plugins, and Themes. However, the security of all
underlying technologies and ensuring all the updates are patched falls
under the Owner&rsquo;s responsibility.</p>
<p>If your hosting provider takes care of your underlying tech stack, it is
your responsibility to ensure the core, themes, and plugins are updated
and downloaded from recommended websites.</p>
<h3 id="about-managed-wordpress">About Managed WordPress</h3>
<p>When you come to Managed WordPress (i.e., wordpress.com), You just need
to register, pay according to your package preference, and start
publishing right away.</p>
<p>Managed WordPress uses the same WordPress Core Software. The underlying
technology, like setting up software and managing the web server and
other resources, is completely handled by the Automattic team.</p>
<p>Authors need to focus only on creating content for their niche.</p>
<h3 id="the-vital-need-for-security">The Vital Need for Security</h3>
<p>Based on the above choices, the security requirements do vary. A managed
service is the best option for most website owners and companies.
However, there are cases where the website owners require more
customizability or manage multiple websites. In those cases, the users
prefer the self-hosted version of WordPress.</p>
<p>Going forward, we will focus only on the security needs of self-hosted
WordPress websites. We will set up a WordPress site and start securing
it step by step.</p>
<p>Cybercriminals are constantly looking for new ways to exploit
vulnerabilities and compromise website security. Any security weakness
on site can be an opportunity for attackers. As a WordPress website
owner, securing the business and customer data hosted on your website is
the most crucial.</p>
<p>Sucuri ranked WordPress as the most infected CMS website in 2022 by
<a href="https://sucuri.net/reports/2022-hacked-website-report/">Sucuri</a>. Below
are statistics on vulnerabilities based on WordPress components by
<a href="https://wpscan.com/statistics/">wpscan</a>.</p>
<figure class="mx-auto block text-center">
    <img loading="lazy" src="Wordpress-Vulnerable-Components-Statistics.png"
         alt="Figure 2: Vulnerable WordPress Components"/> <figcaption>
            <p>Figure 2: Vulnerable WordPress Components</p>
        </figcaption>
</figure>

<p>Most of the vulnerabilities were found in third-party plugins, and a few
of them are in the themes. Attackers leverage these vulnerabilities to
gain unauthorized access to your website, spread malware, steal
sensitive information, or even disrupt the functionality of your site.
As a result, proactive efforts can help you to secure your website.</p>
<blockquote>
<p><strong>Defense in Depth</strong>: Security is always about minimizing the risks by
adding as many layers of protection as possible. It&rsquo;s more of a
risk-reduction strategy.</p>
</blockquote>
<p>Both technical and non-technical users can follow the content covered in
this article.</p>
<p>If, by any chance, you are using another third-party vendor to manage
&ldquo;WordPress&rdquo; for you? check out their support page to understand what is
covered in terms of security and what needs to be taken care of by
yourself.</p>
<h2 id="backup-your-wordpress-site">Backup your WordPress site</h2>
<p>Before making any changes to your website, the first thing to do is to
ensure that a complete website backup is taken and can be easily
restored at any time. This precautionary measure will be helpful in case
any unexpected issues arise. Therefore, data integrity should never be
compromised.</p>
<blockquote>
<p>🚧 The backup copy should always be placed in a separate location,
different from the one where you have hosted your WordPress website.</p>
</blockquote>
<p>It would be a disaster if you lost the backup copy and all the site
contents were tampered with or completely lost in any security attack.</p>
<h3 id="having-scheduled-backup">Having Scheduled Backup</h3>
<p>On-demand backups are a good thing to have. However, having a scheduled
backup is still crucial for a website.</p>
<p><strong>Taking backups at regular intervals</strong> can help you restore in case of
a security incident or from human mistakes. You can set the frequency
based on how much new data is being added to your site.</p>
<p>You can adjust the backup intervals from minutes to days based on the
criticality of the data. This is one of the important things to check
while choosing a hosting provider.</p>
<p>Check about <a href="https://www.wpbeginner.com/beginners-guide/how-to-backup-your-wordpress-site/?ref=raghu.io">how to back up your WordPress
site</a>
by Syed Balkhi.</p>
<h2 id="keeping-wordpress-core-themes-and-plugins-updated">Keeping WordPress core, Themes, and Plugins updated</h2>
<p>One of the most essential steps is to keep your site updated with the
latest version of WordPress core, theme, and plugins being used.</p>
<p>Outdated plugins can always pose security risks. From the above stats,
we can understand that <strong>94%</strong> of the attacks originated from
third-party plugins. Keeping the site updated can help you to prevent a
lot of attacks. This simple step can mitigate a lot of attacks for you.</p>
<p>Log into your WordPress site using an admin account and navigate to the
&ldquo;<strong>Dashboard</strong>&rdquo; - &ldquo;<strong>Updates</strong>&rdquo;.</p>
<p>On your updates dashboard, you should be able to see information about
which things require updates.</p>
<figure class="mx-auto block text-center">
    <img loading="lazy" src="WordPress-Dashboard-Updates-View.png"
         alt="Figure 3: WordPress Dashboard - Updates Information"/> <figcaption>
            <p>Figure 3: WordPress Dashboard - Updates Information</p>
        </figcaption>
</figure>

<ul>
<li>Currently, our WordPress Core is already updated, and the latest
version is present on the server, i.e., Version 6.4.3.</li>
<li>The 5 Plugins installed on the above server require updating. The
updates can be for many reasons, like new feature releases or bug
fixes. You can always click on the &ldquo;<strong>View version x.x.x details</strong>&rdquo;
link, which will take you to the <strong>Changelog</strong>, where a detailed list
of what has been changed and what has been improved.</li>
<li>WordPress Core is Automatically updated with security releases.</li>
</ul>
<p>An Admin can see all the available updates.</p>
<blockquote>
<p>The &ldquo;Updates&rdquo; section of the WordPress dashboard contains information
about all the updates needed for your website, such as the WordPress
core, plugins, and themes.</p>
</blockquote>
<p>You can easily update all the necessary plugins.</p>
<p><strong>❗Points to Remember</strong></p>
<ol>
<li>Ensure all your Custom Coded application functionality is free from
conflicts.</li>
<li>Verify all Plugins, Themes, and Core are compatible with the
versions and tech stack you are using.</li>
</ol>
<h3 id="enable-auto-updates-for-wordpress-plugins-and-themes">Enable auto-updates for WordPress Plugins and Themes</h3>
<p>Navigate to the &ldquo;<strong>Plugins</strong>&rdquo; section in the dashboard, which will be
displayed below.</p>
<figure class="mx-auto block text-center">
    <img loading="lazy" src="WordPress-Plugin-Updates.png"
         alt="Figure 4: WordPress Plugin Updates"/> <figcaption>
            <p>Figure 4: WordPress Plugin Updates</p>
        </figcaption>
</figure>

<p>The &ldquo;<strong>Plugins</strong>&rdquo; page is where you can manage all your plugins and
update them all at once.</p>
<p>For any plugins that you think are not very impactful to your website,
you can click on the &ldquo;<strong>Enable auto-updates</strong>&rdquo; button. It will check for
the latest updates available daily. If yes, it will automatically update
for you.</p>
<p>The above option is very helpful.</p>
<p>Default themes provided by WordPress are rigorously tested for security
vulnerabilities along with the core.</p>
<p>Similarly, navigate to &ldquo;<strong>Appearance</strong>&rdquo; -&gt; &ldquo;<strong>Theme</strong>&rdquo;, select the
theme, and click on &ldquo;<strong>Theme Details</strong>&rdquo; for the one that you are using.</p>
<figure class="mx-auto block text-center">
    <img loading="lazy" src="WordPress-Theme-Update.png"
         alt="Figure 5: WordPress Theme Update"/> <figcaption>
            <p>Figure 5: WordPress Theme Update</p>
        </figcaption>
</figure>

<p>You can manually update or just click on the &ldquo;<strong>Enable auto-updates</strong>&rdquo;
link. I hope you&rsquo;re just using the default team directly provided by the
vendor without any customization.</p>
<h3 id="deactivate-unnecessary-or-unused-plugins-came-default">Deactivate Unnecessary or Unused Plugins came default</h3>
<p>When we spin up a self-hosted WordPress website, we usually use prebuilt
templates provided by the cloud providers or the hosting providers. In
any of those cases, WordPress does come with some pre-installed plugins,
but some of them might not be useful in most cases. You can just
deactivate those plugins or delete them completely if they are not of
much help.</p>
<p>Navigate to the &ldquo;<strong>Plugins</strong>&rdquo; section in the dashboard, select the
&ldquo;<strong>Active</strong>&rdquo; plugins list, and click on the &ldquo;<strong>Deactivate</strong>&rdquo; link for
all the plugins that are not very useful to you.</p>
<figure class="mx-auto block text-center">
    <img loading="lazy" src="Deactivate-Plugins.png"
         alt="Figure 6: Deactivate Unused WordPress Plugin"/> <figcaption>
            <p>Figure 6: Deactivate Unused WordPress Plugin</p>
        </figcaption>
</figure>

<p>Even after the plugin is deactivated, the code is still present and
using your storage place on the disk. The database entries will be
there.</p>
<p>If the plugin does not have any important data, you can go ahead and
delete it. It will delete all the files and data related to it from the
database as well.</p>
<blockquote>
<p><strong>Warning:</strong> Avoid the below step if you haven&rsquo;t backed up your data.
Backups can help you to restore if needed.</p>
</blockquote>
<p>If you think the plugin is no longer needed, You can go ahead and delete
it completely. Click on the &ldquo;<strong>Inactive</strong>&rdquo; filter from the &ldquo;<strong>Plugins</strong>&rdquo;
dashboard and click &ldquo;<strong>Delete</strong>&rdquo;.</p>
<figure class="mx-auto block text-center">
    <img loading="lazy" src="Delete-Inactive-Plugins.png"
         alt="Figure 7: Delete Inactive Plugins"/> <figcaption>
            <p>Figure 7: Delete Inactive Plugins</p>
        </figcaption>
</figure>

<p>The above step is one of the ways in which you can reduce the attack
surface for your website. Not only that, but this step can also increase
the performance of your website.</p>
<h3 id="delete-unused-themes-came-by-default">Delete Unused Themes came by default</h3>
<p>You can keep the unused theme if you are using it for testing or for
other purposes. But I believe there is no point in maintaining a feature
that we don&rsquo;t use.</p>
<p>Navigate to &ldquo;<strong>Appearance</strong>&rdquo; -&gt; &ldquo;<strong>Theme</strong>,&rdquo; select the theme, and
click on &ldquo;<strong>Theme Details</strong>&rdquo; for the one that you are using.</p>
<figure class="mx-auto block text-center">
    <img loading="lazy" src="Delete-Inactive-Theme.png"
         alt="Figure 8: Delete Inactive Theme"/> <figcaption>
            <p>Figure 8: Delete Inactive Theme</p>
        </figcaption>
</figure>

<p>At the bottom of the Theme Details, you can just click on the
&ldquo;<strong>Delete</strong>&rdquo; button.</p>
<h3 id="qualities-to-check-with-your-hosting-provider">Qualities to Check with Your Hosting Provider</h3>
<ul>
<li>The vendor <strong>provides the most recent stable version</strong> of WordPress
Core and the latest version of all underlying tech stack.</li>
<li>Providing reliable methods for <strong>backup and recovery</strong> of your data as
and when needed.</li>
<li>Ensuring <strong>secure communication</strong> between the Client and the Server.
(Ex:TLS)</li>
<li><strong>Transparency in communications</strong> in case of any security incidents.</li>
<li>Ensuring your <strong>site availability</strong>.</li>
<li>Ability to discuss any of your security concerns with the support
team.</li>
</ul>
<blockquote>
<p>🖥️ Website owners must take care of the above in the case of a
self-managed site.</p>
</blockquote>
<h2 id="use-https-secure-communication-protocol">Use HTTPS Secure Communication Protocol</h2>
<p>Ensure your WordPress website is enabled with <strong>Transport Layer
Security</strong> (TLS), i.e., HTTPS enabled. Older versions are referred to as
SSL.</p>
<ul>
<li>HTTPS runs on port <strong>443</strong> by default. (You can change it to any
port.)</li>
<li>HTTP runs on port <strong>80</strong> by default.</li>
</ul>
<p>One of the major drawbacks of the <strong>HTTP</strong> protocol is that anyone on
your network can view and monitor all your activity, including sensitive
information like usernames, passwords, etc.</p>
<p><strong>HTTPS</strong> prevents attackers from viewing or tampering with
Client-Server communication. It transmits and receives all your
communications through a secure channel.</p>
<p>Ensure HTTPS is enabled and that your site only listens to HTTPS
communications. To verify, navigate to the <strong>WordPress Dashboard</strong> –&gt;
<strong>Settings</strong> –&gt; <strong>General</strong>.</p>
<p>Check that the <strong>WordPress Address (URL)</strong> and <strong>Site Address (URL)</strong>
are set with the https prefix as displayed below.</p>
<figure class="mx-auto block text-center">
    <img loading="lazy" src="WordPress-HTTPS-Address-Enabled.png"
         alt="Figure 9: WordPress Site with HTTPS Configured"/> <figcaption>
            <p>Figure 9: WordPress Site with HTTPS Configured</p>
        </figcaption>
</figure>

<p>If you are unable to update it from the portal, you might need to change
it accordingly in the <strong>wp-config.php</strong> configuration file.</p>
<p>Additionally, you can go ahead and add a rule in the firewall to disable
all communications on <strong>HTTP port 80</strong> and redirect all traffic to
<strong>HTTPS port 443</strong>.</p>
<p>Let&rsquo;s verify our site is accessible over HTTPS and has a valid
certificate.</p>
<figure class="mx-auto block text-center">
    <img loading="lazy" src="Valid_TLS_Certificate.png"
         alt="Figure 10: Verifying the site TLS Certificate"/> <figcaption>
            <p>Figure 10: Verifying the site TLS Certificate</p>
        </figcaption>
</figure>

<p>Sometimes, the vendor might already have enabled it or provided you with
the necessary information to do so. Refer to your vendor documentation
for instructions on how to do so.</p>
<h2 id="using-wordpress-security-plugins">Using WordPress Security Plugins</h2>
<p>The built-in options for securing the WordPress site are limited. This
is where <a href="https://wordpress.org/plugins/search/security/?ref=raghu.io">third-party
plugins</a>
and
<a href="https://en.wikipedia.org/wiki/Secure_access_service_edge?ref=raghu.io">SASE-based</a>
firewalls come to our rescue. In this section, I will focus only on one
WordPress security plugin, which contains more options available and is
freely available.</p>
<p>I will use
<a href="https://wordpress.org/plugins/wordfence/?ref=raghu.io">Wordfence</a>
for the examples below. There is no silver bullet in security. You are
free to explore other alternative plugins, both free and paid, listed
below.</p>
<ul>
<li><a href="https://wordpress.org/plugins/wp-simple-firewall/?ref=raghu.io">Shield
Security</a></li>
<li><a href="https://wordpress.org/plugins/sucuri-scanner/?ref=raghu.io">Sucuri</a></li>
<li><a href="https://wordpress.org/plugins/all-in-one-wp-security-and-firewall/?ref=raghu.io">All-In-One
Security</a></li>
<li><a href="https://wordpress.org/plugins/better-wp-security/?ref=raghu.io">Solid
Security</a></li>
<li><a href="https://wordpress.org/plugins/search/security/?ref=raghu.io">others</a></li>
</ul>
<p>Pick one that aligns closely with your requirements. Remember, Trust and
reliability are the most important factors when choosing a security
plugin. Check out their reviews and support information, too.</p>
<h3 id="why-did-i-choose-wordfence">Why did I choose Wordfence?</h3>
<ul>
<li>A good number of security hardening features are available for free,
which can help you quickly start securing your website.</li>
<li>Offers malware scanning for free.</li>
</ul>
<blockquote>
<p>❗The malware scanning rules are updated monthly in a free version,
and Real-time protection is available in a premium version.</p>
</blockquote>
<ul>
<li>It continuously updates the vulnerabilities database.</li>
</ul>
<h3 id="wordfence-installation">Wordfence Installation</h3>
<p>Ensure Wordfence Wordpress plugin is installed and configured. Continue
to the next section if you have already installed it.</p>
<h3 id="admin-login-enable-two-factor-authentication">Admin Login: Enable Two-Factor Authentication</h3>
<p>The first step is to secure the WordPress site&rsquo;s logging-in mechanism.
This will ensure only authorized users are logged into the portal and
<strong>deny all others by default</strong>.</p>
<p>This is not limited to the admin user account. It can be enabled for all
the user accounts and roles that are critical for your business
operations.</p>
<p>To get started, Log into the WordPress admin dashboard.</p>
<figure class="mx-auto block text-center">
    <img loading="lazy" src="Login-Security-Enable-2FA.png"
         alt="Figure 11: Wordfence Enable Two-Factor Authentication"/> <figcaption>
            <p>Figure 11: Wordfence Enable Two-Factor Authentication</p>
        </figcaption>
</figure>

<ol>
<li>On the left side of the WordPress admin menu, click on
&ldquo;<strong>Wordfence</strong>&rdquo;.</li>
<li>Navigate to &ldquo;<strong>Login Security</strong>&rdquo;.</li>
<li>Wordfence &ldquo;<strong>Two-Factor Authentication (2FA)</strong>&rdquo; screen will be
loaded with instructions for setting up the 2FA.</li>
</ol>
<blockquote>
<p>The 2FA provided here is based on a mobile application. You can
register with any of the <strong>Time-based One-time Password</strong> (TOTP) apps,
such as <a href="https://play.google.com/store/apps/details?id=com.google.android.apps.authenticator2&amp;ref=raghu.io">Google
Authenticator</a>,
<a href="https://freeotp.github.io/?ref=raghu.io">FreeOTP</a>,
<a href="https://authy.com/?ref=raghu.io">Authy</a>. Enter the TOTP code
displayed on your Mobile app and verify if it&rsquo;s reflecting correctly
and syncing properly with the server., etc. Full list of supported
apps can be referred
<a href="https://www.wordfence.com/help/?query=module-login-security-2fa&amp;ref=raghu.io">here</a>.</p>
</blockquote>
<ol>
<li>In the above screenshot, &ldquo;<strong>user</strong>&rdquo; is my admin account, and I will
enable 2FA for it.</li>
<li>Using any one of the TOTP-based apps, scan the code and ensure the
entry is added to your 2FA app.</li>
<li>After adding an entry, download and save the Recovery Codes in a
safe location, which can be used when the TOTP code is unavailable.</li>
<li>Enter the TOTP code displayed on your mobile app to verify that it&rsquo;s
reflecting correctly and syncing properly with the server.</li>
<li>Click on the &ldquo;Activate&rdquo; button to ensure your 2FA is added
successfully.</li>
</ol>
<p>I hope you have saved your recovery codes safely. After adding 2FA to
your admin account, the next screen will be displayed about your 2FA
status.</p>
<figure class="mx-auto block text-center">
    <img loading="lazy" src="Post-Enabling-2FA.png"
         alt="Figure 12: Wordfence 2FA Status - Logged-in user"/> <figcaption>
            <p>Figure 12: Wordfence 2FA Status - Logged-in user</p>
        </figcaption>
</figure>

<ol>
<li>Displays information about the Two-Factor Authentication.</li>
<li>2FA status of the currently logged-in user. (i.e., user).</li>
<li>Option to deactivate.</li>
<li>If your recovery codes are compromised or lost, or if you used all
the previous codes, you can generate a new set of recovery codes by
clicking on &ldquo;Generate New Codes&rdquo;.</li>
</ol>
<!-- -->
<ol>
<li>
<p>Verifying Two-Factor Authentication</p>
<p>Let&rsquo;s go ahead and verify the 2FA which we have newly created.
Launch a new incognito window and visit your WordPress admin login
page.</p>
<p>A login window appears, the same as how you used to log in earlier.
Just enter the valid admin username and password. Immediately, you
will be taken to a 2FA authentication page.</p>
<figure class="mx-auto block text-center">
        <img loading="lazy" src="Wordfence-2FA-Authentication.png"
             alt="Figure 13: Wordfence 2FA Verification"/> <figcaption>
                <p>Figure 13: Wordfence 2FA Verification</p>
            </figcaption>
    </figure>

<p>Enter the code from your mobile app for the wordfence and ensure
everything works successfully. This will confirm that you have
successfully set up your 2FA authentication for your admin account.</p>
</li>
</ol>
<h3 id="updating-2fa-settings">Updating 2FA Settings</h3>
<ol>
<li>In the WordPress dashboard, visit &ldquo;<strong>Wordfence</strong>&rdquo; -&gt; &ldquo;<strong>Login
Security</strong>&rdquo; and click on the &ldquo;<strong>Settings</strong>&rdquo; tab.</li>
</ol>
<figure class="mx-auto block text-center">
    <img loading="lazy" src="2FA-Security-Settings.png"
         alt="Figure 14: Wordfence - 2FA settings"/> <figcaption>
            <p>Figure 14: Wordfence - 2FA settings</p>
        </figcaption>
</figure>

<ol>
<li>You can view the summary of user accounts and update the 2FA policy
for your WordPress Portal. I have chosen all the admin accounts that
must have 2FA enabled and are optional for other users.</li>
</ol>
<h3 id="enable-2fa-for-woocommerce">Enable 2FA for WooCommerce</h3>
<p>If you are using WooCommerce, ensure that the 2FA support is extended to
WooCommerce users as well.</p>
<figure class="mx-auto block text-center">
    <img loading="lazy" src="WooCommerce-2FA.png"
         alt="Figure 15: Wordfence - Options for WooCommerce 2FA"/> <figcaption>
            <p>Figure 15: Wordfence - Options for WooCommerce 2FA</p>
        </figcaption>
</figure>

<h3 id="enable-recaptcha">Enable reCaptcha</h3>
<p>In the Wordfence &ldquo;<strong>Login Security</strong>&rdquo; settings, you can even find the
option to enable &ldquo;<strong>reCaptcha</strong>&rdquo;, which verifies it is a human who is
trying to log in or register before submitting.</p>
<figure class="mx-auto block text-center">
    <img loading="lazy" src="login-recaptcha.png"
         alt="Figure 16: Wordfence - Login Settings - reCaptcha"/> <figcaption>
            <p>Figure 16: Wordfence - Login Settings - reCaptcha</p>
        </figcaption>
</figure>

<p>This will help you in defending from <strong>brute-force attacks</strong>.</p>
<ol>
<li>Ensure reCaptcha is checked, and make sure to update the Site Key
and secret provided from your Google account after registering. You
can register for reCaptcha by logging in with your Google account
here.</li>
<li>This is a threshold, which is like how strictly you want to check
whether it&rsquo;s a human or a bot. It&rsquo;s good to start with the default.
1.0 is considered stricter, and 0.0 is the least strict.</li>
</ol>
<blockquote>
<p>Please also consider user convenience. Perform strict checks based on
the criticality of the data you are dealing with.</p>
</blockquote>
<ol>
<li>
<p>Verify reCaptcha</p>
<p>Once Google reCaptcha is enabled, you will see the captcha icon at
the bottom of the WordPress admin login page and user registration
page.</p>
<p>f</p>
<p>From now on, it will verify and ensure that only humans can fill out
and submit the forms on your website.</p>
<figure class="mx-auto block text-center">
        <img loading="lazy" src="google-recaptcha-limit.png"
             alt="Figure 18: Google reCaptha Limits Check"/> <figcaption>
                <p>Figure 18: Google reCaptha Limits Check</p>
            </figcaption>
    </figure>

<blockquote>
<p>Remember, google reCaptcha has a limit on the number of free
assessments that can be done. Beyond the limit, it will be charged
monthly.</p>
</blockquote>
<p>Using the above settings, you can prevent the brute-force attacks on
your website.</p>
</li>
</ol>
<h3 id="strengthen-wordfence-firewall-settings">Strengthen Wordfence Firewall Settings</h3>
<p>Imagine if any of the user accounts on the website used a weak password
or a guessable password from a dictionary. It would be easy for
attackers to brute-force the password and take over the account.</p>
<p>This is one of the common attacks in WordPress, and you might
continuously see the BruteForce attempts on your website.</p>
<p>2FA login security can prevent attacks to an extent, but how about
non-2FA login accounts?</p>
<p>Let&rsquo;s go ahead and tighten the security for those accounts as well.</p>
<p>Enforce a Strong Password Policy</p>
<p>In the WordPress admin dashboard, navigate to &ldquo;Wordfence&rdquo;, and select
&ldquo;All Options&rdquo; from the left side menu.</p>
<p>The Wordfence &ldquo;All Options&rdquo; page will be loaded as displayed below.</p>
<p>Click and Expand the &ldquo;Brute Force Protection&rdquo; section.</p>
<ol>
<li>Ensure the &ldquo;Brute Force Protection&rdquo; is enabled.</li>
<li>Scroll down to the &ldquo;Additional Options&rdquo; section and ensure the
&ldquo;Enforce Strong passwords&rdquo; option is checked.</li>
<li>Set it to &ldquo;Force all members to use strong passwords&rdquo; from the
dropdown menu.</li>
<li>Make sure to click on &ldquo;Save Changes&rdquo;.</li>
</ol>
<p>These options would be enabled by default in Wordfence. It&rsquo;s good to
verify. Going ahead, Wordfence will ensure that all user accounts are
set with strong passwords.</p>
<p>Enforcing Account Lockout - Limiting Login Attempts</p>
<p>On the same page, we can even update the Account Lockout policy settings
as well.</p>
<p>The Account Lockout settings provided by the default Wordfence are a
good limit. You can proceed with it.</p>
<p>If your site is receiving a high number of brute force attacks, you can
improve the lockout policy, as I have updated it on my website.</p>
<p>Additionally, I have selected the option to &ldquo;Prevent the use of
passwords from leaked in data breaches&rdquo;, which prevents the admin from
using the leaked passwords.</p>
<blockquote>
<p>Do not lock yourself out from the WordPress portal.</p>
</blockquote>
<p>Wordfence Firewall - IP Whitelist</p>
<p>To prevent yourself from locking out from the WordPress portal, it is
good to whitelist your IP address.</p>
<ol>
<li>Click on Wordfence in the WordPress admin dashboard.</li>
<li>Select &ldquo;All Options&rdquo; to list all the Wordfence options available.</li>
<li>The application loads the &ldquo;All Options&rdquo; page. Click and Expand
&ldquo;Advanced Firewall Options&rdquo;.</li>
<li>In the Allowed IP address that bypass all rules, enter your Public
IP address.</li>
<li>Click on &ldquo;Save Changes&rdquo; to ensure the changes are persistent.</li>
</ol>
<p>Using the above option, you can ensure that you are not locking out
yourself. The same option can be used to whitelist the security audits
as well.</p>
<p>Ensure Web Application Firewall Enabled</p>
<p>Using a firewall is one way to control what traffic must be allowed and
what needs to be blocked from reaching your website. Web Application
Firewalls (WAFs) can filter out suspicious traffic coming from the
internet.</p>
<p>These WAFs are continuously updated with the patterns used by the
attackers to compromise the website, which is called as rulesets.</p>
<p>This feature is also available in the Wordfence plugin. The free version
of the Wordfence plugin will check and stop complex threats.</p>
<blockquote>
<p>It is important to regularly update and review your firewall settings
to ensure that your website&rsquo;s security remains strong and up-to-date.</p>
</blockquote>
<p>The Wordfence dashboard provides you with the information you need about
firewall settings and alerts as well.</p>
<ol>
<li>Logging into the WordPress admin account, click on the &ldquo;Wordfence&rdquo;
plugin on the left side.</li>
<li>Click on the &ldquo;Firewall&rdquo; link on the left-side menu.</li>
<li>The &ldquo;Wordfence Dashboard&rdquo; will be loaded as displayed in the above
screenshot.</li>
<li>Click on the &ldquo;Manage Firewall&rdquo; to check out all its settings and
options.</li>
</ol>
<p>The firewall options page will be loaded and displayed below.</p>
<p>From the above screenshot, you can understand that the community edition
(i.e. the free version) stops the complex attacks, and its ruleset
updates are delayed for 30 days compared to premium editions.</p>
<ol>
<li>Click and expand the &ldquo;Basic Firewall Options&rdquo;</li>
<li>When you set up the &ldquo;Wordfence&rdquo; plugin, it starts with a &ldquo;Learning
Mode&rdquo;. In this mode, it tries to understand your plugins and themes'
working behaviour, like how they work and what is expected
behaviour.</li>
</ol>
<p>Post learning mode, it will automatically switch to &ldquo;Enabled and
Protecting&rdquo; mode. You could also change it by clicking on the drop-down
menu.</p>
<p>On the same page, click-expand on the &ldquo;Advanced Firewall Options&rdquo; and
scroll down, you would be able to see firewall rules enabled on your
website.</p>
<p>These are the rule sets that check for attack patterns for web
application vulnerabilities like XSS, SQLI, File upload, XXE, etc.</p>
<p>If an attacker tries to exploit your website with an XSS vulnerability,
the Firewall&rsquo;s XSS rule is triggered, and that particular attempt is
blocked immediately.</p>
<p>Let&rsquo;s check the Wordfence Firewall in Action. I will just key in with a
sample XSS payload, and let&rsquo;s see how it behaves.</p>
<p>The above screenshot demonstrates that our firewall is active and
blocking the XSS attempts with an HTTP response Forbidden 403 and a
custom warning message from the Wordfence plugin.</p>
<p>If you have authorized any security professional to carry out the
security assessment on your website, whitelist the IP address of
authorized professionals and remove it when the assessment is complete.</p>
<p>I hope the above options can help you get started. At any point, you
could opt for a premium service or seek professional assistance when
needed.</p>
<p>Avoid Nulled WordPress Plugins or Themes</p>
<p>WordPress Nulled plugins or themes are modified versions of premium
WordPress plugins distributed for free or at a negligible cost over the
Internet through unofficial channels that anyone can download and use.</p>
<p>It might seem like a good deal to use without paying, but it does come
with a few security risks. To learn more about it, check out the below
bookmark.</p>
<p><a href="/security-threats-of-nulled-wordpress-plugins-and-themes-uncovering-the-hidden-dangers/">Security Threats of Nulled WordPress Plugins and
Themes</a></p>
<p>Wordfence Help</p>
<p>All the options I have covered above are good for helping you easily get
started securing your WordPress website.</p>
<p><a href="https://www.wordfence.com/help/">Wordfence Help Center</a></p>
<p>Using Cloudflare Web Application Firewall</p>
<p>Sometimes, the website owner would like to avoid having too many plugins
for multiple reasons, such as slowdowns or maintenance reasons.</p>
<p>In this case, we could opt for a cloud-based web application firewall
like Cloudflare WAF, Amazon WAF, etc. These cloud-based firewalls act as
proxies, monitor traffic and filter out all malicious traffic before
passing it to our Web Server. Since everything is done on the cloud,
your server is not overloaded.</p>
<p>These cloud-based firewalls act as the first line of defence and filter
out OWASP Top 10 Vulnerabilities, Bot Protection, Block DDOS attacks,
and malicious behaviour before allowing traffic to your server.
Cloudflare has free and premium plans. The rest are premium services.</p>
<p>For the demo, we shall get started using the free option that is
available. Before proceeding, I would request you to check the following
link, Adding a Site to Cloudflare, and ensure your website is added to
Cloudflare.</p>
<p>Log into your Cloudflare account, navigate to your DNS settings and
click on Records.</p>
<p>In your DNS records, look out for the one pointing to your WordPress
website. In my case it &ldquo;wp.securityarray.io&rdquo;.</p>
<ol>
<li>Click &ldquo;Edit&rdquo; on your DNS record. i.e. for wp.securityarray.io</li>
<li>Ensure the &ldquo;Proxy Status&rdquo; is enabled and all your incoming traffic
is proxied through Cloudflare.</li>
<li>Click on the &ldquo;Save&rdquo; button to make the changes.</li>
</ol>
<blockquote>
<p>Additionally, Cloudflare also hides your server IP address from the
public and has basic WAF protection, CDN capabilities, and DDOS
protection enabled for your website.</p>
</blockquote>
<p>The above configuration will ensure that all our traffic for
&ldquo;wp.securityarray.io&rdquo; hits Cloudflare first and then reaches my server.</p>
<p>With the above, we have successfully been able to set up the basic WAF
protection for our website.</p>
<p>As of today, a cheaper option for WordPress users is to use Cloudflare
through Cloudways. Cloudways + Cloudflare are integrated and offer
premium WAF capabilities at lower cost.</p>
<p>Scan for Vulnerabilities and Malware</p>
<p>Another important aspect of WordPress security is to scan your website
for any known vulnerabilities and Malware at regular intervals.</p>
<p>Initially, would recommend installing and getting started with a Jetpack
Protect plugin. I</p>
<blockquote>
<p>The Jetpack Protect plugin differs from the Jetpack plugin and is
offered separately by the Jetpack team. It is important to note that
there is no dependency between the Jetpack Protect plugin and the
Jetpack plugin.</p>
</blockquote>
<p>The next steps would be to evaluate the different security plugins that
are available in the market and choose the one that meets your
requirements and needs.</p>
<p>Check out the bookmark below to learn more about the different ways to
scan your WordPress website for vulnerabilities.</p>
<p><a href="/wordpress-scan-for-vulnerabilities-a-comprehensive-guide-for-site-security/">WordPress Scan for
Vulnerabilities</a></p>
<p>Install only reputable and trusted plugins. I recommend checking the
plugins&rsquo; reviews and support information before choosing one.</p>
<p>Monitoring and Responding to Security Threats</p>
<p>A good amount of context is covered in securing the WordPress website.
Hardening the WordPress Site is not a one-time effort.</p>
<p>You would need to dedicate some time to monitoring it continuously,
whether daily, weekly, or monthly, based on the severity of the data you
are handling.</p>
<p>&ldquo;Security is a process, not a product.&rdquo; By: Bruce Schneier</p>
<p>Advantages of Monitoring</p>
<ul>
<li>Helps to keep your WebSite free from malware</li>
<li>You know about the latest threats and keeping the WordPress core and
plugins updated.</li>
<li>Recognize the breaches early.</li>
<li>You could also opt for updates through email notifications.</li>
</ul>
<p>Wordfence Scan</p>
<p>A good amount of monitoring for security threats can be done with the
help of the Wordfence plugin itself.</p>
<ol>
<li>In the WordPress admin dashboard, click and select &ldquo;Wordfence&rdquo;</li>
<li>Click on the &ldquo;Scan&rdquo; link.</li>
<li>The &ldquo;Scan&rdquo; section will loaded and displayed as shown above.</li>
<li>You can start the scan by clicking on the &ldquo;Start New Scan&rdquo; button at
any time on demand. It is generally scheduled to run every 24 hours.
For more information, click on &ldquo;Scan Options and Scheduling&rdquo;.</li>
<li>Wordfence Scan will check for the Server State, File Changes,
Malware Scan, Content Safety, Public Files, Password Strength,
Vulnerability Scan, and User &amp; Option Audit related files.
Additionally, it will display warnings if any are found on your
website.</li>
<li>Results information will be displayed.</li>
</ol>
<p>Just double-click on the result item or click on the details button on
the result. It will provide you with more information.</p>
<p>For each result, you can understand the problem and how to address it.
If you think any of the result is &ldquo;Fase Positive&rdquo;, you can click on the
Ignore button.</p>
<p>Performing all the above actions can help you reduce attacks and secure
the website to a good extent. You can always seek professional services
if additional needs arise.</p>
<h2 id="troubleshooting">Troubleshooting</h2>
<h3 id="my-website-becomes-slow-when-using-wordfence">My Website becomes slow when using Wordfence</h3>
<p>This is one of the performance impacts that can be witnessed on some of
the WordPress websites. One option is to set &ldquo;Low resource scanning&rdquo;.</p>
<p>To do this, Navigate to &ldquo;<strong>Wordfence</strong>&rdquo; -&gt; &ldquo;<strong>Scan</strong>&rdquo; -&gt; <strong>Scanner
Options and Scheduling</strong> -&gt; <strong>Performance Option</strong> -&gt; Ensure &ldquo;<strong>Use
low resource scanning</strong> (reduces server load by lengthening the scan
duration)&rdquo; is enabled and check.</p>
<p>Another option could be to use premium solutions like Sucuri or check
Cloudflare WAF solutions.</p>
<h3 id="i-think-my-website-has-been-hacked">I think my website has been Hacked.</h3>
<p>Try using a couple of options, like cleaning and reinstalling all the
latest versions of the plugins. Scan with malware analysis plugins like
Wordfence, Sucuri, etc. If the issue persists, seek professional
assistance.</p>
<h2 id="conclusion">Conclusion</h2>
<p>In conclusion, website security is of utmost importance, especially for
WordPress website owners. With the increasing number of cyber threats,
it&rsquo;s crucial to take proactive measures to protect your online assets.</p>
<p>Wordfence is a security plugin that is freely available for WordPress
and provides a wide range of features to enhance your website&rsquo;s
security. Free plugins always come with limitations. It is good to get
started, but when demand increases, you might need to opt for premium
options with dedicated support.</p>
<p>By following the steps outlined in this guide, you can configure
Wordfence and its settings to keep your website safe from potential
threats such as malware, brute force attacks, and more.</p>
<p>Additionally, keep monitoring the WordPress security news and take
action accordingly. Don&rsquo;t wait until it&rsquo;s too late – take the necessary
steps to secure your website today.</p>
<h2 id="additional-checklists-and-references">Additional Checklists and References:</h2>
<ul>
<li><a href="https://wordpress.org/news/category/security/?ref=raghu.io">WordPress
Security</a></li>
<li><a href="https://jetpack.com/blog/wordpress-security-checklist/?ref=raghu.io">JetPack - The Only WordPress Security
Checklist</a></li>
<li><a href="https://wpscan.com/blog/wordpress-security-checklist/?ref=raghu.io">The Ultimate WordPress Security
Checklist</a></li>
<li><a href="https://www.cloudways.com/blog/wordpress-security-checklist/?ref=raghu.io">The Ultimate WordPress Security Checklist -
Cloudways</a></li>
</ul>
]]></content:encoded>
    </item>
    <item>
      <title>XSS Explained - Learn cross-site scripting with examples</title>
      <link>https://raghu.io/xss-explained-learn-cross-site-scripting-with-examples/</link>
      <pubDate>Fri, 25 Nov 2022 11:35:43 +0000</pubDate>
      <guid>https://raghu.io/xss-explained-learn-cross-site-scripting-with-examples/</guid>
      <description>Kurukshetra is an intentionally designed XSS-vulnerable application. XSS is explained with examples, and it&amp;#39;s an open-source lab for practicing and learning cross-site scripting vulnerabilities.</description>
      <content:encoded><![CDATA[<p>You would like to learn more about what a cross-site scripting
vulnerability is and how it can be exploited with examples. This is the
right place for you. I have compiled short lessons on cross-site
scripting (XSS) vulnerability with trial testing scenarios close to
real-time, which can help you get started with real-world applications.</p>
<p>Let&rsquo;s start by setting up the lab environment needed for practicing XSS,
and upcoming articles will cover the theory and step-by-step approach
for identifying the vulnerability.</p>
<figure>
    <img loading="lazy" src="/icons/tool-box.png"/> 
</figure>

<h2 id="kurukshetra--an-xss-vulnerable-app-by-design">Kurukshetra- An XSS-vulnerable app by design</h2>
<p>In the author&rsquo;s own words, &ldquo;<strong>Kurukshetra is a vulnerable lab geared
towards practicing XSS challenges.</strong>&rdquo;</p>
<p>The app&rsquo;s motto is to give you hands-on experience in identifying the
XSS vulnerability in different ways and also keep you updated about the
theory and basics needed.</p>
<p>Check out the <a href="https://github.com/D4rk36/Kurukshetra/?ref=raghu.io">GitHub -
D4rk36/Kurukshetra</a>
for more info.</p>
<figure>
    <img loading="lazy" src="/icons/caution.png"/> 
</figure>

<blockquote>
<p>All the content here provided is only for the educational purposes.
Authors, Application Creators or Web Site Owners are not responsible
for misuse of your knowledge. You are responsible for your own
actions!.</p>
</blockquote>
<!--quoteend-->
<blockquote>
<p>Kurukshetra app isn&rsquo;t for production use! Only for testing and
learning on a host machine.</p>
</blockquote>
<h2 id="preparing-environment">Preparing Environment</h2>
<p>A couple of things must be done to start working on the
&ldquo;<strong>Kurukshetra</strong>&rdquo; XSS vulnerable application.</p>
<ol>
<li><strong>Docker &amp; Docker Compose</strong> must be installed and working</li>
<li>A working <strong>OS(Linux/Windows/Mac)</strong> with network connectivity</li>
<li><strong>Git</strong> installed</li>
</ol>
<p>Feel free to skip to the next section if all the required tools are
pre-installed.</p>
<p>For users whose Docker is not installed, please visit the <a href="https://docs.docker.com/get-docker/?ref=raghu.io">Get
Docker</a> page
and follow the instructions as specified.</p>
<p>Once installed, make sure the Docker is working. The output of the
command should be something similar to the below output.</p>
<h3 id="docker-check">Docker check:</h3>
<div class="highlight"><pre tabindex="0" class="chroma"><code class="language-shell" data-lang="shell"><span class="line"><span class="cl">docker --version
</span></span></code></pre></div><p><strong>Output</strong>:</p>
<div class="highlight"><pre tabindex="0" class="chroma"><code class="language-text" data-lang="text"><span class="line"><span class="cl">Docker version 20.10.17, build 100c701
</span></span></code></pre></div><p>After installing the Docker, you can set up the
<a href="https://docs.docker.com/compose/install/?ref=raghu.io">docker-compose</a>
by referring to the given link. It is needed to build up the environment
on the go.</p>
<p>Make sure the docker-compose is working by verifying the version
information.</p>
<h3 id="docker-compose-check">Docker Compose check:</h3>
<div class="highlight"><pre tabindex="0" class="chroma"><code class="language-shell" data-lang="shell"><span class="line"><span class="cl">docker compose version
</span></span></code></pre></div><p><strong>Output</strong>:</p>
<div class="highlight"><pre tabindex="0" class="chroma"><code class="language-text" data-lang="text"><span class="line"><span class="cl">Docker Compose version v2.12.2
</span></span></code></pre></div><p>Hopefully, &ldquo;<strong>git</strong>&rdquo; is installed on most of them. If you think you
don&rsquo;t have one, just go ahead and install it from your package manager
or the link given below.</p>
<p><a href="https://git-scm.com/downloads?ref=raghu.io">Git - Download</a></p>
<figure>
    <img loading="lazy" src="/icons/application.png"/> 
</figure>

<h2 id="lab-setup---kurukshetra-application-">Lab-Setup - &ldquo;Kurukshetra&rdquo; Application 💻</h2>
<p>Let&rsquo;s clone the application from the GitHub repository and copy it onto
your system.</p>
<div class="highlight"><pre tabindex="0" class="chroma"><code class="language-bash" data-lang="bash"><span class="line"><span class="cl">git clone https://github.com/D4rk36/Kurukshetra.git
</span></span></code></pre></div><p>Navigate to the downloaded directory.</p>
<div class="highlight"><pre tabindex="0" class="chroma"><code class="language-bash" data-lang="bash"><span class="line"><span class="cl"><span class="nb">cd</span> ./Kurukshetra
</span></span></code></pre></div><p>Inside the directory, you will find a &ldquo;<strong>docker-compose.yml</strong>&rdquo; file,
which contains the instructions for running the application. You have to
run &ldquo;<code>docker compose up</code>&rdquo; to bring up the environment.</p>
<div class="highlight"><pre tabindex="0" class="chroma"><code class="language-bash" data-lang="bash"><span class="line"><span class="cl">docker compose up
</span></span></code></pre></div><p>Once the environment is up, let&rsquo;s verify by accessing the app
environment by clicking on the following URL: <a href="http://localhost:8066/">http://localhost:8066/</a>
or paste it into your browser.</p>
<blockquote>
<p>💡In case you are facing any errors. Please re-verify all the steps
from the docker installation.</p>
</blockquote>
<p>The page will be displayed below.</p>
<figure class="mx-auto block text-center">
    <img loading="lazy" src="Challenge-Page.png"
         alt="Figure 1: Kurukshetra - XSS Challenges Page"/> <figcaption>
            <p>Figure 1: Kurukshetra - XSS Challenges Page</p>
        </figcaption>
</figure>

<p>Bringing up the Docker instance might take a couple of minutes, based on
your network speeds. You should also be able to see the log as displayed
below while starting up.</p>
<figure class="mx-auto block text-center">
    <img loading="lazy" src="Kurukshetra-Running.png"
         alt="Figure 2: Kurukshetra Running"/> <figcaption>
            <p>Figure 2: Kurukshetra Running</p>
        </figcaption>
</figure>

<p>During any time in the lab, you can run &ldquo;<strong>Ctrl - c</strong>&rdquo; to stop the
running environment.</p>
<p>Additionally, to completely remove the &ldquo;Kurukshetra&rdquo; containers running
from your system, run the remove command from the same directory where
the <strong>docker-compose.yml</strong> file is present.</p>
<div class="highlight"><pre tabindex="0" class="chroma"><code class="language-bash" data-lang="bash"><span class="line"><span class="cl">docker compose rm
</span></span></code></pre></div><p>Now that our lab environment is up and working, you are good to proceed
to the next step of identifying the XSS vulnerabilities.</p>
<figure>
    <img loading="lazy" src="/icons/report.png"/> 
</figure>

<h2 id="summary">Summary</h2>
<p>The setup is straightforward for users who are familiar with Docker. For
other users who are new to docker, you might need to get adapted to
using it. Most of the tools are now being containerized to avoid the
installation process. Just download and run with docker.</p>
<p>Ensure your lab environment is working to jump-start learning about
cross-site scripting vulnerability. The next articles will cover types
of cross-site scripting vulnerabilities and techniques used to identify
them. 😃</p>
<h2 id="additional-references-for-xss-practice">Additional References for XSS Practice:</h2>
<ul>
<li>XSSy Labs</li>
</ul>
]]></content:encoded>
    </item>
    <item>
      <title>DVWA - Brute Force Attack and Prevention Explained</title>
      <link>https://raghu.io/dvwa-brute-force-attack-and-prevention-explained/</link>
      <pubDate>Fri, 30 Sep 2022 06:53:00 +0000</pubDate>
      <guid>https://raghu.io/dvwa-brute-force-attack-and-prevention-explained/</guid>
      <description>This detailed guide explains Brute Force Attacks, how they work, and ways to prevent them. You can also explore a demo to understand the concept better and discover effective prevention mechanisms to safeguard your online security.</description>
      <content:encoded><![CDATA[<p>Brute Force is one of the security vulnerabilities which is commonly
seen. This article will demonstrate the brute force attack on the Damn
Vulnerable Web Application - an intentionally designed vulnerable
application. In addition, it will cover how they work, the potential
impact, and effective ways to prevent and safeguard your online
security.</p>
<p>The following post is part of learning application security with the
DVWA application.</p>
<p>Before jumpstart, ensure the <a href="/lab-setup-docker-dvwa/">docker
DVWA</a> application is
enabled, configured, and accessible.</p>
<h2 id="what-is-a-brute-force-attack">What is a Brute Force Attack?</h2>
<p>A brute force attack is a trial-and-error method in which every possible
combination of commonly used words, usernames, and passwords is tried
out, hoping any of them will work.</p>
<p>Brute Force attacks are aimed at guessing commonly known files on the
web server, breaking into email accounts, guessing remote services SQL
or SSH server credentials (online), cracking password hashes (offline),
etc., to gain unauthorized access to sensitive data or compromise
security.</p>
<p>It would require a good amount of computing resources and <strong>time</strong>. #️⃣</p>
<p>The screenshot below from
<a href="https://www.cloudflare.com/img/learning/security/threats/brute-force-attack/brute-force-cracking-time.png?ref=raghu.io">Cloudflare</a>
demonstrates how long it can take to crack a password based on the
number of characters.</p>
<figure class="mx-auto block text-center">
    <img loading="lazy" src="brute-force-cracking-time.png"
         alt="Figure 1: BruteForce Attack Statistics - [[https://www.cloudflare.com/learning/bots/brute-force-attack/][Cloudflare]]"/> <figcaption>
            <p>Figure 1: BruteForce Attack Statistics - [[https://www.cloudflare.com/learning/bots/brute-force-attack/][Cloudflare]]</p>
        </figcaption>
</figure>

<p>Today&rsquo;s hardware helps us crack a hashed password of 5 characters or
fewer in seconds. The one with 12 characters or more, combining small
letters, upper-case letters, special characters, and numerics, takes
years to crack. The bigger the password, the more time it takes to crack
using a Brute Force attack.</p>
<blockquote>
<p>Think wisely, how much time you would like to spend for any brute
force attack. A day or two may be good, but years and decades may not
be worth enough.</p>
</blockquote>
<p>Speaking on behalf of security assessments, we will be spending days or
weeks. But attackers do have all the time they want.</p>
<h2 id="how-do-brute-force-attacks-work">How do Brute Force attacks work?</h2>
<p>Brute Force attacks are performed using automated tools or software. A
massive list of dictionaries containing common passwords, usernames,
words, etc., is generated and given to the tool as input.</p>
<p>The tool keeps interacting with the service and tries out the dictionary
entries one by one until a valid match is found, at which point it
stops.</p>
<p>During this process, the attacker uses large dictionary data sets until
the correct combination is discovered and successful access to
confidential resources is obtained.</p>
<p>From now on, we will use the &ldquo;<a href="https://portswigger.net/">Burp
Suite</a>&rdquo;
as an ideal tool for all our brute force attacks and to keep demos
focused. If you would like to learn more about the basics and usage of
the tool, Check out the following post on <a href="/burpsuite-overview/">BurpSuite
Overview</a>.</p>
<p>Next, I will be using a small custom dictionary of usernames and
passwords for fast brute-force results, which will be performed later.</p>
<div class="highlight"><pre tabindex="0" class="chroma"><code class="language-text" data-lang="text"><span class="line"><span class="cl">admin
</span></span><span class="line"><span class="cl">administrator
</span></span><span class="line"><span class="cl">user
</span></span><span class="line"><span class="cl">john
</span></span><span class="line"><span class="cl">dvwa
</span></span><span class="line"><span class="cl">bob
</span></span><span class="line"><span class="cl">alice
</span></span><span class="line"><span class="cl">root
</span></span><span class="line"><span class="cl">superuser
</span></span><span class="line"><span class="cl">super
</span></span></code></pre></div><div class="highlight"><pre tabindex="0" class="chroma"><code class="language-text" data-lang="text"><span class="line"><span class="cl">admin
</span></span><span class="line"><span class="cl">admin123
</span></span><span class="line"><span class="cl">password
</span></span><span class="line"><span class="cl">password123
</span></span><span class="line"><span class="cl">user
</span></span><span class="line"><span class="cl">user123
</span></span><span class="line"><span class="cl">administrator
</span></span><span class="line"><span class="cl">passw0rd
</span></span><span class="line"><span class="cl">r3m3mb3rM3
</span></span><span class="line"><span class="cl">admin123$
</span></span></code></pre></div><h2 id="brute-force-attack---demo">Brute Force Attack - Demo</h2>
<p>The DVWA application has a Login page functionality that can be used to
brute-force and find the right match of user credentials, simulating the
attackers to compromise the application.</p>
<p>Let&rsquo;s go ahead and simulate the steps of an attacker and see if we can
break in.</p>
<p>In information security, it&rsquo;s all about chaining up every piece of
information you know, experimenting with it, and confirming if it works.
In short, it lies in your creativity when using the information.</p>
<figure class="mx-auto block text-center">
    <img loading="lazy" src="DVWA_BruteForce_Vulnerability.png"
         alt="Figure 2: DVWA Brute Force - Login Page"/> <figcaption>
            <p>Figure 2: DVWA Brute Force - Login Page</p>
        </figcaption>
</figure>

<p>At the moment, we do not have any information about the
username/password. All we see is a login page.</p>
<p>We will start with the Brute Force attack using the above dictionaries.</p>
<p>Let&rsquo;s start the BurpSuite tool and use the small custom dictionaries we
created above. The tool tests for all possible combinations, and this
method is scalable to thousands of combinations.</p>
<p>In the Burp Suite tool, navigate to the &ldquo;<strong>Proxy</strong>&rdquo; tab and click on the
&ldquo;<strong>Open Browser</strong>&rdquo; button. A Chromium browser will be launched and will
be displayed as shown below.</p>
<figure class="mx-auto block text-center">
    <img loading="lazy" src="BurpSuite-Chromium-Browser.png"
         alt="Figure 3: Burp Suite In-Built Chromium Browser"/> <figcaption>
            <p>Figure 3: Burp Suite In-Built Chromium Browser</p>
        </figcaption>
</figure>

<p>Log into the DVWA application using &ldquo;<strong>admin/password</strong>&rdquo; and navigate to
the &ldquo;<strong>Brute Force</strong>&rdquo; item in the menu.</p>
<p>Let&rsquo;s try some known username and password combinations.</p>
<p>Say &ldquo;<strong>administrator/admin123</strong>&rdquo;, &ldquo;<strong>admin/admin123</strong>&rdquo;,
&ldquo;<strong>user/user123</strong>&rdquo; etc. For all incorrect attempts, we keep getting the
&ldquo;<strong>Username and/or password incorrect</strong>.&rdquo; message.</p>
<p>Manually trying out is also known as a simple brute force attack, which
is painful and limits the knowledge to oneself. This approach is
time-consuming and isn&rsquo;t scalable.</p>
<p>If you found a valid login match this approach? <strong>Excellent. You
perfectly guessed it</strong>. 👍</p>
<p>In Burp Suite, we need to capture the Login request. I will enable the
Intercept option to capture a specific login request so we can perform
automated operations using it.</p>
<p>To enable it, navigate to Burp Suite &ldquo;<strong>Proxy</strong>&rdquo; tab ⇾ &ldquo;<strong>Intercept</strong>&rdquo; ⇾
toggle on the &ldquo;<strong>intercept off</strong>&rdquo; button. It immediately turns to
&ldquo;<strong>intercept on</strong>&rdquo; as displayed below.</p>
<figure class="mx-auto block text-center">
    <img loading="lazy" src="BurpSuite-Intercept-On.png"
         alt="Figure 4: BurpSuite Intercept &ldquo;Toggle On&rdquo;"/> <figcaption>
            <p>Figure 4: BurpSuite Intercept &ldquo;Toggle On&rdquo;</p>
        </figcaption>
</figure>

<p>Key in some random data in the username and password file, then click on
the &ldquo;<strong>Login</strong>&rdquo; button as shown below.</p>
<figure class="mx-auto block text-center">
    <img loading="lazy" src="BruteForce_enter_randomcreds.png"
         alt="Figure 5: Key in random credentials on the Login Page"/> <figcaption>
            <p>Figure 5: Key in random credentials on the Login Page</p>
        </figcaption>
</figure>

<p>Once the Burp Suite receives an intercept request, you should be able to
see the highlights immediately. Navigate to the &ldquo;<strong>Proxy</strong>&rdquo; tab. ⇾
&ldquo;<strong>Intercept</strong>&rdquo;. You should be able to see a request similar to the one
below.</p>
<figure class="mx-auto block text-center">
    <img loading="lazy" src="BruteForce-Login-Request.png"
         alt="Figure 6: Brute Force functionality Login Request"/> <figcaption>
            <p>Figure 6: Brute Force functionality Login Request</p>
        </figcaption>
</figure>

<p>An <strong>HTTP GET</strong> method is used, remember the GET method doesn&rsquo;t have a
message body. Therefore, all the parameters and values will be sent as a
URL.</p>
<div class="highlight"><pre tabindex="0" class="chroma"><code class="language-text" data-lang="text"><span class="line"><span class="cl">GET /vulnerabilities/brute/?username=admin&amp;password=testpassword&amp;Login=Login HTTP/1.1
</span></span></code></pre></div><p>Here, we are trying to access a page called &ldquo;<strong>/vulnerabilities/brute</strong>&rdquo;
and passing parameter values
&ldquo;<strong>username=admin&amp;password=testpassword&amp;Login=Login</strong>&rdquo; to perform the
login action required by the application.</p>
<p>If your credentials are valid, you will be able to log in successfully.
Otherwise, you will receive an invalid login error message.</p>
<p>Now, click on the &ldquo;<strong>Action</strong>&rdquo; button and select &ldquo;<strong>Send to Intruder</strong>&rdquo;.</p>
<figure class="mx-auto block text-center">
    <img loading="lazy" src="BruteForce_Send_To_intruder.png"
         alt="Figure 7: Send to Intruder"/> <figcaption>
            <p>Figure 7: Send to Intruder</p>
        </figcaption>
</figure>

<p>Switch to the &ldquo;<strong>Intruder</strong>&rdquo; tab, and you should be able to see the same
request there. Under the &ldquo;<strong>Positions</strong>&rdquo; sub-tab, The tool automatically
detects where all the changeable values need to be placed and highlights
the five parameter values section for us.</p>
<figure class="mx-auto block text-center">
    <img loading="lazy" src="BruteForce-Intruder-Payload.png"
         alt="Figure 8: Request Being Used as Payload"/> <figcaption>
            <p>Figure 8: Request Being Used as Payload</p>
        </figcaption>
</figure>

<p>I will clear all the payload locations and select only username and
password using the &ldquo;<strong>Clear</strong>&rdquo; and &ldquo;<strong>Add</strong>&rdquo; buttons beside.</p>
<figure class="mx-auto block text-center">
    <img loading="lazy" src="BruteForce_Intruder_Choose_Payloads.png"
         alt="Figure 9: Select the Positions in a Request to autoamte payloads with dictionaries"/> <figcaption>
            <p>Figure 9: Select the Positions in a Request to autoamte payloads with dictionaries</p>
        </figcaption>
</figure>

<h2 id="types-of-brute-force-attacks">Types of Brute Force Attacks</h2>
<p>There are four brute-force attack types that are supported by the &ldquo;Burp
Suite&rdquo; tool.</p>
<figure class="mx-auto block text-center">
    <img loading="lazy" src="Intruder-Attack-Types.png"
         alt="Figure 10: BurpSuite Intruder Attack Types"/> <figcaption>
            <p>Figure 10: BurpSuite Intruder Attack Types</p>
        </figcaption>
</figure>

<p><strong>Cluster Bomb</strong> best suits our requirements. Set the attack type to
&ldquo;<strong>Cluster Bomb</strong>&rdquo; and switch to the &ldquo;<strong>Payload</strong>&rdquo; sub-tab.</p>
<figure class="mx-auto block text-center">
    <img loading="lazy" src="BruteForce-Choose-Intruder-Attack-Type.png"
         alt="Figure 11: BurpSuite Brute Force select Attack Type"/> <figcaption>
            <p>Figure 11: BurpSuite Brute Force select Attack Type</p>
        </figcaption>
</figure>

<p>In the &ldquo;<strong>Payloads</strong>&rdquo; sub-tab, select &ldquo;<strong>Payload Set 1</strong>&rdquo;, payload type
as &ldquo;<strong>simple list</strong>&rdquo; and paste all the contents in payload options
copied from the <strong>usernames.txt</strong> list.</p>
<p>This is for the &ldquo;<strong>Username</strong>&rdquo; values.</p>
<figure class="mx-auto block text-center">
    <img loading="lazy" src="BruteForce-Intruder-Payload-Set-1.png"
         alt="Figure 12: Usernames Payload"/> <figcaption>
            <p>Figure 12: Usernames Payload</p>
        </figcaption>
</figure>

<p>Second, select the &ldquo;<strong>Payloads</strong>&rdquo; sub-tab, set &ldquo;<strong>Payload Set 2</strong>&rdquo;, set
the payload type as &ldquo;<strong>simple list</strong>&rdquo; and paste all the contents in
payload options copied from the <strong>passwords.txt</strong> list.</p>
<p>This is for the &ldquo;<strong>Password</strong>&rdquo; values.</p>
<figure class="mx-auto block text-center">
    <img loading="lazy" src="BruteForce-Intruder-Payload-Set-2.png"
         alt="Figure 13: Password Payloads"/> <figcaption>
            <p>Figure 13: Password Payloads</p>
        </figcaption>
</figure>

<p>Observe that the request count is now set to 100. Using the two lists
now, we will be trying out 100 possible combinations.</p>
<p>Lastly, click the &ldquo;<strong>brute-force</strong>&rdquo; button at the top right to initiate
our brute-force attack.</p>
<blockquote>
<p>In the BurpSuite Community edition it prompts with a warning box as
some features are limited. Click &ldquo;Ok&rdquo; to continue.</p>
</blockquote>
<p>An intruder window pops up, and the payload information and request
status will be displayed below.</p>
<p>If you take a look, we can see we are getting a <strong>200</strong> status for each
request, which means &ldquo;<strong>200 Ok</strong>&rdquo;.</p>
<p>How do we know which payload combination worked and which hasn&rsquo;t?</p>
<p>One way is to click on each request with a <strong>200 Ok</strong> status, select the
&ldquo;<strong>Response</strong>&rdquo; sub-tab, and search for the string named &ldquo;<strong>Username
and/or password incorrect</strong>&rdquo;. We know this belongs to a failed login
attempt.</p>
<p>If the string isn&rsquo;t present, it means the credentials combination
worked, and that would be our match.</p>
<figure class="mx-auto block text-center">
    <img loading="lazy" src="BruteForce-Attack-Results.png"
         alt="Figure 14: Brute Force Intruder Attack Results"/> <figcaption>
            <p>Figure 14: Brute Force Intruder Attack Results</p>
        </figcaption>
</figure>

<p>BurpSuite Intruder figured out there is one positive match on the bottom
right side of the screenshot. This is a time-consuming approach.</p>
<p>Focus on the size of the length as shown below. For all incorrect
attempts, the response message length is the same &ldquo;<strong>4666</strong>&rdquo;. Check one
of a different length, i.e., <strong>4704</strong>.</p>
<figure class="mx-auto block text-center">
    <img loading="lazy" src="BruteForce-Worked-Combination-Intruder.png"
         alt="Figure 15: Brute Force Payload Match Found"/> <figcaption>
            <p>Figure 15: Brute Force Payload Match Found</p>
        </figcaption>
</figure>

<p>Observe whether the username/password combination &ldquo;<strong>admin/password</strong>&rdquo;
worked. Navigate to the response sub-tab, We can see the &ldquo;<strong>welcome to
the password protected area of admin</strong>&rdquo; message.</p>
<p><strong>Hurray!!</strong> we found the right password match! 👏</p>
<h3 id="password-match-verification">Password Match Verification</h3>
<p>It is always good practice to re-verify the security bug before we
report it.</p>
<p>Make sure all the Intercepts in the proxy tab are toggled to off. Then,
let&rsquo;s return to the brute force page and verify our match to confirm our
results.</p>
<figure class="mx-auto block text-center">
    <img loading="lazy" src="BruteForce-Password-Match-Confirm.png"
         alt="Figure 16: Login Successful"/> <figcaption>
            <p>Figure 16: Login Successful</p>
        </figcaption>
</figure>

<p>Yep, our newly found password combination worked.</p>
<p><strong>Excellent!</strong> We found a security bug using a Brute-Force attack, i.e.,
a guessable username and password.</p>
<p>You were able to learn a quick way to Perform a Brute-Force attack using
DVWA.</p>
<p>I have used a short custom-built word list for demo purposes, Give a try
with other lists. Search for &ldquo;<strong>Brute-Force attack</strong>&rdquo; or &ldquo;<strong>Brute force
wordlist</strong>&rdquo;, and you will find many resources.</p>
<p><a href="https://github.com/topics/bruteforce-wordlist?ref=raghu.io">Here</a>
are some lists from Github.</p>
<h2 id="impact-of-brute-force-attacks">Impact of Brute Force Attacks</h2>
<p>The impact of a successful brute force attack can be severe.</p>
<ul>
<li>Unauthorized access to sensitive information.</li>
<li>Financial loss</li>
<li>Loss of organization&rsquo;s reputation</li>
<li>Leading to potential legal and financial repercussions for the
affected individuals or organizations.</li>
<li>Loss of customer trust, etc.</li>
</ul>
<figure class="mx-auto block text-center">
    <img loading="lazy" src="Fixing-BruteForce-Attack-Banner.png"
         alt="Figure 17: Preventing Brute Force Attacks"/> <figcaption>
            <p>Figure 17: Preventing Brute Force Attacks</p>
        </figcaption>
</figure>

<h2 id="preventing-brute-force-attacks">Preventing Brute Force Attacks</h2>
<p>Security Researchers and web application developers need to be familiar
with mitigation techniques. These skills can help them defend web
applications from malicious actors.</p>
<p>So, let&rsquo;s talk about some ways to detect it and then mitigate it.</p>
<h3 id="patterns-of-brute-force-attack">Patterns of Brute Force Attack</h3>
<p>Some of the common patterns can help to detect brute-force attacks on
our webserver.</p>
<ul>
<li>Too many requests originate from a single IP address within a minute
or hour.</li>
<li>Multiple logins of a single user account from a different IP address
and province.</li>
<li>Excessive usage of the server resources and bandwidth.</li>
<li>Increased number of failed login attempts of various usernames and
passwords.</li>
<li>Logged into multiple user accounts from a single IP address. (i.e.,
guessable default password) etc.</li>
</ul>
<p>The above is a small list targeting user credentials, but the patterns
vary for other resources.</p>
<h2 id="defending-brute-force-attacks">Defending Brute Force Attacks</h2>
<p>Brute force attacks are difficult to stop, but with good measures, we
can limit the attack surface.</p>
<figure>
    <img loading="lazy" src="/icons/question.png"/> 
</figure>

<h3 id="avoid-using-defaultguessable-passwords">Avoid Using Default/Guessable Passwords</h3>
<p>One of the most commonly exploited techniques says some application
servers come with pre-defined default passwords for the initially
created accounts. (Say &ldquo;admin/password&rdquo;)</p>
<p><a href="https://cirt.net/passwords/?ref=raghu.io">Default Password Database -
cirt.net</a></p>
<p>Some companies follow an initial password with the company name followed
by a number sequence. Say &ldquo;<strong>ABCCompany123</strong>&rdquo; or the special character
&ldquo;<strong>ABCCompany123$</strong>&rdquo;, some with established year appending at the end
with a prefix of the usernames &ldquo;<strong>Username2022</strong>&rdquo; etc.</p>
<p>These are all unknown until someone figures them out. Once figured out,
they are easy to try out with all the user accounts to which the user
account has access.</p>
<p>Additionally, prevent users from using passwords such as &ldquo;<strong>password</strong>&rdquo;,
&ldquo;<strong>admin123</strong>&rdquo;, &ldquo;<strong>12345</strong>&rdquo; etc.</p>
<figure>
    <img loading="lazy" src="/icons/limit.png"/> 
</figure>

<h3 id="limit-login-attempts">Limit Login Attempts</h3>
<p>One good practice is to limit the number of failed login attempts the
user is allowed to make. Beyond 7 failed login attempts, the account is
locked for a temporary time period. Like banks, beyond three failed
attempts, the user account will be locked out for 24 hours. Or</p>
<blockquote>
<p>👥The challenge with this type is that unauthorized users keep trying
with valid user accounts and lock out genuine users.</p>
</blockquote>
<figure>
    <img loading="lazy" src="/icons/pin-code.png"/> 
</figure>

<h3 id="enforce-a-strong-password-policy">Enforce a Strong Password Policy</h3>
<p>A best-designed password policy like the use of a combination of small
case letters, upper case letter, numerics, special characters will make
it hard to crack for attackers.</p>
<ul>
<li>Use of password managers wherever applicable.</li>
<li>Avoid re-using the same password.</li>
<li>The length of passwords is to be 8 or above.</li>
<li>Prevent the use of common dictionary words or guessable sequences.</li>
<li>Use of certificates for authentication rather than passwords.</li>
<li>Educate users about using a different password for all accounts.</li>
</ul>
<figure>
    <img loading="lazy" src="/icons/clock.png"/> 
</figure>

<h3 id="progressive-delay">Progressive Delay</h3>
<p>This is also the best technique where the wait time keeps on multiplying
with each failed login attempt.</p>
<p>Say, initially start with &ldquo;<strong>60 Seconds</strong>&rdquo; wait time at the first
attempt, then <strong>15 minutes</strong> of wait time for the second attempt, <strong>60
minutes</strong> for the third attempt, and so on it goes.</p>
<p>Generally, some applications multiply wait seconds by 60 for each failed
attempt.</p>
<h3 id="using-captcha">Using Captcha</h3>
<figure>
    <img loading="lazy" src="/icons/captcha.png"/> 
</figure>

<p>Captchas are used to filter automated bots or programs and prevent them
from abusing the services.</p>
<blockquote>
<p>🤖This is a bit of an inconvenience, but solving a captcha will help
verify that it&rsquo;s human and not automation.</p>
</blockquote>
<h3 id="multi-factor-authentication">Multi-Factor Authentication</h3>
<figure>
    <img loading="lazy" src="/icons/password.png"/> 
</figure>

<p>Adding additional layers of verification makes brute force attack very
tough. Using the OTP - One-time passcode, verification of token through
email, or Security Questions before logging in makes it more difficult
for attackers.</p>
<p>The attacker needs to compromise multiple sources to gain access to your
user accounts which is very tough but not impenetrable.</p>
<h3 id="storing-salted-password-hashes">Storing Salted Password Hashes</h3>
<figure>
    <img loading="lazy" src="/icons/password2.png"/> 
</figure>

<p>Even though our application is secured in all possible ways, some
third-party plugins or disgruntled employees may lead to compromise of
the application and say the attacker was able to gain access to all the
passwords in the database.</p>
<p>When a user enters the password say &ldquo;admin123&rdquo; it is not a good practice
to store it as plain text. It must be hashed and stored.</p>
<div class="highlight"><pre tabindex="0" class="chroma"><code class="language-text" data-lang="text"><span class="line"><span class="cl">hash(admin123) = GX8N365FMeK9hsRkW9Dl2S/ikcQ
</span></span></code></pre></div><p>Now add salt to the above hash. Where salt does not need to be a secret
text but a random text. ( say &ldquo;<strong>5MU63YzoOm7ig</strong>&rdquo;)</p>
<p>The Hash + Salt will be displayed as shown below</p>
<div class="highlight"><pre tabindex="0" class="chroma"><code class="language-text" data-lang="text"><span class="line"><span class="cl">hash(admin123 + 5MU63YzoOm7ig ) = LL/0NIJmT2JcfCXkfOln62pj8Hw
</span></span></code></pre></div><p>The salted hashes make it much more difficult for attackers to crack the
passwords offline.</p>
<p>Even though the attackers have salted hashes, it would be tough for them
to crack and re-use them. Meanwhile, requesting the user to reset the
passwords in case of compromise makes it more secure.</p>
<h3 id="whitelisting">Whitelisting</h3>
<figure>
    <img loading="lazy" src="/icons/regulation.png"/> 
</figure>

<p>Whitelisting or Allowing a list is an approach of letting only what you
trust and blocking all the rest from accessing.</p>
<p>Let&rsquo;s say for high privileged admin user accounts, employ a way to
whitelist the login&rsquo;s from known IP addresses or authorized VPNs and
restrict all others from accessing admin features.</p>
<p>This reduces a huge attack surface.</p>
<h3 id="using-web-application-firewalls">Using Web application firewalls</h3>
<figure>
    <img loading="lazy" src="/icons/firewall.png"/> 
</figure>

<p>Configuring and using Web Application Firewalls (WAFs) protects web
applications from a wide range of attacks, such as brute force attacks,
denial of service attacks, and malicious input filtering, etc. Examples:
AWS WAF, Cloudflare WAF, etc.</p>
<p>More information on blocking brute force attacks can be found on the
<a href="https://owasp.org/www-community/controls/Blocking_Brute_Force_Attacks?ref=raghu.io">Blocking Brute Force Attacks OWASP
site</a>.</p>
<h2 id="conclusion">Conclusion</h2>
<p>Understanding the basics of brute-force attacks and their potential
impacts is crucial for safeguarding against cyber threats. By
implementing robust security measures, such as strong password policies,
multifactor authentication, and network monitoring, individuals and
organizations can mitigate the risk of falling victim to a brute-force
attack.</p>
<p>Using of captcha&rsquo;s can be inconvinient feature, but use it cautiously to
prevent automated bots or from automated attacks. Hope by this you are
familiar with what a brute force attack is and how it can be exploited.</p>
<p>Keep Learning!! 😄</p>
]]></content:encoded>
    </item>
    <item>
      <title>Mitigating XSS Vulnerability</title>
      <link>https://raghu.io/mitigating-xss-vulnerability/</link>
      <pubDate>Sat, 20 Aug 2022 04:30:12 +0000</pubDate>
      <guid>https://raghu.io/mitigating-xss-vulnerability/</guid>
      <description>Mitigation recommendations for Cross-Site Scripting Vulnerability</description>
      <content:encoded><![CDATA[<p>Cross-Site Scripting(XSS) is a serious security vulnerability. In short,
Attackers use this for a wide range of security attacks like stealing
user session cookies, redirecting all the users to a malicious website,
logging keystrokes of the victim&rsquo;s activity, defacing an organization&rsquo;s
website, even can use the victim system as a bots for malicious
activity, etc.</p>
<p>A single technique cannot mitigate XSS vulnerability completely. Using
the right defenses can help in preventing XSS attacks.</p>
<p>One of the best practices is &ldquo;<strong>Defense-In-Depth</strong>&rdquo;, Enabling multiple
layers of defense so even if a layer fails, other layers of protection
can minimize the impact of an XSS attack.</p>
<figure>
    <img loading="lazy" src="/icons/framework.png"/> 
</figure>

<h2 id="use-frameworks">Use Frameworks</h2>
<p>In modern development practices, developers like to code faster and
avoid recreating the wheel.</p>
<p>Rather than building applications from scratch, using the frameworks can
protect the application from lots of vulnerabilities. As security
features are in-built into frameworks and just need to enable.</p>
<p>For example input validation checks, XSS prevention, preventing access
control issues, etc. (Some PHP frameworks include laravel,
CodeIgniter,etc.)</p>
<p>Additionally, these frameworks do address the security vulnerabilities
when discovered, all you need to ensure is that you are using the latest
version of the application framework.</p>
<figure>
    <img loading="lazy" src="/icons/quality-control.png"/> 
</figure>

<h2 id="validate-client-data">Validate Client Data</h2>
<p>One of the most crucial steps is to validate each and every input
received from the client.</p>
<p>As we have demonstrated throughout our articles, any data coming from
the client side can be modified with the help of intercepting proxies.</p>
<p>For the same reason, each and every piece of data coming from the client
must be validated then must follow through next steps of verification.
<img loading="lazy" src="/icons/decode.png"></p>
<h2 id="output-encoding">Output Encoding</h2>
<p>Output encoding is one of the techniques used to take user-controlled
data and safely display it without interpreting it as code, and
considering it as text.</p>
<p>Below is an example XSS payload.</p>
<div class="highlight"><pre tabindex="0" class="chroma"><code class="language-text" data-lang="text"><span class="line"><span class="cl">&lt;script&gt;alert(document.domain);&lt;/script&gt;
</span></span></code></pre></div><p>HTML-encoded text of XSS payload will be displayed as shown below.</p>
<div class="highlight"><pre tabindex="0" class="chroma"><code class="language-text" data-lang="text"><span class="line"><span class="cl">&amp;lt;script&amp;gt;alert(document.domain);&amp;lt;/script&amp;gt;
</span></span></code></pre></div><ul>
<li>&ldquo;&lt;&rdquo; changed to &ldquo;&lt;&rdquo;</li>
<li>&ldquo;&gt;&rdquo; changed to &ldquo;&gt;&rdquo;</li>
</ul>
<p>As the browser parses HTML, JavaScript, CSS, and URL differently. Each
much be encoded depending on the requirements.</p>
<p>Another good example in PHP, the &ldquo;<strong>htmlspecialchars</strong>&rdquo; function will
convert the &ldquo;<strong>&lt;</strong>&rdquo; less than, &ldquo;<strong>&gt;</strong>&rdquo; greater than symbols to HTML
entities such as &ldquo;<strong><code>&amp;lt;</code></strong>&rdquo; for less than, &ldquo;<strong><code>&amp;gt;</code></strong>&rdquo; for greater
than respectively. This again makes the application treat all as text
without breaking the syntax.</p>
<p>URL, HTML, JavaScript, and CSS can be encoded.</p>
<figure>
    <img loading="lazy" src="/icons/input.png"/> 
</figure>

<h2 id="sanitization">Sanitization</h2>
<p>In some cases, the users need to retain HTML code as it is. In this
case, the output encoding will break the document structure.</p>
<p>To retain the data as it is, the sanitization technique is used.</p>
<p>As part of the sanitization, it produced a new HTML document that
contains only the &ldquo;safe&rdquo; or allowed HTML tags. This prevents XSS, this
is performed in combination with the whitelist and blacklist approach.</p>
<p>Example, In PHP we used a
&ldquo;<a href="https://www.php.net/manual/en/function.strip-tags.php?ref=raghu.io">strip_tags</a>&rdquo;
function is used to filter out all the HTML tags, the
&ldquo;<a href="https://www.php.net/manual/en/function.addslashes?ref=raghu.io">addslashes</a>&rdquo;
function escapes the special chars like a quote, and a double quote with
backward slashes to retain it as text without breaking code syntax.</p>
<figure>
    <img loading="lazy" src="/icons/headers.png"/> 
</figure>

<h2 id="xss-header">XSS Header</h2>
<p>The <strong>X-XSS-Protection</strong> response header is one of the features used to
prevent the reflected XSS from executing.</p>
<p>Below is an example of enabling the XSS protection header by completely
blocking script execution.</p>
<div class="highlight"><pre tabindex="0" class="chroma"><code class="language-http" data-lang="http"><span class="line"><span class="cl"><span class="err">X-XSS-Protection: 1; mode=block
</span></span></span></code></pre></div><p>The following can be ignored if the strongly protected
&ldquo;<strong>Content-Security-Policy</strong>&rdquo; is being used.</p>
<h3 id="httponly---cookie-attribute">HTTPOnly - Cookie Attribute</h3>
<p>This is another cookie flag that helps in reducing the XSS impact.
Enabling the &ldquo;<strong>HTTPOnly</strong>&rdquo; flag for session cookies can prevent the
javascript code from accessing it.</p>
<h3 id="content-type">Content-Type</h3>
<p><strong>Content-Type</strong> is one of the response headers which specifies the type
of content delivered. It is recommended to set the script content to
&ldquo;<strong>application/json</strong>&rdquo; than &ldquo;text/html&rdquo;</p>
<div class="highlight"><pre tabindex="0" class="chroma"><code class="language-http" data-lang="http"><span class="line"><span class="cl"><span class="err">Content-Type: application/json
</span></span></span></code></pre></div><p>Setting the content type to &ldquo;<strong>application/json</strong>&rdquo; prevents the
execution of script tags. <img loading="lazy" src="/icons/compliant.png"></p>
<h2 id="content-security-policy-csp">Content Security Policy (CSP)</h2>
<p>Content Security Policy is an added layer of security protection. This
helps in detecting and mitigating the XSS and other code injection
attacks.</p>
<p>CSP instructs the browser on how to deal with the content. On
CSP-enabled websites, it becomes very hard to exploit the XSS
vulnerability.</p>
<p>A <strong>Content-Security-Policy</strong> header is appended by the server with
policy configuration.</p>
<div class="highlight"><pre tabindex="0" class="chroma"><code class="language-text" data-lang="text"><span class="line"><span class="cl">Content-Security-Policy: default-src &#39;self&#39;; img-src *; script-src userscripts.example.com
</span></span></code></pre></div><p>Above is an
<a href="https://developer.mozilla.org/en-US/docs/Web/HTTP/CSP?ref=raghu.io">example</a>
of CSP, instructing the browser to permit only content from the same
site, images from anywhere, and execute scripts only from
&ldquo;userscripts.example.com&rdquo; <img loading="lazy" src="/icons/regulation.png"></p>
<h2 id="whitelisting-rather-blacklisting">Whitelisting rather Blacklisting</h2>
<p>Whitelisting or allowing a known good is an approach of letting only
what you trust and rejecting all the rest.</p>
<p>Whitelist is one of the supporting steps adding to all the above defense
layers. Even in the case of unknown payloads as well whitelist defends
well.</p>
<p>Let&rsquo;s say allowing the trusted characters upper case, small case
letters, numerics, and some special characters based on need.</p>
<p>Limit usage of the blacklist only for reasonable business requirements.</p>
<figure>
    <img loading="lazy" src="/icons/firewall.png"/> 
</figure>

<h2 id="use-web-application-firewalls-wafs">Use Web Application Firewalls (WAFs)</h2>
<p>Configuring and using Web Application Firewalls, protects web
applications from a wide range of attacks like XSS, Brute Force attacks,
Denial of Service attacks, Malicious input filtering, etc. a lot more.</p>
<p>Say AWS WAF, Cloudflare WAF, etc.</p>
<h2 id="additional-references">Additional References:</h2>
<p>More information on mitigating XSS attacks can be found on the OWASP
site.</p>
<ul>
<li><a href="https://cheatsheetseries.owasp.org/cheatsheets/Cross_Site_Scripting_Prevention_Cheat_Sheet.html?ref=raghu.io">Cross Site Scripting Prevention - OWASP Cheat
Sheet</a></li>
<li><a href="https://cheatsheetseries.owasp.org/cheatsheets/DOM_based_XSS_Prevention_Cheat_Sheet.html?ref=raghu.io">DOM based XSS Prevention - OWASP Cheat
Sheet</a></li>
</ul>
]]></content:encoded>
    </item>
    <item>
      <title>Mitigating Command Injection</title>
      <link>https://raghu.io/mitigating-command-injection/</link>
      <pubDate>Wed, 10 Aug 2022 09:47:10 +0000</pubDate>
      <guid>https://raghu.io/mitigating-command-injection/</guid>
      <description>Mitigation Recommendations for Command Injection Vulnerability</description>
      <content:encoded><![CDATA[<p>In this post, we will be covering the ways available to mitigate the
command injection vulnerability.</p>
<p>Firstly, we will go through the standard practices that are generally
used for mitigating the command injection vulnerabilities, followed by
we will be covering how the vulnerability has been fixed in the DVWA
application.</p>
<figure>
    <img loading="lazy" src="/icons/firewall1.png"/> 
</figure>

<h2 id="avoid-calling-os-command-directly">Avoid Calling OS Command Directly</h2>
<p>One of the most effective ways is to avoid calling all the system
commands directly by taking from the user input.</p>
<p>Using the <strong>built-in library functions</strong> is a good option, as it
performs the tasks intended without tampering.</p>
<p>In our command injection examples, the application takes the domain
name, and IP address then followed by we could append the additional
system commands. The application doesn&rsquo;t filter and is directly passed
on to the server for execution.</p>
<p>If you were able to view the source code, the
&ldquo;<strong>shell_exec()</strong>&rdquo; function in PHP is being used for taking
all our user inputs and passing them to the server.</p>
<div class="highlight"><pre tabindex="0" class="chroma"><code class="language-bash" data-lang="bash"><span class="line"><span class="cl">shell_exec<span class="o">(</span> <span class="s1">&#39;ping -c 4&#39;</span> . USER_INPUT <span class="o">)</span><span class="p">;</span>
</span></span></code></pre></div><p>The <strong>escapeshellcmd()</strong> or <strong>escapeshellarg()</strong> can be used instead of
&ldquo;<strong>shell_exec()</strong>&rdquo; to prevent command injection. What it does
is, it passes everything within a single quote ensuring to run all of
one text rather than breaking it into multiple commands.</p>
<p>If you think, in your current scenario you can not avoid it but that&rsquo;s
the only way to go ahead. then there are other ways to mitigate it.
<img loading="lazy" src="/icons/regulation.png"></p>
<h2 id="whitelisting">Whitelisting</h2>
<p>As we covered whitelisting earlier. Whitelisting is an approach of
letting only what you trust and rejecting all the unknown.</p>
<ul>
<li>Allowing only the valid characters, like small case letters, upper
case letters, and numerics.</li>
<li>Limiting only the special characters which are supposed to be used.
(say, allow period &ldquo;.&rdquo; and reject all)</li>
<li>Only allowing the system command that the user is supposed to use.</li>
</ul>
<p>In the command injection &ldquo;<strong>high</strong>&rdquo; example, we say the blacklisting is
being used to filter a lot of characters, where the &lsquo;<strong>|</strong>&rsquo; <strong>OR</strong> and
<strong>SPACE</strong> operator are being filtered than of &ldquo;<strong>|</strong>&rdquo; only OR operator.</p>
<p>Blacklisting can be used but is more of an error-prone approach.</p>
<figure>
    <img loading="lazy" src="/icons/input.png"/> 
</figure>

<h2 id="strong-input-validation">Strong Input Validation</h2>
<p>Validating the inputs in conjunction with whitelisting provides a strong
defense.</p>
<p>Treating every input from the client can be tampered with, verifying the
inputs and ensuring it is clean from all types of malicious payloads.</p>
<p>A <strong>parameterization</strong> is an option where the command and the input data
can be segregated using a structured mechanism. This helps in quoting
the input data before processing.</p>
<p>Never escape the user input with metacharacters directly as it is more
error-prone.</p>
<p>Additionally, the <strong>Regular Expressions</strong> can also be used for filtering
the input before processing.</p>
<figure>
    <img loading="lazy" src="/icons/access.png"/> 
</figure>

<h2 id="least-privilege-user-account">Least Privilege User Account</h2>
<p>Use a user account with minimal privileges to execute the needed system
operations on the server rather than one having admin privileges.</p>
<figure>
    <img loading="lazy" src="/icons/bug.png"/> 
</figure>

<h2 id="command-injection---fix-dvwa">Command Injection - Fix (DVWA)</h2>
<p>Let&rsquo;s see how the vulnerability was fixed in the DVWA application.</p>
<p>Log into the DVWA application and set the security level to
&ldquo;<strong>Impossible</strong>&rdquo;.</p>
<p>Navigate to the &ldquo;<strong>Command Injection</strong>&rdquo; and click on the &ldquo;<strong>View
Source</strong>&rdquo; button at the bottom.</p>
<blockquote>
<p>Note, only the partial code is displayed below.</p>
</blockquote>
<div class="highlight"><pre tabindex="0" class="chroma"><code class="language-php" data-lang="php"><span class="line"><span class="cl"><span class="c1">// Split the IP into 4 octects
</span></span></span><span class="line"><span class="cl"><span class="nv">$octet</span> <span class="o">=</span> <span class="nx">explode</span><span class="p">(</span> <span class="s2">&#34;.&#34;</span><span class="p">,</span> <span class="nv">$target</span> <span class="p">);</span>
</span></span><span class="line"><span class="cl">
</span></span><span class="line"><span class="cl"><span class="c1">// Check IF each octet is an integer
</span></span></span><span class="line"><span class="cl">
</span></span><span class="line"><span class="cl"><span class="k">if</span><span class="p">(</span> <span class="p">(</span> <span class="nx">is_numeric</span><span class="p">(</span> <span class="nv">$octet</span><span class="p">[</span><span class="mi">0</span><span class="p">]</span> <span class="p">)</span> <span class="p">)</span> <span class="o">&amp;&amp;</span> <span class="p">(</span> <span class="nx">is_numeric</span><span class="p">(</span> <span class="nv">$octet</span><span class="p">[</span><span class="mi">1</span><span class="p">]</span> <span class="p">)</span> <span class="p">)</span> <span class="o">&amp;&amp;</span> <span class="p">(</span> <span class="nx">is_numeric</span><span class="p">(</span> <span class="nv">$octet</span><span class="p">[</span><span class="mi">2</span><span class="p">]</span> <span class="p">)</span> <span class="p">)</span> <span class="o">&amp;&amp;</span> <span class="p">(</span> <span class="nx">is_numeric</span><span class="p">(</span> <span class="nv">$octet</span><span class="p">[</span><span class="mi">3</span><span class="p">]</span> <span class="p">)</span> <span class="p">)</span> <span class="o">&amp;&amp;</span> <span class="p">(</span> <span class="nx">sizeof</span><span class="p">(</span> <span class="nv">$octet</span> <span class="p">)</span> <span class="o">==</span> <span class="mi">4</span> <span class="p">)</span> <span class="p">)</span> <span class="p">{</span>
</span></span><span class="line"><span class="cl">
</span></span><span class="line"><span class="cl">    <span class="c1">// If all 4 octets are int&#39;s put the IP back together.
</span></span></span><span class="line"><span class="cl">
</span></span><span class="line"><span class="cl">    <span class="nv">$target</span> <span class="o">=</span> <span class="nv">$octet</span><span class="p">[</span><span class="mi">0</span><span class="p">]</span> <span class="o">.</span> <span class="s1">&#39;.&#39;</span> <span class="o">.</span> <span class="nv">$octet</span><span class="p">[</span><span class="mi">1</span><span class="p">]</span> <span class="o">.</span> <span class="s1">&#39;.&#39;</span> <span class="o">.</span> <span class="nv">$octet</span><span class="p">[</span><span class="mi">2</span><span class="p">]</span> <span class="o">.</span> <span class="s1">&#39;.&#39;</span> <span class="o">.</span> <span class="nv">$octet</span><span class="p">[</span><span class="mi">3</span><span class="p">];</span>
</span></span><span class="line"><span class="cl">  <span class="c1">// Determine OS and execute the ping command.
</span></span></span></code></pre></div><p>Code Snippet 1: Command Injection - Mitigation</p>
<p>In the above screenshot, the developer now has removed all types of
blacklisting approaches and moved to a whitelist.</p>
<p>At the moment, only numeric IP addresses and a special character of a
dot are allowed and reject all the other input.</p>
<p>This reduces the attack surface to a greater extent for exploitation.</p>
<p>More information about the mitigation techniques can be found on the <a href="https://cheatsheetseries.owasp.org/cheatsheets/OS_Command_Injection_Defense_Cheat_Sheet.html?ref=raghu.io">OS
Command Injection Defense - OWASP Cheat
Sheet.</a></p>
<p>I Hope, Now you can secure your web applications from the command
injection vulnerabilities. Thank you! :)</p>
]]></content:encoded>
    </item>
    <item>
      <title>DVWA Brute Force Attack - High Severity</title>
      <link>https://raghu.io/dvwa-brute-force-attack-high-severity/</link>
      <pubDate>Thu, 04 Aug 2022 11:44:26 +0000</pubDate>
      <guid>https://raghu.io/dvwa-brute-force-attack-high-severity/</guid>
      <description>This detailed post explains Brute-Force Attacks&amp;#39; High severity using DVWA and how improper security fixes can be bypassed. You can also explore a demo to understand the concept better and discover and optimize your attack with the BurpSuite tool.</description>
      <content:encoded><![CDATA[<p>This section will be a kind of recap of the Brute Force vulnerability
covered so far and some additional fine-tuning options available in the
BurpSuite tool.</p>
<h2 id="required-tool-set">Required Tool Set</h2>
<ol>
<li>A working DVWA docker image will be needed.</li>
<li>BurpSuite Community Edition tool.</li>
<li>Wordlists (username.txt and password.txt)</li>
</ol>
<p>If you are unable to follow any of the sections, refer back to the
earlier posts.</p>
<p><a href="/dvwa-brute-force-attack-and-prevention-explained/">DVWA - Brute Force Attack and Prevention
Explained</a>
This detailed guide explains Brute Force Attacks, how they work, and
ways to prevent them.</p>
<p><a href="/dvwa-brute-force-attack-medium-severity/">DVWA Brute Force Attack - Medium</a>
This detailed post explains Brute-Force Attacks&rsquo; Medium severity using
DVWA and how partial security fixes can be bypassed.</p>
<h2 id="dvwa-brute-force-vulnerability---demo">DVWA Brute Force Vulnerability - Demo</h2>
<p>Log into your DVWA environment, and click on the &ldquo;<strong>Security level</strong>&rdquo;
menu on the left sidebar.</p>
<p>Select &ldquo;<strong>High</strong>&rdquo; and click on the submit button, as shown below, to
ensure the Security Level is updated.</p>
<figure class="mx-auto block text-center">
    <img loading="lazy" src="Brute-Force-Security-Level-High.png"
         alt="Figure 1: Setting DVWA Security Level to High"/> <figcaption>
            <p>Figure 1: Setting DVWA Security Level to High</p>
        </figcaption>
</figure>

<h2 id="re-testing-scenario">Re-testing Scenario</h2>
<p>Imagine the development team returning again and informing you that the
vulnerability is fixed and needs re-verification.</p>
<p>Let&rsquo;s go ahead and repeat all the steps.</p>
<ol>
<li>Launch the BurpSuite Community Tool.</li>
<li>Navigate to the &ldquo;<strong>Proxy</strong>&rdquo; tab -&gt; &ldquo;<strong>Intercept</strong>&rdquo; sub-tab and
click on the &ldquo;<strong>Open Browser</strong>&rdquo;</li>
<li>Once the Chromium browser is launched, login to the DVWA application
using admin credentials.</li>
<li>Visit the &ldquo;<strong>Brute Force</strong>&rdquo; link in the menu.</li>
<li>Switch to the Burp Suite &ldquo;<strong>Proxy</strong>&rdquo; tab, select the &ldquo;<strong>Intercept</strong>&rdquo;
sub-tab, and toggle &ldquo;<strong>Intercept is Off</strong>&rdquo; to enable it.</li>
<li>Enter the random values in the username and password fields, then
click on &ldquo;<strong>Login</strong>&rdquo;.</li>
<li>The &ldquo;<strong>Intercept</strong>&rdquo; captured login request will be displayed below.</li>
</ol>
<figure class="mx-auto block text-center">
    <img loading="lazy" src="BruteForce-High-Request.png"
         alt="Figure 2: Brute Force Login Request - Security Level High"/> <figcaption>
            <p>Figure 2: Brute Force Login Request - Security Level High</p>
        </figcaption>
</figure>

<p>In line number 1, the test values are placed in the username and
password fields. In line 16, the security level parameter is set to
<strong>high</strong>.</p>
<p>Additionally, a new &ldquo;<strong>user_token</strong>&rdquo; is being passed in the
URL parameter compared to the previous requests.</p>
<p>A copy of the previous request is provided below.</p>
<figure class="mx-auto block text-center">
    <img loading="lazy" src="BruteForce-Login-Request-Medium.png"
         alt="Figure 3: Brute Force Login Request - Security Level Medium"/> <figcaption>
            <p>Figure 3: Brute Force Login Request - Security Level Medium</p>
        </figcaption>
</figure>

<ol>
<li>
<p>Click on the &ldquo;<strong>Action</strong>&rdquo; button or <strong>right-click</strong> and select
&ldquo;<strong>Send to the Intruder</strong>&rdquo;.</p>
</li>
<li>
<p>In payload positions, &ldquo;<strong>Clear</strong>&rdquo; all the selected payload
placeholders and then select the &ldquo;<strong>Username</strong>&rdquo; value field and the
&ldquo;<strong>Password</strong>&rdquo; value field by clicking the &ldquo;<strong>Add</strong>&rdquo; button for
placing custom payloads.</p>
</li>
</ol>
<figure>
    <img loading="lazy" src="BurpSuite-Intruder-Brute-Force-High.png"/> 
</figure>

<p>Choose the attack type to &ldquo;<strong>Cluster bomb</strong>&rdquo;</p>
<p>The same word list of common usernames and passwords can be used for the
current scenario. Save the text files onto your system or use copy-paste
to load the information in the payloads tab.</p>
<p><strong>usernames.txt</strong></p>
<div class="highlight"><pre tabindex="0" class="chroma"><code class="language-text" data-lang="text"><span class="line"><span class="cl">admin
</span></span><span class="line"><span class="cl">administrator
</span></span><span class="line"><span class="cl">user
</span></span><span class="line"><span class="cl">john
</span></span><span class="line"><span class="cl">dvwa
</span></span><span class="line"><span class="cl">bob
</span></span><span class="line"><span class="cl">alice
</span></span><span class="line"><span class="cl">root
</span></span><span class="line"><span class="cl">superuser
</span></span><span class="line"><span class="cl">super
</span></span></code></pre></div><p><strong>passwords.txt</strong></p>
<div class="highlight"><pre tabindex="0" class="chroma"><code class="language-text" data-lang="text"><span class="line"><span class="cl">admin
</span></span><span class="line"><span class="cl">admin123
</span></span><span class="line"><span class="cl">password
</span></span><span class="line"><span class="cl">password123
</span></span><span class="line"><span class="cl">user
</span></span><span class="line"><span class="cl">user123
</span></span><span class="line"><span class="cl">administrator
</span></span><span class="line"><span class="cl">passw0rd
</span></span><span class="line"><span class="cl">r3m3mb3rM3
</span></span><span class="line"><span class="cl">admin123$
</span></span></code></pre></div><p>In the &ldquo;<strong>Payloads</strong>&rdquo; sub-tab, select &ldquo;<strong>Payload Set 1</strong>&rdquo;, set the
payload type as &ldquo;<strong>simple list</strong>&rdquo;, and paste all the contents in
<strong>payload options</strong> copied from the <strong>usernames.txt</strong> list.</p>
<p>Second, select the &ldquo;<strong>Payloads</strong>&rdquo; sub-tab, set &ldquo;<strong>Payload Set 2</strong>&rdquo;, set
the payload type as &ldquo;<strong>simple list</strong>&rdquo; and paste all the contents in
payload options copied from the <strong>passwords.txt</strong> list.</p>
<p>Switch to the &ldquo;<strong>Options</strong>&rdquo; sub-tab and enable the &ldquo;<strong>Grep - Match</strong>&rdquo;
with the &ldquo;<strong>incorrect</strong>&rdquo; string. so we can understand which requests
have failed.</p>
<figure class="mx-auto block text-center">
    <img loading="lazy" src="Intruder-Grep-Match-Incorrect.png"
         alt="Figure 4: Intruder Grep Match - Incorrect string"/> <figcaption>
            <p>Figure 4: Intruder Grep Match - Incorrect string</p>
        </figcaption>
</figure>

<p>Lastly, click on &ldquo;<strong>Start Attack</strong>&rdquo; and monitor the results.</p>
<figure>
    <img loading="lazy" src="Brute-Force-Intuder-Start-Attack-High.png"/> 
</figure>

<h3 id="failed-intruder-attack-results">Failed Intruder Attack Results</h3>
<figure>
    <img loading="lazy" src="Brute-Force-Intruder-Failed-Results.png"/> 
</figure>

<p>Only in one response was the &ldquo;username and/or password incorrect&rdquo; string
found.</p>
<p>For all other requests, we are getting &ldquo;<strong>302</strong>&rdquo; status codes instead of
&ldquo;<strong>200 OK</strong>&rdquo;, which means something is not working and our brute force
attack is failing.</p>
<p>Now, shall we assume that the &ldquo;<strong>Vulnerability is fixed</strong>&rdquo; and close the
security flaw?</p>
<figure>
    <img loading="lazy" src="/icons/thinking.png"/> 
</figure>

<p>Well, we can close it. But this is a strange scenario in which we don&rsquo;t
see errors or warnings.</p>
<p>Let&rsquo;s analyze more thoroughly and see what exactly is happening here.
and why we are getting &ldquo;<strong>302 Found</strong>&rdquo; redirects.</p>
<blockquote>
<p>Remember, you can automate only if application behaviour is
consistent.</p>
</blockquote>
<p>Re-submit the username and password with new random values on the Brute
Force login page and intercept the login request.</p>
<figure>
    <img loading="lazy" src="Brute-Force-Login-Request-High.png"/> 
</figure>

<p>Analyzing with the BurpSuite Tool without going to the browser gives us
more control over the HTTP messages. Therefore, I want to view the HTTP
response messages in the Burp Suite itself.</p>
<p>Let&rsquo;s enable the option to Intercept and view the &ldquo;<strong>Response</strong>&rdquo;
messages received from the server before sending them to the Browser.</p>
<p>Visit the &ldquo;<strong>Proxy</strong>&rdquo; tab -&gt; Select &ldquo;<strong>Options</strong>&rdquo; sub-tab, scroll down
to &ldquo;<strong>Intercept Server Responses</strong>&rdquo; and enable &ldquo;<strong>Intercept responses
based on the following rules</strong>&rdquo; as displayed below.</p>
<figure class="mx-auto block text-center">
    <img loading="lazy" src="BurpSuite-Enable-Intercept-Server-Response.png"
         alt="Figure 5: BurpSuite Proxy - Enable Intercept Server Responses"/> <figcaption>
            <p>Figure 5: BurpSuite Proxy - Enable Intercept Server Responses</p>
        </figcaption>
</figure>

<p>Switch to the &ldquo;<strong>Intercept</strong>&rdquo; sub-tab under the &ldquo;<strong>Proxy</strong>&rdquo; tab and
click on the &ldquo;<strong>Forward</strong>&rdquo; button.</p>
<p>The &ldquo;<strong>Forward</strong>&rdquo; button will send the request to the server and now
start &ldquo;<strong>Intercept</strong>&rdquo; immediate HTTP &ldquo;<strong>Response</strong>&rdquo; received from the
server and display it as shown below.</p>
<figure>
    <img loading="lazy" src="BruteForce-Intruder-Response.png"/> 
</figure>

<p>By clicking on the &ldquo;<strong>Forward</strong>&rdquo; button again, the response is now sent
to the browser.</p>
<p>Toggle the proxy &ldquo;<strong>Intercept is on</strong>&rdquo; to disable it.</p>
<p>Use the BurpSuite &ldquo;Chromium browser&rdquo; session, manually try for random
username/passwords say &ldquo;<strong>administrator/admin123</strong>&rdquo;,
&ldquo;<strong>admin/admin123</strong>&rdquo;, &ldquo;<strong>user/user123</strong>&rdquo; etc.. with 4 or 5 incorrect
credentials.</p>
<p>For all incorrect attempts, we keep getting the &ldquo;<strong>Username and/or
password incorrect.</strong>&rdquo; message.</p>
<p>This confirms that the &ldquo;<strong>Brute Force</strong>&rdquo; attack still does exist, which
means the Vulnerability remains Open. Yay!!. :)
<img loading="lazy" src="/icons/success.png"></p>
<p>Now the question is, why is our <strong>Intruder</strong> tool unable to pick it up?</p>
<p>Let&rsquo;s review all the previous HTTP messages and see if we can find any
patterns.</p>
<p>The Burp Suite HTTP message history can be found under the &ldquo;<strong>Proxy</strong>&rdquo;
tab -&gt; &ldquo;<strong>HTTP history</strong>&rdquo; sub-tab.</p>
<figure class="mx-auto block text-center">
    <img loading="lazy" src="BurpSuite-Proxy-HTTP-History.png"
         alt="Figure 6: BurpSuite HTTP History"/> <figcaption>
            <p>Figure 6: BurpSuite HTTP History</p>
        </figcaption>
</figure>

<p>Observing the HTTP GET requests that we have manually tried, the
username and password values are being passed, but one parameter value
keeps on changing in the &ldquo;<strong>URL</strong>&rdquo; section.</p>
<p>Remember a new parameter is being passed on the Login request? Yes,
&ldquo;<strong>user_token</strong>&rdquo;.</p>
<figure>
    <img loading="lazy" src="/icons/idea.png"/> 
</figure>

<p>The &ldquo;<strong>user_token</strong>&rdquo; keeps updating for each request.
Therefore, we cannot use the same &ldquo;user_token&rdquo; for all HTTP
requests.</p>
<p>This is the reason our tool fails. If we perform brute force manually,
<strong>it works!</strong></p>
<h3 id="finding-the-origin-of-user_token">Finding the origin of &ldquo;user_token&rdquo;</h3>
<p>Let&rsquo;s find out from where the &ldquo;<strong>user_token</strong>&rdquo; is being set
and updated.</p>
<p>In the case of HTTP, it can be set in Headers, Response Bodies, or
Cookies. Let&rsquo;s review the HTTP responses received one by one.</p>
<figure class="mx-auto block text-center">
    <img loading="lazy" src="Brute-Force-Response-User-Token.png"
         alt="Figure 7: Finding User Token"/> <figcaption>
            <p>Figure 7: Finding User Token</p>
        </figcaption>
</figure>

<p>After a thorough review Of one of the requests from <strong>HTTP history</strong>, I
was able to find out it is being set in &ldquo;<strong>HTTP Response Body</strong>&rdquo;</p>
<div class="highlight"><pre tabindex="0" class="chroma"><code class="language-html" data-lang="html"><span class="line"><span class="cl"><span class="p">&lt;</span><span class="nt">input</span> <span class="na">type</span><span class="o">=</span><span class="s">&#39;hidden&#39;</span> <span class="na">name</span><span class="o">=</span><span class="s">&#39;user_token&#39;</span> <span class="na">value</span><span class="o">=</span><span class="s">&#39;90f9f7a06213b032dbe9e5d1d4717ce0&#39;</span> <span class="p">/&gt;</span>
</span></span></code></pre></div><p>The code is a simple HTML tag that is hidden in the background of the
&ldquo;Login&rdquo; page and passed every time when the user submits &ldquo;<strong>username</strong>&rdquo;
and &ldquo;<strong>password</strong>&rdquo; credentials.</p>
<p>Based on the above request, the HTML input tag is dynamically generated
on the fly with an updated &ldquo;<strong>user_token</strong>&rdquo;.</p>
<p>We found the source! Can you automate it with Burp Intruder? <strong>Yes</strong></p>
<p>One more important point to discuss before we proceed.
<img loading="lazy" src="/icons/process.png"></p>
<h2 id="choosing-the-intruder-attack-type">Choosing the Intruder Attack Type</h2>
<p>Guess what the attack type could be here?</p>
<p>Cluster Bomb? <strong>NO</strong></p>
<figure class="mx-auto block text-center">
    <img loading="lazy" src="Pitch-Fork--Cluster-Bomb.png"
         alt="Figure 8: Pitchfork vs Cluster Bomb"/> <figcaption>
            <p>Figure 8: Pitchfork vs Cluster Bomb</p>
        </figcaption>
</figure>

<p>Remember what the &ldquo;<strong>Cluster bomb</strong>&rdquo; does? It tries out all possible
permutations and combinations by varying the first &ldquo;<strong>Payload 1</strong>&rdquo; and
keeping the &ldquo;<strong>Payload 2</strong>&rdquo; standard, then jumps to the next
permutation.</p>
<blockquote>
<p>A big challenge here is, you cannot keep the
&ldquo;<strong>user_token</strong>&rdquo; same for multiple requests.</p>
</blockquote>
<p>Therefore, the &ldquo;cluster bomb&rdquo; doesn&rsquo;t meet our requirements.</p>
<h3 id="what-about-pitchfork">What about &ldquo;Pitchfork&rdquo;?</h3>
<p>Yes, the &ldquo;<strong>Pitchfork</strong>&rdquo; option helps in the current scenario. Takes the
first payload from &ldquo;<strong>Payload set 1</strong>&rdquo; and the first payload from
&ldquo;<strong>Payload set 2</strong>&rdquo; and then iterates through.</p>
<p>Overall, our current wordlist of <strong>usernames</strong> and <strong>passwords</strong>
generates only 10 possible payload requests, as shown below.</p>
<p>We could definitely miss our valid combination match. i.e.,
&ldquo;<strong>admin/password</strong>&rdquo;.</p>
<p>So, to brute force from here on, we need to use the username, which
definitely exists on the server. (say &ldquo;<strong>admin</strong>&rdquo;)</p>
<p>The DVWA dev team gave us a good challenge. Let&rsquo;s put in additional
efforts to perform the Brute Force attack.</p>
<h2 id="fine-tuning-the-intruder-payload">Fine-tuning the Intruder Payload</h2>
<p>Repeat all the steps from step 1 to step 7 mentioned above, from the
launching of the BurpSuite to sending the new log-in request to the
intruder.</p>
<blockquote>
<p>Use a completely new intercepted Login request, else intruder is bound
to fail.</p>
</blockquote>
<figure>
    <img loading="lazy" src="Brute-Force-Intruder-Select-Payloads-Custom.png"/> 
</figure>

<p>Choose the &ldquo;<strong>Pitchfork</strong>&rdquo; attack type and select two payload positions.
i.e. <em>password</em> value field and <strong>user_token</strong> value field
as displayed above.</p>
<p>This time for payloads, the first position will be of the password value
field and the second position will be of the user_token value
field.</p>
<p>Select the &ldquo;<strong>Payloads</strong>&rdquo; sub-tab, set &ldquo;Payload Set <strong>1</strong>&rdquo;, payload type
as &ldquo;<strong>simple list</strong>&rdquo; and paste the <strong>passwords.txt</strong> list contents into
payload options.</p>
<p>Second, select the &ldquo;<strong>Payloads</strong>&rdquo; sub-tab, set &ldquo;Payload Set <strong>2</strong>&rdquo;, and
payload type as &ldquo;<strong>recursive grep</strong>&rdquo; from the list. This is for the
&ldquo;<strong>user_token</strong>&rdquo; field.</p>
<figure>
    <img loading="lazy" src="Brute-Force-Intruder-Recursive-Grep-Payload.png"/> 
</figure>

<p>The &ldquo;<strong>recursive grep</strong>&rdquo; is used when you want to extract specific data
from the previous response and use it in the request as a payload.</p>
<p>The &ldquo;<strong>Grep - Extract</strong>&rdquo; feature is used to find specific strings based
on the pattern or use regular expressions to get useful information from
the HTTP response.</p>
<figure class="mx-auto block text-center">
    <img loading="lazy" src="Grep-Extract.png"
         alt="Figure 9: Grep Extract - Add"/> <figcaption>
            <p>Figure 9: Grep Extract - Add</p>
        </figcaption>
</figure>

<p>Next, go to the &ldquo;<strong>Intruder</strong>&rdquo; tab -&gt; &ldquo;<strong>Options</strong>&rdquo; sub-tab, scroll
down to &ldquo;<strong>Grep Extract</strong>&rdquo; and click on the &ldquo;<strong>Add</strong>&rdquo; button.</p>
<p>A new window named &ldquo;Define extract grep item&rdquo; is loaded.</p>
<p>In the &ldquo;<strong>Define extract grep item</strong>&rdquo; window, click on the &ldquo;<strong>Fetch
Response</strong>&rdquo; button on the right side.</p>
<figure>
    <img loading="lazy" src="Brute-Force-Intruder-Fetch-Response.png"/> 
</figure>

<p>The &ldquo;<strong>Fetch response</strong>&rdquo; will take the currently configured request in
the &ldquo;<strong>fetch</strong>&rdquo; tab and fetch, the server response for it.</p>
<p>Once the HTTP response is loaded, Using the mouse select the
user_token value then select only the value string highlighted
as shown below.</p>
<figure>
    <img loading="lazy" src="Grep-Extract-Copy-Brute-Force-Payload.png"/> 
</figure>

<p>The &ldquo;<strong>Start after expression</strong>&rdquo; and &ldquo;<strong>End at delimiter</strong>&rdquo; values will
be auto-populated. Just click on the &ldquo;<strong>OK</strong>&rdquo; button to proceed.</p>
<figure>
    <img loading="lazy" src="Grep-Extract-Brute-Force-Pitchfork.png"/> 
</figure>

<p>Use &ldquo;<strong>Ctrl - c</strong>&rdquo; to copy the token value
&ldquo;<strong>1802dab0e42ee4ef48e71d491981abb1</strong>&rdquo; will be used for updating initial
payload.</p>
<p>Switch back to the Intruder Payloads section. Observe the &ldquo;<strong>Grep
Extract</strong>&rdquo; pattern updated and displayed in &ldquo;Payload Options&rdquo;.</p>
<figure>
    <img loading="lazy" src="Brute-Force-Intruder-Payload-Set-2.png"/> 
</figure>

<p>Now, set the &ldquo;<strong>initial payload for first request</strong>&rdquo; value as the one we
copied earlier, the latest token &ldquo;<strong>1802dab0e42ee4ef48e71d491981abb1</strong>&rdquo;.</p>
<p>All set, but there is one more thing to do.</p>
<blockquote>
<p>Remember, a new user_user token can be fetched only when you
send each request one by one after updating. If thrown multiple
concurrent requests at once than we can&rsquo;t get correct user token in
sequence.</p>
</blockquote>
<p>In the &ldquo;Intruder&rdquo; tab &ldquo;<strong>Resource Pool</strong>&rdquo; is a place where we can
fine-tune the number of threads to use or delay between requests etc.</p>
<p>Navigate to the &ldquo;<strong>Intruder</strong>&rdquo; tab and select the &ldquo;<strong>Resource Pool</strong>&rdquo;
sub-tab. Select &ldquo;<strong>Create new resource pool</strong>&rdquo; named &ldquo;Brute Force
Attack - High&rdquo;.</p>
<figure>
    <img loading="lazy" src="Brute-Force-Intruder-Resource-Pool-Set.png"/> 
</figure>

<p>Set the &ldquo;<strong>Maximum concurrent requests</strong>&rdquo; to <strong>1</strong>.</p>
<p>Done, we have configured our intruder and now click to &ldquo;<strong>Start
attack</strong>&rdquo; button.</p>
<figure>
    <img loading="lazy" src="Brute-Force-Intruder-Attack-Summary-High.png"/> 
</figure>

<p><strong>Wow!! finally accomplished</strong>. 😄</p>
<p>The intruder configuration works, and we no longer see the &ldquo;<strong>302
Found</strong>&rdquo; redirect status codes being displayed.</p>
<p>Observe the user_token value taken from the previous response
field, displayed under the &ldquo;value&rdquo; row and updated in the request as the
&ldquo;Payload 2&rdquo;. The fine-tuning worked!</p>
<p>Let&rsquo;s check the one with of different length &ldquo;<strong>4792</strong>&rdquo; and Yes, We
found our credentials match (<strong>admin/password</strong>).</p>
<p>The &ldquo;<strong>Grep - Match</strong>&rdquo; flags can also be enabled.</p>
<p><strong>Well done!!</strong> 🎉</p>
<p>Thus, the Brute force vulnerability still remains open.</p>
<p>We have covered a lot of ground here to exploit the Brute Force attack.
Re-visit the article and keep practicing until you become familiar with
it.</p>
<p>Check out the below article to learn more about prevention techniques.</p>
<p><a href="/dvwa-brute-force-attack-and-prevention-explained/">DVWA - Brute Force Attack and Prevention
Explained</a></p>
]]></content:encoded>
    </item>
    <item>
      <title>DVWA Brute Force Attack - Medium Severity</title>
      <link>https://raghu.io/dvwa-brute-force-attack-medium-severity/</link>
      <pubDate>Wed, 03 Aug 2022 06:22:22 +0000</pubDate>
      <guid>https://raghu.io/dvwa-brute-force-attack-medium-severity/</guid>
      <description>This detailed post explains Brute-Force Attacks&amp;#39; Medium severity using DVWA and how partial security fixes can be bypassed. You can also explore a demo to better understand the concept and discover and optimize your attack with the BurpSuite tool.</description>
      <content:encoded><![CDATA[<p>I hope you are familiar with brute-force attacks by now.</p>
<p>In the current section, we will explore a bit more about the Brute Force
attack and options available in the BurpSuite tool for effectively
identifying successful brute-force attempts.</p>
<p>If you haven&rsquo;t read the previous article about the Brute Force attack,
feel free to refer to the bookmark below.</p>
<p><a href="/dvwa-brute-force-attack-and-prevention-explained/">DVWA - Brute Force Attack and Prevention
Explained</a></p>
<h2 id="dvwa-brute-force-vulnerability---demo">DVWA Brute Force Vulnerability - Demo</h2>
<p>Imagine we found a vulnerability and reported it to the DVWA development
team. The team reverted, claiming the security flaw was fixed.</p>
<blockquote>
<p>Trust but Verify</p>
</blockquote>
<p>It is always a good practice to re-verify and ensure that the
vulnerability is mitigated as per best practices. Let&rsquo;s verify.</p>
<p>Log into the DVWA application. In the sidebar, scroll to the bottom of
the page and click on &ldquo;<strong>DVWA Security</strong>&rdquo;. A page will load as shown
below.</p>
<figure class="mx-auto block text-center">
    <img loading="lazy" src="DVWA_SecurityLevel_Medium.png"
         alt="Figure 1: Choosing DVWA Security Level to Medium"/> <figcaption>
            <p>Figure 1: Choosing DVWA Security Level to Medium</p>
        </figcaption>
</figure>

<p>Set the security level to &ldquo;<strong>Medium</strong>&rdquo; and click on the <strong>Submit</strong>
button. Ensure it is updated and displayed on the left side at the
bottom of the page.</p>
<p>Launch the BurpSuite tool, navigate to the &ldquo;<strong>Proxy</strong>&rdquo; tab, and click on
the &ldquo;<strong>Open Browser</strong>&rdquo; button.</p>
<p>Visit the DVWA application, Select the &ldquo;<strong>Brute Force</strong>&rdquo; vulnerability,
and then enter any random credentials as discussed in the previous
article.</p>
<p>Enable the intercept option and capture the login request displayed, as
shown below. Observe that the security parameter value is set to
<strong>medium</strong> in line 16.</p>
<figure class="mx-auto block text-center">
    <img loading="lazy" src="BruteForce-Login-Request-Medium.png"
         alt="Figure 2: Brute Force Login Reqest Medium"/> <figcaption>
            <p>Figure 2: Brute Force Login Reqest Medium</p>
        </figcaption>
</figure>

<p>Similar to the previous lesson, click on &ldquo;<strong>Action</strong>&rdquo; and select &ldquo;<strong>Send
to Intruder</strong>&rdquo;. Set the attack type to &ldquo;<strong>Cluster bomb</strong>&rdquo;, clear all
fields, and add only the username and password value fields for
inserting custom payloads.</p>
<figure class="mx-auto block text-center">
    <img loading="lazy" src="BruteForce-Intruder-Position-Slection-Medium.png"
         alt="Figure 3: The intruder with a user athentication request"/> <figcaption>
            <p>Figure 3: The intruder with a user athentication request</p>
        </figcaption>
</figure>

<p>For the current scenario, we will use the same Word list of common
usernames and passwords. Save the text files onto your system or use
copy-paste to load the information in the payloads tab.</p>
<p><strong>usernames.txt</strong></p>
<div class="highlight"><pre tabindex="0" class="chroma"><code class="language-text" data-lang="text"><span class="line"><span class="cl">admin
</span></span><span class="line"><span class="cl">administrator
</span></span><span class="line"><span class="cl">user
</span></span><span class="line"><span class="cl">john
</span></span><span class="line"><span class="cl">dvwa
</span></span><span class="line"><span class="cl">bob
</span></span><span class="line"><span class="cl">alice
</span></span><span class="line"><span class="cl">root
</span></span><span class="line"><span class="cl">superuser
</span></span><span class="line"><span class="cl">super
</span></span></code></pre></div><p><strong>passwords.txt</strong></p>
<div class="highlight"><pre tabindex="0" class="chroma"><code class="language-text" data-lang="text"><span class="line"><span class="cl">admin
</span></span><span class="line"><span class="cl">admin123
</span></span><span class="line"><span class="cl">password
</span></span><span class="line"><span class="cl">password123
</span></span><span class="line"><span class="cl">user
</span></span><span class="line"><span class="cl">user123
</span></span><span class="line"><span class="cl">administrator
</span></span><span class="line"><span class="cl">passw0rd
</span></span><span class="line"><span class="cl">r3m3mb3rM3
</span></span><span class="line"><span class="cl">admin123$
</span></span></code></pre></div><p>In the &ldquo;<strong>Payloads</strong>&rdquo; sub-tab, select &ldquo;<strong>Payload Set 1</strong>&rdquo;, payload type
as &ldquo;<strong>simple list</strong>&rdquo;, and paste all the contents in <strong>payload options</strong>
copied from the <strong>usernames.txt</strong> list. (For username values)</p>
<p>Second, select the &ldquo;<strong>Payloads</strong>&rdquo; sub-tab, set &ldquo;<strong>Payload Set 2</strong>&rdquo;, and
payload type as &ldquo;<strong>simple list</strong>&rdquo;, and paste all the contents in
<strong>payload options</strong> copied from the <strong>passwords.txt</strong> list. (For
password field values)</p>
<figure class="mx-auto block text-center">
    <img loading="lazy" src="BruteForce-Payload-Set-Medium.png"
         alt="Figure 4: Brute Force Attack - Intruder Payloads Set"/> <figcaption>
            <p>Figure 4: Brute Force Attack - Intruder Payloads Set</p>
        </figcaption>
</figure>

<p>The steps were similar to the previous one.</p>
<p>If you remember, in the previous Intruder attack summary, we needed to
go through each request, select the response message, and look out for
the message &ldquo;<strong>Username and/or password incorrect</strong>&rdquo;.</p>
<p>We earlier used the &ldquo;<strong>Length</strong>&rdquo; size option to drill down and focus on
the one with a different size.</p>
<p>The Intruder tool provides us with a better way to do it, called
&ldquo;<strong>Grep - Match</strong>&rdquo;, which helps us to find a specific string in the HTTP
response body using grep and flags it. A more suitable way to view the
results.</p>
<p>In the &ldquo;<strong>Intruder</strong>&rdquo; tab, click on the &ldquo;<strong>Options</strong>&rdquo; sub-tab and scroll
down to &ldquo;<strong>Grep - Match</strong>&rdquo;, then click on the &ldquo;<strong>Clear</strong>&rdquo; button.</p>
<figure class="mx-auto block text-center">
    <img loading="lazy" src="BruteForce-Intruder-Grep-Match-Clear.png"
         alt="Figure 5: Burp Suite Grep - Match"/> <figcaption>
            <p>Figure 5: Burp Suite Grep - Match</p>
        </figcaption>
</figure>

<p>If prompts for confirmation, click on &ldquo;<strong>Yes</strong>&rdquo; to clear.</p>
<figure class="mx-auto block text-center">
    <img loading="lazy" src="Intruder-Grep-Match-Clear.png"
         alt="Figure 6: Grep Match Clear Confirmation"/> <figcaption>
            <p>Figure 6: Grep Match Clear Confirmation</p>
        </figcaption>
</figure>

<p>In &ldquo;<strong>Grep-Match</strong>&rdquo;, type &ldquo;<strong>incorrect</strong>&rdquo; in a text area and click on
the &ldquo;<strong>Add</strong>&rdquo; button. This word is taken from the invalid user
credentials error message &ldquo;Username and/or password <strong>incorrect</strong>&rdquo;.</p>
<figure class="mx-auto block text-center">
    <img loading="lazy" src="Intruder-Grep-Match-Add-Incorrect.png"
         alt="Figure 7: Grep Match Custom String"/> <figcaption>
            <p>Figure 7: Grep Match Custom String</p>
        </figcaption>
</figure>

<p>Make sure &ldquo;<strong>Flag result items with responses matching these
expressions</strong>.&rdquo; is enabled and confirm &ldquo;<strong>incorrect</strong>&rdquo; string is added.</p>
<figure class="mx-auto block text-center">
    <img loading="lazy" src="Intruder-Grep-Match-Incorrect.png"
         alt="Figure 8: Grep Match for &ldquo;Incorrect&rdquo; string"/> <figcaption>
            <p>Figure 8: Grep Match for &ldquo;Incorrect&rdquo; string</p>
        </figcaption>
</figure>

<p>Match type &ldquo;<strong>Simple string</strong>&rdquo; suffixed our current requirement.</p>
<p>Finally, click on the &ldquo;<strong>Start attack</strong>&rdquo; button and let us verify
whether the brute-force vulnerability is fixed or not.</p>
<figure class="mx-auto block text-center">
    <img loading="lazy" src="Start-Attack-Intruder-Options.png"
         alt="Figure 9: Intruder Start Attack"/> <figcaption>
            <p>Figure 9: Intruder Start Attack</p>
        </figcaption>
</figure>

<p>A new window pops up, and all the Intruder attack summaries will be
displayed. Now, an additional row named &ldquo;<strong>incorrect</strong>&rdquo; is added.</p>
<p>You can see that our grep match pattern is working, as we are able to
view the match count in the &ldquo;<strong>incorrect</strong>&rdquo; row updated for each
request.</p>
<figure class="mx-auto block text-center">
    <img loading="lazy" src="Brute-Force-Intruder-Attack-Medium-Result.png"
         alt="Figure 10: Brute Force Attack Result"/> <figcaption>
            <p>Figure 10: Brute Force Attack Result</p>
        </figcaption>
</figure>

<p>If you closely observe, there is one problem. It is slow compared to the
previous brute-force attack.</p>
<p>It seems the DVWA development team added a small delay, but it&rsquo;s still
not stopping us from performing a Brute Force attack.</p>
<p>It took more time than before, but we found a valid password match again
using the brute-force attack.</p>
<p>The one where the &ldquo;<strong>incorrect</strong>&rdquo; count is empty. i.e.,
<strong>admin/password</strong>. As displayed in the above screenshot.</p>
<p>Scroll down to check for the response body and observe a message.
&ldquo;<strong>Welcome to the password protected area of admin</strong>&rdquo;.</p>
<p>Yay!! The vulnerability still remains open. Let&rsquo;s report it back to the
DVWA dev team. 😄</p>
<h2 id="dvwa-informational-optional">DVWA Informational (Optional)</h2>
<p>We are testing this in a DVWA, an intentionally vulnerable environment.
The application also allows us to view the backend code for knowledge
purposes.</p>
<blockquote>
<p>Remember you might not have this option in real-world applications.</p>
</blockquote>
<p>Navigate to the &ldquo;<strong>Brute Force</strong>&rdquo; menu item in the sidebar. On the same
page click on the &ldquo;<strong>View Source</strong>&rdquo; button at the bottom of the page.</p>
<figure class="mx-auto block text-center">
    <img loading="lazy" src="BruteForce-Medium-Attack-Page-View-Source.png"
         alt="Figure 11: Brute Force View Source"/> <figcaption>
            <p>Figure 11: Brute Force View Source</p>
        </figcaption>
</figure>

<p>A pop-up window will be loaded, and the code will be displayed.</p>
<figure class="mx-auto block text-center">
    <img loading="lazy" src="BruteForce-Sleep-Code.png"
         alt="Figure 12: Brute Force Medium Source Code"/> <figcaption>
            <p>Figure 12: Brute Force Medium Source Code</p>
        </figcaption>
</figure>

<p>Observe that the application delays <strong>2</strong> seconds before sending the
response message back to the client for all failed logins.</p>
<p>In general, the vulnerability can be mitigated in many ways, but
industry best practices should be adhered to.</p>
]]></content:encoded>
    </item>
    <item>
      <title>Lab Setup - Docker DVWA</title>
      <link>https://raghu.io/lab-setup-docker-dvwa/</link>
      <pubDate>Sat, 30 Jul 2022 07:42:00 +0000</pubDate>
      <guid>https://raghu.io/lab-setup-docker-dvwa/</guid>
      <description>Step-by-step guide to setting up a DVWA Docker lab environment for practicing web application security testing.</description>
      <content:encoded><![CDATA[<p>If you&rsquo;re interested in learning and practicing web application security
skills but not sure where to get started, this section will walk you
through setting up the lab environment of the DVWA docker image, which
is one of the practical vulnerable applications for learning web
application security skills.</p>
<h2 id="what-is-dvwa">What is DVWA?</h2>
<p>Damn Vulnerable web app or Damn Vulnerable Web Application (DVWA) is an
intentionally designed vulnerable application for pen-testers and
security experts in learning and testing web application security in a
legal environment. It is developed using PHP/MySQL and can be deployed
easily using an Apache server.</p>
<p><a href="https://github.com/digininja/DVWA">DVWA Git Repository</a></p>
<p>DVWA can be installed in multiple ways, such as using code from GitHub,
Vagrant, or a Docker image, etc.</p>
<blockquote>
<p>It is recommended to host the vulnerable applications in a host-only
environment to prevent compromising other systems on your network by
attackers.</p>
</blockquote>
<p>You can even view the source code or contribute to the DVWA project.
It&rsquo;s an open-source project.</p>
<p>For simplicity, we will be using our systems and pre-built docker DVWA
image, which is publicly available, rather than setting up the whole
stuff by ourselves. By running the DVWA docker container, we can save a
lot of time and jump-start learning application security and penetration
testing directly.</p>
<h2 id="requirements">Requirements</h2>
<ol>
<li><strong>Docker installed</strong> &amp; enabled on your Laptop/Desktop</li>
<li><strong>Any Operating System (OS)</strong> Linux/Windows/Mac</li>
</ol>
<p>I am a GNU/Linux user, so most of the commands you will see from here on
will be based on <strong>Linux (Debian)</strong>, and similar commands do apply to
other Linux flavors like Ubuntu and Mac with minor tweaks.</p>
<p>For Windows users, you can use either <strong>PowerShell</strong> or <strong>git Bash</strong>,
where similar commands can be executed, or even the Windows Subsystem
for Linux can also be used.</p>
<h2 id="verify-docker-setup">Verify Docker Setup</h2>
<div class="highlight"><pre tabindex="0" class="chroma"><code class="language-bash" data-lang="bash"><span class="line"><span class="cl">docker --version
</span></span></code></pre></div><p><strong>Output:</strong></p>
<div class="highlight"><pre tabindex="0" class="chroma"><code class="language-text" data-lang="text"><span class="line"><span class="cl">Docker version 20.10.17, build 100c701
</span></span></code></pre></div><p>If the output is similar to the above, it means the docker is installed
on your system and good to start.</p>
<p>For users whose docker is not installed, please visit the <a href="https://docs.docker.com/get-started/get-docker/">Get
Docker</a> page for
installation.</p>
<h2 id="manage-docker-as-non-root-users-linux-based-os-users">Manage Docker as Non-Root Users (Linux-based OS Users)</h2>
<p>For users who are using docker on Linux-based operating systems, we need
to take one more additional step to ensure we can manage the docker
image as non-root users.</p>
<p>After installation of docker, create a docker group and add the newly
created user to the docker group.</p>
<div class="highlight"><pre tabindex="0" class="chroma"><code class="language-bash" data-lang="bash"><span class="line"><span class="cl">$ sudo groupadd docker
</span></span><span class="line"><span class="cl">
</span></span><span class="line"><span class="cl">$ sudo usermod -aG docker <span class="nv">$USER</span>
</span></span></code></pre></div><p>Now log out of the user account and log back in again to verify you are
now able to manage the docker instances from non-root users.</p>
<div class="highlight"><pre tabindex="0" class="chroma"><code class="language-bash" data-lang="bash"><span class="line"><span class="cl">$ docker run hello-world
</span></span></code></pre></div><p><strong>Output</strong>:</p>
<figure class="mx-auto block text-center">
    <img loading="lazy" src="hello-world-docker.jpg"
         alt="Figure 1: Docker Hello World Output"/> <figcaption>
            <p>Figure 1: Docker Hello World Output</p>
        </figcaption>
</figure>

<p>The above output confirms that we can manage Docker with non-root user
privileges. More details can be found on the <a href="https://docs.docker.com/engine/install/linux-postinstall/">post-installation
docker</a> page
below.</p>
<figure class="mx-auto block text-center">
    <img loading="lazy" src="/icons/balance.png"
         alt="Figure 2: Benefits of DVWA"/> <figcaption>
            <p>Figure 2: Benefits of DVWA</p>
        </figcaption>
</figure>

<h2 id="benefits-of-local-dvwa-environment">Benefits of Local DVWA Environment</h2>
<ul>
<li><strong>Practice</strong> any time.</li>
<li>Ability to test <strong>any customized payloads or exploits</strong>.</li>
<li>It can be used to test the <strong>effectiveness of Web Vulnerability
Scanners</strong> or <strong>Automated Tools</strong></li>
<li>It can be used for <strong>Teaching</strong>.</li>
<li>Ability to test custom <strong>security fixes</strong>.</li>
</ul>
<h2 id="running-dvwa-docker">Running DVWA docker</h2>
<p>I hope your Docker environment is configured so we can start working.
Here, we will use the Docker image, which has already been built and
hosted in the Docker Hub.</p>
<p>Damn Vulnerable Web Application Docker Image:
<a href="https://hub.docker.com/r/vulnerables/web-dvwa/">https://hub.docker.com/r/vulnerables/web-dvwa/</a></p>
<p><strong>Command</strong>:</p>
<div class="highlight"><pre tabindex="0" class="chroma"><code class="language-bash" data-lang="bash"><span class="line"><span class="cl">docker run --rm -it -p 80:80 vulnerables/web-dvwa
</span></span></code></pre></div><p>The above command will download the docker image for the first time and
will start immediately on port <strong>80</strong> after downloading it. Click
<a href="http://localhost/">here</a> to verify.</p>
<blockquote>
<p>If you are using port &ldquo;80&rdquo; for some other service in your operating
system, you can change the docker container port to some random one
(say 8443). Update the -p value with -p 80:8443. Ensure the updated
port is used in the URL while accessing the DVWA web application.</p>
</blockquote>
<p>To manually view, open a browser and visit &ldquo;<a href="http://localhost/">http://localhost/</a>&rdquo;, you
should be able to see the output as shown below:</p>
<figure class="mx-auto block text-center">
    <img loading="lazy" src="DVWA-Home-Screen.jpg"
         alt="Figure 3: DVWA Login Page"/> <figcaption>
            <p>Figure 3: DVWA Login Page</p>
        </figcaption>
</figure>

<p>The image will start displaying the console logs of the operations being
performed on the DVWA website for reference.</p>
<p>Stop the running Docker image anytime by typing <strong>Ctrl - c</strong> in your
console.</p>
<h2 id="dvwa-admin-password">DVWA Admin Password</h2>
<p>Now log into the application using Username <strong>admin</strong>, Password as
<strong>password</strong>, Navigate to Setup DVWA ⇾ click on Create/Reset Database
button.</p>
<figure class="mx-auto block text-center">
    <img loading="lazy" src="Setup-DVWA.jpg"
         alt="Figure 4: Setting up DVWA"/> <figcaption>
            <p>Figure 4: Setting up DVWA</p>
        </figcaption>
</figure>

<figure class="mx-auto block text-center">
    <img loading="lazy" src="create-reset-db-dvwa.jpg"
         alt="Figure 5: DVWA database creation"/> <figcaption>
            <p>Figure 5: DVWA database creation</p>
        </figcaption>
</figure>

<p>We can observe that the database has been created with a users&rsquo; table.
Some sample data is also inserted into the tables for our testing
purposes.</p>
<h2 id="damn-vulnerable-web-app-walkthrough">Damn Vulnerable Web App Walkthrough:</h2>
<p>Log into the DVWA application and observe most of OWASP&rsquo;s top-known
vulnerabilities that have been created so you can get started. They are
displayed as shown below.</p>
<figure class="mx-auto block text-center">
    <img loading="lazy" src="DVWA-Challenges-Overview.jpg"
         alt="Figure 6: DVWA Challenges Overview"/> <figcaption>
            <p>Figure 6: DVWA Challenges Overview</p>
        </figcaption>
</figure>

<p>Our practice lab environment is up and is good to go.</p>
<p>From the above screenshot, you can use the DVWA to practice and get
hands-on experience with known vulnerabilities, such as Brute Force,
Command Injection, CSRF, XSS, etc.</p>
<p>Click on any vulnerability in the left-side menu, and the application
will load the vulnerable page. All pages simulate close-to real-time
application behaviors and provide hints to help you narrow down and use
the correct type of vulnerable payloads for exploitation.</p>
<p>Remember that all our changes will be lost once you stop the DVWA docker
image. You might need to repeat the above steps when you start. This is
how the docker is designed, and it also allows us to begin with a fresh
environment without worrying about previous changes.</p>
<p>The docker image needs some more tweaks, but we will do them when needed
based on the type of attack we are discussing.</p>
<h2 id="dvwa-security-levels">DVWA Security Levels</h2>
<p>In the DVWA application, there are multiple levels to test any specific
vulnerability, ranging from Low to Medium to High and Impossible.</p>
<figure class="mx-auto block text-center">
    <img loading="lazy" src="DVWA-Levels.png"
         alt="Figure 7: DVWA Security Level"/> <figcaption>
            <p>Figure 7: DVWA Security Level</p>
        </figcaption>
</figure>

<p>These levels help you build skills by understanding each scenario.
First, you learn about the attack itself. Then, you will know how broken
fixes are implemented and how they can be bypassed. Lastly, you will
learn the best way to secure a particular functionality.</p>
<blockquote>
<p>The DVWA security levels are different for older versions. In the old
version, high is a good practice for fixing code.</p>
</blockquote>
<p>It is recommended that you go step by step. I still use it today to test
specific payloads before they are applied to real-time applications as
part of security testing.</p>
<h2 id="dvwa-view-source-and-view-help">DVWA View Source and View Help</h2>
<p>The DVWA application is mainly designed as a learning platform for
application security. It also allows us to view the backend code for
knowledge purposes.</p>
<blockquote>
<p>Remember, you might not have this option for real-world applications.
This is just for educational purposes only.</p>
</blockquote>
<p>Navigate to any vulnerability in the menu. Say the &ldquo;<strong>Brute Force</strong>&rdquo;
menu item in the sidebar. On the same page, click on the &ldquo;<strong>View
Source</strong>&rdquo; button at the bottom.</p>
<p>Similarly, the &ldquo;<strong>View Help</strong>&rdquo; button or &ldquo;<strong>More Information</strong>&rdquo; section
can be used if you struck somewhere as initial help.</p>
<figure class="mx-auto block text-center">
    <img loading="lazy" src="DVWA-View-Source-Help.png"
         alt="Figure 8: DVWA View Source or Help Information"/> <figcaption>
            <p>Figure 8: DVWA View Source or Help Information</p>
        </figcaption>
</figure>

<p>I hope the above information helps you to get started with a damn
vulnerable web app docker.</p>
<p>If you want to learn about some basic web foundations before jumping
into web security vulnerabilities, refer to the bookmarks below.</p>
<p>Security Foundations: <a href="/what-is-web-application-and-how-does-it-work/">What is Web Application and How does it
work?</a> Discover
the fundamentals of what is a web application, URLs, and popular web
application architectures. Gain insights into the core concepts that
drive the digital world forward. Begin your journey by establishing
strong security foundations.</p>
<p>Security Foundations: <a href="/http-basics-tutorial/">HTTP Basics
Tutorial</a> Uncover the
fundamentals of HTTP in this beginner-friendly way. HTTP Basics
Tutorials is a guide for those new to information security or diving
into web application security.</p>
<h2 id="faqs">FAQ&rsquo;s</h2>
<h3 id="how-to-log-into-a-damn-vulnerable-web-app-login">How to log into a damn vulnerable web app login?</h3>
<p>You can use the credentials like username as admin and password as
password.</p>
]]></content:encoded>
    </item>
    <item>
      <title>BurpSuite Installation</title>
      <link>https://raghu.io/burpsuite-installation/</link>
      <pubDate>Thu, 28 Jul 2022 06:11:00 +0000</pubDate>
      <guid>https://raghu.io/burpsuite-installation/</guid>
      <description>The following post will walk you through different packages of BurpSuite Tool and the Installation of a tool in the Linux Environment.</description>
      <content:encoded><![CDATA[<p>BurpSuite is a tool specifically designed for application security
testing. It is used for crawling the website, tampering with HTTP
messages, identifying vulnerabilities, automating security testing, and
many more functionalities are inbuilt.</p>
<p>We will cover the sections of BurpSuite individually as we keep trying
for security vulnerabilities.</p>
<p>BurpSuite(owned by portswigger) offers three variants, a community
edition, a professional, and an enterprise edition. We will use
community edition throughout the articles, which suffixes our
requirement.</p>
<p>Burp Suite can be found on the PortSwigger website:
<a href="https://portswigger.net/">https://portswigger.net/</a>.</p>
<p>Once you are familiar with security assessments and concepts, I would
recommend you to go for the professional edition as it has many more
benefits, like saving the sessions, optimizing scans, scheduling the
assessments, etc.</p>
<p>BurpSuite professional edition saves a lot of time while performing
real-world security assessments.</p>
<p>OWASP ZAP is an alternative. You can also use it or keep using the
BurpSuite community edition, which has limitations but can help complete
our work.</p>
<h2 id="burpsuite-installation">BurpSuite Installation</h2>
<p>Visit the <a href="https://portswigger.net/">PortSwigger website</a> and look for
Burp Suite downloads.</p>
<figure class="mx-auto block text-center">
    <img loading="lazy" src="/images/burpsuite/BurpSuite-Community-Download.webp"
         alt="Figure 1: BurpSuite Community Download Page"/> <figcaption>
            <p>Figure 1: BurpSuite Community Download Page</p>
        </figcaption>
</figure>

<ol>
<li>
<p>Make sure you are downloading the community version.</p>
</li>
<li>
<p>I am using the Linux-based OS, therefore choosing the Linux (64-bit)
version and clicking on the &ldquo;Download&rdquo; button.</p>
</li>
<li>
<p>Click on the &ldquo;Show Checksums&rdquo; after downloading. It is displayed as
shown below.</p>
</li>
</ol>
<figure class="mx-auto block text-center">
    <img loading="lazy" src="/images/burpsuite/CheckSums.webp"
         alt="Figure 2: Validate Checksums"/> <figcaption>
            <p>Figure 2: Validate Checksums</p>
        </figcaption>
</figure>

<ol>
<li>use md5sum or sha256 sum from the command line to verify your
download.</li>
</ol>
<!--listend-->
<div class="highlight"><pre tabindex="0" class="chroma"><code class="language-bash" data-lang="bash"><span class="line"><span class="cl"><span class="nv">$md5sum</span> burpsuite_community_linux_v2022_7_1.sh
</span></span><span class="line"><span class="cl">c48c31aa69754adaf394a215dff0ecc5 burpsuite_community_linux_v2022_7_1.sh
</span></span></code></pre></div><p>This helps to verify that the file you have downloaded is indeed from
the portswigger release and not tampered with by any malicious users.</p>
<ol>
<li>The installation is straightforward. Make the script executable
using the chmod command.</li>
</ol>
<p>If you are using Kali Linux, the BurpSuite will come pre-installed.</p>
<div class="highlight"><pre tabindex="0" class="chroma"><code class="language-bash" data-lang="bash"><span class="line"><span class="cl">chmod u+x burpsuite_community_linux_v2022_7_1.sh
</span></span></code></pre></div><ol>
<li>Run the executable and follow the instructions.</li>
</ol>
<!--listend-->
<div class="highlight"><pre tabindex="0" class="chroma"><code class="language-bash" data-lang="bash"><span class="line"><span class="cl">./burpsuite_community_linux_v2022_7_1.sh
</span></span></code></pre></div><figure class="mx-auto block text-center">
    <img loading="lazy" src="/images/burpsuite/burpsuite-install-screen.webp"
         alt="Figure 3: BurpSuite Installation Screen"/> <figcaption>
            <p>Figure 3: BurpSuite Installation Screen</p>
        </figcaption>
</figure>

<p>Select where you want to install the BurpSuite and click on the next.</p>
<figure class="mx-auto block text-center">
    <img loading="lazy" src="/images/burpsuite/BurpSuite_Choose_Install_directory.webp"
         alt="Figure 4: Choose Installation Directory"/> <figcaption>
            <p>Figure 4: Choose Installation Directory</p>
        </figcaption>
</figure>

<p>Keep the default for the location of the symlink and click on next.</p>
<figure class="mx-auto block text-center">
    <img loading="lazy" src="/images/burpsuite/BurpSuite_Simlinks_selection.webp"
         alt="Figure 5: Selecting symlinks&rsquo; default location"/> <figcaption>
            <p>Figure 5: Selecting symlinks&rsquo; default location</p>
        </figcaption>
</figure>

<p>Click on &ldquo;Finish&rdquo; to complete the installation.</p>
<figure class="mx-auto block text-center">
    <img loading="lazy" src="/images/burpsuite/BurpSuite_Complete_Install.webp"
         alt="Figure 6: BurpSuite Installation Complete"/> <figcaption>
            <p>Figure 6: BurpSuite Installation Complete</p>
        </figcaption>
</figure>

<h2 id="starting-burpsuite">Starting BurpSuite</h2>
<p>Navigate through your system application, look for the &ldquo;<strong>BurpSuite
Community</strong>&rdquo; icon, and click to launch. It can also be found manually by
going to the BurpSuite installation directory and running
<strong>./BurpSuiteCommunity</strong>.</p>
<figure class="mx-auto block text-center">
    <img loading="lazy" src="/images/burpsuite/BurpSuite_Launch_Screen.webp"
         alt="Figure 7: BurpSuite Launch Screen"/> <figcaption>
            <p>Figure 7: BurpSuite Launch Screen</p>
        </figcaption>
</figure>

<p>Here we can observe that the saving of the project feature is only
limited to the professional edition.</p>
<p>Select the Temporary project and click the &ldquo;Next&rdquo; button to continue.</p>
<figure class="mx-auto block text-center">
    <img loading="lazy" src="/images/burpsuite/BurpSuite_Choose_Load_Configuration.webp"
         alt="Figure 8: BurpSuite Configuration Screen"/> <figcaption>
            <p>Figure 8: BurpSuite Configuration Screen</p>
        </figcaption>
</figure>

<p>Custom configuration in BurpSuite gives you more control over how the
tool must behave, what type of checks you want to enable by default etc.
This we will be covering more in the advanced section.</p>
<p>Let&rsquo;s start using the BurpSuite defaults and click the &ldquo;<strong>Start
Burp</strong>&ldquo;button.</p>
<p>Finally, the BurpSuite will be launched and will be displayed as shown
below.</p>
<figure class="mx-auto block text-center">
    <img loading="lazy" src="/images/burpsuite/BurpSuite_Launch.webp"
         alt="Figure 9: BurpSuite Tool"/> <figcaption>
            <p>Figure 9: BurpSuite Tool</p>
        </figcaption>
</figure>

<p>The installation process will be very similar to Mac and Windows
operating systems, with minor changes.</p>
<p>Ensure your BurpSuite is installed and running before continuing to the
next section, the BurpSuite overview.</p>
]]></content:encoded>
    </item>
    <item>
      <title>What is Web Application and How does it work?</title>
      <link>https://raghu.io/what-is-web-application-and-how-does-it-work/</link>
      <pubDate>Mon, 25 Jul 2022 14:15:00 +0000</pubDate>
      <guid>https://raghu.io/what-is-web-application-and-how-does-it-work/</guid>
      <description>Discover the fundamentals of what is a web application, URLs, and popular web application architectures. Gain insights into the core concepts that drive the digital world forward. Begin your journey by establishing strong security foundations.</description>
      <content:encoded><![CDATA[<p>In this section, we shall cover the web and how it works. This will act
as a foundation for identifying security vulnerabilities further down
the posts.</p>
<h2 id="what-is-a-web-application">What is a web Application?</h2>
<p>Web applications are programs designed to perform specific operations
for users or other applications.</p>
<p>Examples: Reading News, Watching Videos, Editing Photos online, etc.</p>
<p>As users, we will be using Web Browsers like Chrome, Firefox, etc., to
interact with the web applications where numerous actions are performed
by our browsers behind the scenes once we give domain information in the
URL bar.</p>
<figure class="mx-auto block text-center">
    <img loading="lazy" src="/icons/web-application.webp"
         alt="Figure 1: Web Application Introduction"/> <figcaption>
            <p>Figure 1: Web Application Introduction</p>
        </figcaption>
</figure>

<p>Have you ever wondered how different browsers handle all these
functions, and you get similar results in all Web Browsers to the most
extent?</p>
<p>The <a href="https://en.wikipedia.org/wiki/Internet_Engineering_Task_Force">Internet Engineering Task
Force</a> is
a standards organization body for the Internet and other technical
standards.</p>
<p>The standards body is an individual or group of engineers and computer
scientists who publish the methods, behaviors, innovations, and
standards of how the internet and internet-connected systems should
work.</p>
<p><a href="https://en.wikipedia.org/wiki/Request_for_Comments?ref=raghu.io">Request For Comments (RFC)</a></p>
<p>RFC: After lots of peer review and evaluations are done for each
proposal, it is standardized, and each proposal is given a Request For
Comment (RFC) number. Therefore, all the applications developed to work
with the internet must adhere to RFC standards.</p>
<p>I recommend going through RFC documents whenever you want to learn
further. This might help you uncover new security bugs.</p>
<h2 id="what-is-a-url">What is a URL?</h2>
<p>URL is an acronym used for the Uniform Resource Locator. It&rsquo;s a type of
web address that specifies the location of a specific resource on the
internet.</p>
<p>URL consists of different components. Let&rsquo;s look at them in detail.</p>
<figure class="mx-auto block text-center">
    <img loading="lazy" src="/images/application-security-foundations/url.webp"
         alt="Figure 2: URL Components"/> <figcaption>
            <p>Figure 2: URL Components</p>
        </figcaption>
</figure>

<ol>
<li><strong>Protocol</strong> - A standard used for processing data.</li>
<li><strong>Domain Name</strong> - A user-readable address pointing to an IP address
on the internet.</li>
<li><strong>Port</strong> - Specific port used for communication. (HTTP runs on port
80, and HTTPS runs on port 443).</li>
<li><strong>Path</strong> - It represents the file or subdirectory structure on the
server.</li>
<li><strong>Parameter</strong> - A special kind of variable defined to pass values
for processing.</li>
<li><strong>Value</strong> - The value of a parameter assigned. It can contain
characters and numerics.</li>
</ol>
<h2 id="how-does-url-work">How does URL work?</h2>
<p>When you type a URL in your browser, the first request will be sent to
the Domain Name System (DNS). In DNS, it will look out for the mapping
IP address for the given domain name and send IP information to the
browser.</p>
<figure class="mx-auto block text-center">
    <img loading="lazy" src="/images/application-security-foundations/How-DNS-Works.webp"
         alt="Figure 3: How DNS Works"/> <figcaption>
            <p>Figure 3: How DNS Works</p>
        </figcaption>
</figure>

<p>Next, the browser uses the IP address information received and initiates
the TCP connection with the Server. Once the server responds with
confirmation, a valid channel is established and starts exchanging
requests and responses.</p>
<h2 id="web-applications-architectures">Web Applications Architectures</h2>
<p>Let&rsquo;s dig a bit deeper. All web applications and technologies are
logically connected for client-server communication to ensure a better
web experience.</p>
<p>From here on, we will refer to all the operations performed on the user
side as Client (Ex, Web Browsers, Terminal, etc.) and one which accepts
our request and responds as Server (Example: Nginx, Apache, etc.).</p>
<p>As of today, web application architectures have become very complex.
Let&rsquo;s start with the basics without worrying much, and you can build on
your expertise from here on.</p>
<h3 id="client---server-architecture-2-tiered">Client - Server Architecture (2-Tiered)</h3>
<figure class="mx-auto block text-center">
    <img loading="lazy" src="/images/application-security-foundations/Client-Server-2tiered.webp"
         alt="Figure 4: Client Server Architecture"/> <figcaption>
            <p>Figure 4: Client Server Architecture</p>
        </figcaption>
</figure>

<p>In the case of client-server architecture, A web application is hosted
on a single server that will process all the client&rsquo;s requests and
respond back.</p>
<h3 id="client---server-architecture-3---tiered">Client - Server Architecture (3 - Tiered)</h3>
<figure class="mx-auto block text-center">
    <img loading="lazy" src="/images/application-security-foundations/Client-Server-3-tier.webp"
         alt="Figure 5: Client Server - (3 - Tiered)"/> <figcaption>
            <p>Figure 5: Client Server - (3 - Tiered)</p>
        </figcaption>
</figure>

<p>In the case of client-server architecture, A web application is hosted
on multiple servers, a Web Server and a Database Server, where the web
server takes a request from clients and fetches the necessary data from
the database, formats it and sends it back to the client requested.</p>
<h3 id="client---server-n-tier">Client - Server (n-tier)</h3>
<figure class="mx-auto block text-center">
    <img loading="lazy" src="/images/application-security-foundations/Client-Server-n-tier.webp"
         alt="Figure 6: Client Server - (n-tired) or Hybrid Architecture"/> <figcaption>
            <p>Figure 6: Client Server - (n-tired) or Hybrid Architecture</p>
        </figcaption>
</figure>

<p>In the case of n-tier architecture, there can be any number of Web and
Database servers, where all the traffic being received from the client
is routed to the server with less load. Most of today&rsquo;s applications are
deployed similarly to the above architecture.</p>
<h2 id="technologies">Technologies</h2>
<p>Technologies are generally classified into two types.</p>
<ol>
<li>Client Side Technologies</li>
<li>Server Side Technologies.</li>
</ol>
<p>Let&rsquo;s check out some examples. You might already be familiar with some
technologies.</p>
<figure class="mx-auto block text-center">
    <img loading="lazy" src="/images/application-security-foundations/Technologies.webp"
         alt="Figure 7: Various Technologies&#39;"/> <figcaption>
            <p>Figure 7: Various Technologies'</p>
        </figcaption>
</figure>

<h3 id="client-side-technologies">Client Side Technologies</h3>
<p>Our browser understands HTML, CSS, and JavaScript technologies whenever
the server sends information using them. The browser renders and
displays the content in a human-readable format by hiding all complex
code from the user&rsquo;s view.</p>
<h3 id="server-side-technologies">Server Side Technologies</h3>
<p>In the screenshot above, we highlighted a few programming languages like
Python, PHP, Golang, etc., but there are many more server-side
technologies. These high-level programming languages run on the server,
process data, and format the data into a format the client can
understand.</p>
<h2 id="conclusion">Conclusion</h2>
<p>I hope you have some idea about the web and its technologies by now.</p>
<p>Next, Refer the HTTP basics, which are helpful for security assessments
and used by developers and administrators to understand what the server
says and take action based on it.</p>
]]></content:encoded>
    </item>
    <item>
      <title>The Importance of a Security.txt File</title>
      <link>https://raghu.io/the-importance-of-a-security.txt-file/</link>
      <pubDate>Thu, 06 Jan 2022 06:15:00 +0000</pubDate>
      <guid>https://raghu.io/the-importance-of-a-security.txt-file/</guid>
      <description>Importance and uses of security.txt file on a website.</description>
      <content:encoded><![CDATA[<p>Do you own or maintain any websites? If yes, this might be helpful for
you.</p>
<p>Security is a significant concern for any website these days. To help
provide security to their users, many websites have adopted the proposed
security standard of a security.txt file to allow researchers and
hackers alike to find vulnerabilities and report them without fear of
legal reprisal. This article will discuss what security.txt files are,
how they work, why your business/owner of the website should care about
adopting them, and more!</p>
<h2 id="what-is-a-securitytxt-file">What is a security.txt file?</h2>
<p>It is one of the proposed website standards that allows owners and
security researchers to work more closely to report any identified
security issues.</p>
<p>This &ldquo;security.txt&rdquo; file is a new open standard and still in the draft
stage, used by website administrators, bug bounty hunters, and other
security researchers who want to share information about discovered
vulnerabilities with website owners in an organized manner.</p>
<h2 id="how-does-securitytxt-work">How does security.txt work?</h2>
<p>If you are the site owner, you list contact information for reporting
vulnerabilities (such as an email address and PGP key) in your
security.txt file, and researchers can use this information to report
any issues they find privately. By doing this, you make it easier for
researchers to report vulnerabilities.</p>
<blockquote>
<p>&ldquo;security.txt&rdquo; is generally placed on your website at
<code>https://www.example.com/.well-known/security.txt</code></p>
</blockquote>
<p>Here are the example contents of the <strong>security.txt</strong> file.</p>
<figure>
    <img loading="lazy" src="images/security-txt/security-txt-1.webp"
         alt="Figure 1: : Sample security.txt file"/> <figcaption>
            <p>Figure 1: : Sample security.txt file</p>
        </figcaption>
</figure>

<h2 id="why-should-you-care-about-securitytxt">Why should you care about security.txt?</h2>
<p>A common phrase in the security industry is, &ldquo;<strong>Security is only as
strong as the weakest link.</strong>&rdquo; A single security bug is more than enough
to compromise the complete chain.</p>
<p>The website owner might ensure all the necessary steps to protect their
online asset from all malicious actors.</p>
<p>The security vulnerabilities are like the &ldquo;Cat and Mouse&rdquo; story as the
developers continuously work in a fast-paced agile environment to
deliver value to the customers in a shorter time, where some security
issues might go unnoticed.</p>
<p>However, if an attacker can find and exploit a vulnerability on the
website that was not patched or adequately addressed, it can potentially
do much damage.</p>
<p>As a site owner, you should care about adopting security.txt files
because they can help make it easier for researchers to report
vulnerabilities to you privately and securely. This can help protect the
researcher and your website from legal repercussions if the
vulnerability is not reported responsibly.</p>
<h3 id="additional-benefits">Additional Benefits:</h3>
<ul>
<li>
<p>Information about the organization&rsquo;s secure disclosure policy can be
stated so that researchers can look at and comply to the best extent.</p>
</li>
<li>
<p>The security.txt file helps information to communicate directly with
the respective security team, who is already familiar with the
reported topic.</p>
</li>
<li>
<p>Security researchers can also understand what part of the website is
in scope for testing and what is not part of the scope.</p>
</li>
<li>
<p>Acknowledgments for all the previously reported security researchers.</p>
</li>
<li>
<p>Links to job references if the organization seeks a security analyst
or red team expert.</p>
</li>
</ul>
<p>It is easy! You can create a security.txt file using this handy tool:
<a href="https://securitytxt.org/#generate">https://securitytxt.org/#generate</a></p>
<h2 id="references">References</h2>
<ul>
<li><a href="https://en.wikipedia.org/wiki/Security.txt">https://en.wikipedia.org/wiki/Security.txt</a></li>
<li><a href="https://securitytxt.org/">https://securitytxt.org/</a> - Template Generation</li>
<li><a href="https://github.com/securitytxt/security-txt">https://github.com/securitytxt/security-txt</a></li>
</ul>
]]></content:encoded>
    </item>
    <item>
      <title>Challenge 1 - Stored cross-site scripting attack</title>
      <link>https://raghu.io/challenge-1-stored-cross-site-scripting-attack/</link>
      <pubDate>Tue, 13 Dec 2022 05:43:59 +0000</pubDate>
      <guid>https://raghu.io/challenge-1-stored-cross-site-scripting-attack/</guid>
      <description>You will learn about what cross-site scripting vulnerability is, the types of cross-site scripting vulnerabilities, and how to identify a stored XSS</description>
      <content:encoded><![CDATA[<p>Welcome back to learning Cross-Site Scripting (XSS) vulnerability with
the Kurukshetra app built by
<a href="https://github.com/D4rk36/Kurukshetra?ref=raghu.io">d4rk36</a>.</p>
<p>This post will start with what an XSS vulnerability is and then will try
to analyze the XSS challenges on the vulnerable app.</p>
<p>Ensure your lab is up and running if you have not set up your lab yet.</p>
<figure>
    <img loading="lazy" src="/icons/javascript.png"/> 
</figure>

<h2 id="what-is-cross-site-scripting">What is Cross-Site Scripting?</h2>
<p>Cross-site scripting is also referred to as &ldquo;<strong>XSS</strong>.&rdquo;</p>
<p>Cross-site scripting is an application flaw that takes a malformed input
from the client (i.e., Browser or Proxy) and the server without
verifying appends, then sends the input as it is back in an HTTP
response without proper validation.</p>
<blockquote>
<p>If you are not familiar with what HTTP is, check out the following
HTTP Basics Tutorial to help you get started.</p>
</blockquote>
<p>The malformed input lets an attacker inject malicious code(like HTML or
JavaScript ) into the server&rsquo;s HTTP response and can change the
application&rsquo;s behavior.</p>
<p>XSS vulnerability can be used to deface the landing pages of websites,
which is called defacement. Stealing user sessions and gaining access to
user accounts. Secretly log and monitor the victim&rsquo;s keystrokes, Control
the victim&rsquo;s web browser, retrieve user-saved passwords from the
browser, Or even redirect victims to a malicious page, and much more.</p>
<p>Additionally, XSS, combined with other security vulnerabilities, makes
the attack more severe.</p>
<p>In total, there are three types of XSS vulnerabilities, as detailed
below.</p>
<figure class="mx-auto block text-center">
    <img loading="lazy" src="Types-Of-XSS.png"
         alt="Figure 1: Types of Cross-Site Scripting Vulnerabilities"/> <figcaption>
            <p>Figure 1: Types of Cross-Site Scripting Vulnerabilities</p>
        </figcaption>
</figure>

<figure>
    <img loading="lazy" src="/icons/lab.png"/> 
</figure>

<h2 id="stored-xss---walkthrough">Stored XSS - Walkthrough</h2>
<p>After setting up the lab, Visit <a href="http://localhost:8066">http://localhost:8066</a>. The vulnerable
Kurukshetra application should be loaded as shown below.</p>
<figure class="mx-auto block text-center">
    <img loading="lazy" src="Challenge-1-Page.png"
         alt="Figure 2: XSS Vulnerable Kurukshetra App - Challenge 1"/> <figcaption>
            <p>Figure 2: XSS Vulnerable Kurukshetra App - Challenge 1</p>
        </figcaption>
</figure>

<p>Take some time to understand how the application functionality works
before we start assessing.</p>
<p>Try adding a simple &ldquo;<strong>HelloWorld</strong>&rdquo; string, and check how the input is
appended to the below comments.</p>
<figure class="mx-auto block text-center">
    <img loading="lazy" src="Key-In-Input.png"
         alt="Figure 3: Understaing how the application behaves with user input"/> <figcaption>
            <p>Figure 3: Understaing how the application behaves with user input</p>
        </figcaption>
</figure>

<p>From the above behavior, we can understand that the given input is
stored and displayed back.</p>
<p>💡 This is one of the signs where you can check if it can accept any
malformed input as well. Let&rsquo;s go ahead and try out the classic XSS
payload.</p>
<figure class="mx-auto block text-center">
    <img loading="lazy" src="Classic-XSS-String.png"
         alt="Figure 4: Class XSS Snippet"/> <figcaption>
            <p>Figure 4: Class XSS Snippet</p>
        </figcaption>
</figure>

<p><code>*&lt;script&gt;*</code> tag in HTML is used to extend the page capabilities and
include interactivity, which will be used to test if it is possible to
inject the code snippets.</p>
<p><code>alert()</code> function in JavaScript is used to display the popup window.</p>
<p>I will insert the script code to make things visually appealing, as
displayed in the image below. When we see the popup window, it means our
script code got injected and executed successfully.</p>
<figure class="mx-auto block text-center">
    <img loading="lazy" src="Trying-XSS-Payload.png"
         alt="Figure 5: Inserting XSS Payload"/> <figcaption>
            <p>Figure 5: Inserting XSS Payload</p>
        </figcaption>
</figure>

<p>Inject the script code in the input field and click the &ldquo;<strong>Submit</strong>&rdquo;
button.</p>
<p>Immediately, a popup message will be displayed, as shown below, to
confirm our script execution.</p>
<figure class="mx-auto block text-center">
    <img loading="lazy" src="XSS-Alert.png"
         alt="Figure 6: XSS alert pop-up"/> <figcaption>
            <p>Figure 6: XSS alert pop-up</p>
        </figcaption>
</figure>

<p>Click the &ldquo;<strong>OK</strong>&rdquo; button, and the application usually loads the page.</p>
<p>To further understand our script injection, Right-click, select &ldquo;<strong>View
Page Source</strong>,&rdquo; and then search for the above-injected script code.</p>
<figure class="mx-auto block text-center">
    <img loading="lazy" src="XSS-Alert-HTML-Source.png"
         alt="Figure 7: XSS Script Code in HTML Response"/> <figcaption>
            <p>Figure 7: XSS Script Code in HTML Response</p>
        </figcaption>
</figure>

<p>The script code was injected as it was given. This confirms we could
inject the malformed script code in the user input field.</p>
<p>Revisit the following page: <a href="http://localhost:8066/ch01.php">http://localhost:8066/ch01.php</a>. Observe
the popup message will be displayed again.</p>
<p>This is what a stored cross-site scripting vulnerability is. Once the
malformed input is injected, it will be executed every time the page is
loaded. If multiple users are using the same application, then the
script code will also be executed for each and every individual victim
as well.</p>
<p>Attackers can use the above type of functionality to deface the page and
completely change it based on malicious intent using JavaScript and HTML
code. Similarly, write a malicious piece of code to steal all the
authenticated users&rsquo; session tokens and reuse it for accessing the
user&rsquo;s account without passwords. Or even redirect victims to a
malicious page, etc.</p>
<p>🎉 This type of behavior is called Stored Cross-Site Scripting
vulnerability. Yay! We found a stored cross-site scripting vulnerability
and solved XSS Challenge 1.</p>
<h2 id="about-xss-payloads">About XSS Payloads</h2>
<p>The above example demonstrates a simple XSS code snippet.</p>
<p>You might be wondering how I would ever be able to create those script
payloads, and I am not even familiar with JavaScript and that stuff.</p>
<p>Well, lots of security researchers have already done most of the work
related to payloads for you. You all need to know when to use it and
what needs to be changed based on your scenario. As the experience
grows, you will be able to write your own custom payloads for yourself.</p>
<p>Here is a repository of
&ldquo;<a href="https://github.com/swisskyrepo/PayloadsAllTheThings/tree/master/XSS%20Injection?ref=raghu.io">PayloadsAllThings</a>&rdquo;
that you might need to bookmark it.</p>
<p>You will find a lot of information on different vulnerabilities and
their payloads. Just search for &ldquo;XSS Injection&rdquo;.</p>
<p>Go ahead and try out with a wide range of XSS payloads and see how the
application behaves.</p>
<blockquote>
<p>💡Practice Makes perfect.</p>
</blockquote>
<h2 id="clean-up---xss-data">Clean up - XSS Data</h2>
<p>It might become annoying if we keep getting too many popups, which can
even impact usability.</p>
<p>Click on the &ldquo;<strong>Purge Database</strong>&rdquo; button to eliminate the annoying
popups and start fresh.</p>
<figure class="mx-auto block text-center">
    <img loading="lazy" src="Purge-Database.png"
         alt="Figure 8: Clean up all annoying warnings with - Purge Database"/> <figcaption>
            <p>Figure 8: Clean up all annoying warnings with - Purge Database</p>
        </figcaption>
</figure>

<figure>
    <img loading="lazy" src="/icons/report.png"/> 
</figure>

<h2 id="conclusion">Conclusion</h2>
<p>I hope you learned about the different types of cross-site scripting
vulnerabilities. Organizations are using the most secure coding
frameworks and best practices, but they might still miss out due to
complex application ecosystems, which can give way to XSS
vulnerabilities. The above example demonstrates how improper coding
practices can be used to exploit stored XSS vulnerabilities, and fixing
them as soon as possible as part of security assessments can reduce the
huge impact on production systems.</p>
]]></content:encoded>
    </item>
    <item>
      <title>BurpSuite Overview</title>
      <link>https://raghu.io/burpsuite-overview/</link>
      <pubDate>Fri, 29 Jul 2022 14:36:00 +0000</pubDate>
      <guid>https://raghu.io/burpsuite-overview/</guid>
      <description>A high-level walk-through of the BurpSuite tool. A much needed for the application security pentesting</description>
      <content:encoded><![CDATA[<p>In this post, we will walk through BurpSuite and start learning the
concepts that we will be using, and I will be covering more about the
features when needed during our assessments.</p>
<p>If you haven&rsquo;t installed the Burp Suite, refer <a href="/burpsuite-installation/">BurpSuite
Installation</a> and ensure the tool is
successfully installed.</p>
<h2 id="overview">Overview</h2>
<p>Let&rsquo;s launch the BurpSuite community edition using the steps from
BurpSuite Installation guide.</p>
<p>At launch, the &ldquo;<strong>Learn</strong>&rdquo; tab will be selected and all the information
required for learning and using the tool will be displayed as shown
below. You can always explore the text and video tutorials provided by
the tool.</p>
<figure class="mx-auto block text-center">
    <img loading="lazy" src="/images/burpsuite/BurpSuite_Community-Learn-Tab.webp"
         alt="Figure 1: BurpSuite Communtiy - Learn Tab"/> <figcaption>
            <p>Figure 1: BurpSuite Communtiy - Learn Tab</p>
        </figcaption>
</figure>

<h3 id="dashboard">Dashboard</h3>
<p>A place where you can see information about the crawling and issues
identified.</p>
<figure class="mx-auto block text-center">
    <img loading="lazy" src="/images/burpsuite/BurpSuite-Dashboard.webp"
         alt="Figure 2: BurpSuite Dashboard"/> <figcaption>
            <p>Figure 2: BurpSuite Dashboard</p>
        </figcaption>
</figure>

<p><strong>Tasks</strong> section is a place where we can configure crawling for all
websites we visit and keep an eye on their status. By default, the tool
helps us by enabling &ldquo;Live passive crawl&rdquo;.</p>
<p>Passive crawl means when I visit any website using the <strong>Proxy</strong> tool,
it starts looking at all the HTML content and collects page URLs,
parameters, etc. keeps building the sitemaps locally for our knowledge
base.</p>
<p>This is similar to the daemon service, it will keep on continuously
running from the start of the BurpSuite tool, you can disable it by
setting the &ldquo;Capturing&rdquo; off.</p>
<p><strong>Event Log</strong> section gives you information about the BurpSuite tool
itself like services started, error information if it is unable to load
any extender plugin, network issues, and warning about the tool which
might impact your work.</p>
<p><strong>Issues Activity</strong> is a place where the BurpSuite scanner will display
all the vulnerabilities identified by the tool</p>
<p><strong>Issues Information</strong> section where you can see a detailed description
of the security bug reported and the proof of concept of how the tool
was able to identify it as a security defect.</p>
<p>The above issues sections are only available in the BurpSuite
Professional edition.</p>
<h3 id="target">Target</h3>
<p>The target tab consists of three items, site map, scope, and issue
definitions.</p>
<p><strong>Site map</strong> is the place where you can see all the URLs, and parameters
information collected by the crawler. As we can only see the status in
the dashboard, here you can find the detailed information post crawling
of websites.</p>
<figure class="mx-auto block text-center">
    <img loading="lazy" src="/images/burpsuite/BurpSuite_Target.webp"
         alt="Figure 3: BurpSuite Target"/> <figcaption>
            <p>Figure 3: BurpSuite Target</p>
        </figcaption>
</figure>

<p><strong>Scope</strong> is the most important section while performing any security
assessments or pentesting.</p>
<p>Be very clear about which particular websites are part of your scope for
security testing, and add them to the &ldquo;In Scope&rdquo; section. (Example:
securityarray.io as in scope)</p>
<p>Anything which is not supposed to be tested on a particular website
excludes all of them from testing by adding it to the &ldquo;Out of Scope&rdquo;
section. (Example: payments.securityarray.io)</p>
<p>Always keep in mind, that only perform security testing on the scope
mentioned to you. Violating the terms and conditions of the scope of
your assessments will lead to banning you, or sometimes you might face
legal challenges from the owners of the website.</p>
<p><strong>Issue definitions</strong> are like a vulnerabilities inventory of BurpSuite
about all the vulnerabilities it can identify. The security defects are
all categorized from informational to High severity.</p>
<p>This is also a good place to keep referring to vulnerabilities
information.</p>
<h3 id="proxy">Proxy</h3>
<p><strong>This is the core feature of the BurpSuite tool.</strong></p>
<p>In short, once you configure the BurpSuite proxy with your web browser,
Any traffic which goes from your web browser to the web server will be
viewable in your BurpSuite proxy tab.</p>
<p>Not only view, but you can also intercept and modify any request before
it goes to the server.</p>
<p>Generally, the browser limits our capabilities to only view the HTTP
messages for debugging purposes, by using this proxy tool as an
intermediate you can overcome those limitations</p>
<figure class="mx-auto block text-center">
    <img loading="lazy" src="/images/burpsuite/BurpSuite-Proxy.webp"
         alt="Figure 4: BurpSuite Proxy"/> <figcaption>
            <p>Figure 4: BurpSuite Proxy</p>
        </figcaption>
</figure>

<p>In security, we often keep on saying &ldquo;Validate every piece of data which
is coming from the client side&rdquo;. As it can be tampered with.</p>
<figure class="mx-auto block text-center">
    <img loading="lazy" src="/images/burpsuite/BurpSuite-Proxy-Enable.webp"
         alt="Figure 5: BurpSuite Proxy Enabled"/> <figcaption>
            <p>Figure 5: BurpSuite Proxy Enabled</p>
        </figcaption>
</figure>

<p>After launching the BurpSuite tool, the first thing to ensure your proxy
listener is started and in a running state.</p>
<p>Navigate to the &ldquo;Proxy&rdquo; tab ⇾ &ldquo;Options&rdquo; ⇾ &ldquo;Proxy Listeners&rdquo;. As shown in
the above screenshot.</p>
<p><strong>HTTP History</strong> is a location where all the ongoing HTTP traffic
information can be viewed.</p>
<p><strong>Intercept</strong> tab is where you have the option to enable for all or each
request you want to change before sending to the web server, or turn it
off if you don&rsquo;t want to modify any requests.</p>
<p>By default, the intercept feature is enabled at startup.</p>
<p>Navigate to the &ldquo;Proxy&rdquo; tab ⇾ &ldquo;Options&rdquo; ⇾ &ldquo;Intercept Client Requests&rdquo;.
As shown in the above screenshot.</p>
<figure class="mx-auto block text-center">
    <img loading="lazy" src="/images/burpsuite/BurpSuite-Intercept-Rules.webp"/> 
</figure>

<p>You would be able to see the Intercept requests enabled, and the rule
set of what all requests the Burp Proxy will intercept.</p>
<p>Similarly, we can enable the intercepting of responses as well if you
want to see it in the proxy itself.</p>
<p>Additionally, the Intercept tool also does contain an inbuilt Chromium
browser which is preconfigured.</p>
<figure class="mx-auto block text-center">
    <img loading="lazy" src="/images/burpsuite/Burp-Intercept-Browser.webp"
         alt="Figure 6: BurpSuite Intercept Browser"/> <figcaption>
            <p>Figure 6: BurpSuite Intercept Browser</p>
        </figcaption>
</figure>

<p>Launch the browser and start accessing any website, you should be able
to see all the data being seeded into your BurpSuite Proxy.</p>
<p>In short, the takeaway from the proxy tool is to configure with any web
browser, and we can start playing with the requests sent from the client
to the server.</p>
<h3 id="intruder">Intruder</h3>
<p>This is one of the best features of the BurpSuite. Let&rsquo;s say you are
having a situation where you need to test whether the application is
using the default username and passwords for the server.</p>
<p>Yes, we do consider it a security bug if you use the default username
and passwords on the server. Because anyone on the internet can guess
it.</p>
<p>If our list of default usernames/passwords is less than 10, probably you
can do it manually. But what if it&rsquo;s 100+ and beyond?</p>
<figure class="mx-auto block text-center">
    <img loading="lazy" src="/images/burpsuite/BurpSuite-Intruder.webp"/> 
</figure>

<p>BurpSuite intruder is a big savior here. All, we need is to load the
HTTP request, choose where you need to inject the modified values, set
the payloads list (usernames or passwords list), and fire. That&rsquo;s it!</p>
<p>Intruder itself is a very big concept, which we will be covering in
upcoming articles.</p>
<p>For now, all you need to remember is we can fine-tune custom payloads
and reduce our manual efforts at the time of security testing for
various scenarios using intruder.</p>
<h3 id="repeater">Repeater</h3>
<p>Based on the tab name, you could have probably guessed it is used to
send repeated instructions!</p>
<figure class="mx-auto block text-center">
    <img loading="lazy" src="/images/burpsuite/BurpSuite-Repeater.webp"/> 
</figure>

<p>For example, you are testing a Password Strength functionality where you
need to check if accepts only small characters, or only numerics or
passwords with lengths less than 5, etc.</p>
<p>Here, we can do this from a web browser by accessing the application
interface. But, don&rsquo;t you think it&rsquo;s too repetitive to always reload the
page and enter a value, click submit and observe results?</p>
<p>Yes, the repeater saves us a lot of time. Just capture any request
message and modify it before sending it to the server. You can see the
response in the repeater tab itself. This saves us a lot of time when
sending repeated requests.</p>
<h3 id="sequencer">Sequencer</h3>
<p>As the name suggests, it is used to analyze a large sample of tokens to
see whether it is predictable or completely randomized and
unpredictable.</p>
<figure class="mx-auto block text-center">
    <img loading="lazy" src="/images/burpsuite/BurpSuite-Sequencer.webp"
         alt="Figure 7: BurpSuite Sequencer"/> <figcaption>
            <p>Figure 7: BurpSuite Sequencer</p>
        </figcaption>
</figure>

<p>In general, this is used for analyzing the session tokens to find if it
is predictable. If you can predict what the next session token will be
set by the server, then this is considered a security flaw.</p>
<p><strong>Live capture</strong> helps you to capture each request directly by
interacting with the web server. Whereas <strong>Manual load</strong> is a place
where you can give samples of the tokens you have collected for
analyzing the strength of the tokens.</p>
<h3 id="decoder">Decoder</h3>
<p>You encountered a type of encoded hash and are not sure what type of
hash it is and how to decode it during assessments. We even have a way
to decode/encode it using the decoder tool.</p>
<figure class="mx-auto block text-center">
    <img loading="lazy" src="/images/burpsuite/BurpSuite-Decoder.webp"
         alt="Figure 8: BurpSuite Decoder"/> <figcaption>
            <p>Figure 8: BurpSuite Decoder</p>
        </figcaption>
</figure>

<p>Start by using the &ldquo;Smart decode&rdquo; option, which will figure out the type
of encoding and decodes it to plain text.</p>
<p>BurpSuite decoder currently supports URL, HTML, base64, ASCII hex, hex,
binary, octal, and GZIP encodings as of today.</p>
<h3 id="comparer">Comparer</h3>
<p>Comparer lets you view the differences between the two messages of what
was modified and what was added newly.</p>
<figure class="mx-auto block text-center">
    <img loading="lazy" src="/images/burpsuite/BurpSuite-Comparer.webp"
         alt="Figure 9: BurpSuite Comparer"/> <figcaption>
            <p>Figure 9: BurpSuite Comparer</p>
        </figcaption>
</figure>

<h3 id="logger">Logger</h3>
<p>Logger displays all the communication information between your BurpSuite
tool set and the target website.</p>
<figure class="mx-auto block text-center">
    <img loading="lazy" src="/images/burpsuite/BurpSuite-Logger.webp"
         alt="Figure 10: BurpSuite Logger"/> <figcaption>
            <p>Figure 10: BurpSuite Logger</p>
        </figcaption>
</figure>

<h3 id="extender">Extender</h3>
<p>BurpSuite extender gives additional superpowers to expand the
capabilities of the current toolset.</p>
<figure class="mx-auto block text-center">
    <img loading="lazy" src="/images/burpsuite/BurpSuite-Extender.webp"
         alt="Figure 11: BurpSuite Extender"/> <figcaption>
            <p>Figure 11: BurpSuite Extender</p>
        </figcaption>
</figure>

<p><strong>BAppStore</strong> is a list of plugins inventory that is provided by
portswigger as well as from the security community.</p>
<p><strong>APIs</strong> provide us the capability to add custom functionalities based
on requirements.</p>
<p><strong>Extensions</strong> tab provides you with information about all the
extensions which are enabled and their output.</p>
<h3 id="project-options">Project options</h3>
<p>Let&rsquo;s say I want to automate the set of sequential operations which need
to be performed with less manual effort. Can I do it?</p>
<p>Yes, you can do that using Macros.</p>
<figure class="mx-auto block text-center">
    <img loading="lazy" src="/images/burpsuite/BurpSuite-Project-Options.webp"
         alt="Figure 12: BurpSuite Project Options"/> <figcaption>
            <p>Figure 12: BurpSuite Project Options</p>
        </figcaption>
</figure>

<p>Project options provide you with a lot more benefits to tweak session
handling rules, how and where the cookies are maintained, Macros to
repeat a sequence of actions based on rules, HTTP communication
preferences, etc.</p>
<p>To save all the changes, navigate to the &ldquo;Project&rdquo; menu item ⇾ select
&ldquo;Project options&rdquo; ⇾ &ldquo;save project options&rdquo;.</p>
<p>Similar way, you can load the saved options using &ldquo;Load project
options&rdquo;.</p>
<h3 id="user-options">User options</h3>
<p>These are settings specifically for the user who uses the BurpSuite.</p>
<figure class="mx-auto block text-center">
    <img loading="lazy" src="/images/burpsuite/BurpSuite-UserOptions.webp"
         alt="Figure 13: BurpSuite User Options"/> <figcaption>
            <p>Figure 13: BurpSuite User Options</p>
        </figcaption>
</figure>

<p>Some options where we are tweaking repeatedly while launching BurpSuite,
probably there is a way to save that setting and use it whenever you
launch the tool rather than configuring it every time.</p>
<p>Say, you want to change the Interface to how it looks better for you or
update shortcut keys, change temporary file location, update
communications information, etc.</p>
<p>All about how you want the tool to behave can be updated here.</p>
<p>Lastly, to save all the changes, navigate to the &ldquo;Burp&rdquo; menu ⇾ select
&ldquo;User Options&rdquo; ⇾ &ldquo;save user options&rdquo;. Using the same way, you can load
the saved options using &ldquo;Load user options&rdquo;.</p>
<h2 id="summary">Summary</h2>
<p>Well, we have covered a good amount of information about the different
sections available in the BurpSuite tool.</p>
<p>I hope, by now, you are familiar to navigate and choose different tabs
based on requirements.</p>
]]></content:encoded>
    </item>
    <item>
      <title>HTTP Basics Tutorial</title>
      <link>https://raghu.io/http-basics-tutorial/</link>
      <pubDate>Tue, 26 Jul 2022 08:53:00 +0000</pubDate>
      <guid>https://raghu.io/http-basics-tutorial/</guid>
      <description>Uncover the fundamentals of HTTP in this beginner-friendly way. HTTP Basics Tutorials is a guide for those new to information security or diving into web application security.</description>
      <content:encoded><![CDATA[<p>Discover the internals of HTTP with the following beginner&rsquo;s tutorial.
If you are new to information security or getting started in web
application security, this post will walk you through the HTTP basics
and foundations needed.</p>
<h2 id="introduction-to-http-and-its-importance">Introduction to HTTP and its importance</h2>
<p>HTTP, which stands for &ldquo;Hypertext Transfer Protocol&rdquo;, is the foundation
used for data communications on the World Wide Web. In simple words,
this protocol lets communication between our web browser and web
servers.</p>
<p>Understanding the HTTP is crucial for anyone who is interested in
getting into security testing. It is a basic foundation for all the data
communication on the internet. Knowing about the HTTP Requests,
Responses, and Status Codes will help us to understand more about a web
application and its behaviour during the security testing process and
even help us automate repetitive manual work.</p>
<h3 id="what-is-http">What is HTTP?</h3>
<p>HTTP is a protocol with a set of defined rules for communicating between
the client and the server. Think of it like this: we humans use a common
language to speak and communicate with each other. Similarly, the
protocol is to communicate with the client (Example: Web Browser) and
the server (Example: Apache HTTP).</p>
<p>Our modern web browsers hide this complexity by taking care of them and
loading beautiful web pages for us to be easy to read and understand.</p>
<blockquote>
<p>💡On the web, all I see is HTTPS. Yes, you are right. The working
principle is the same, with few changes. Will cover those as well.</p>
</blockquote>
<h3 id="http-is-text-based-protocol">HTTP is text based protocol</h3>
<p><a href="https://en.wikipedia.org/wiki/HTTP">HTTP</a> is a simple message-based
request/response protocol. When the user requests a web page, the
browser sends the HTTP request to the server in the background, which
then responds with the requested resources. The website responds back
with the requested resource, which is called response.</p>
<p>HTTP acts as a medium through which information is exchanged. It allows
the transfer of various types of data, including text, images,
multimedia files, etc.</p>
<h3 id="structure-of-http-requests-and-responses">Structure of HTTP Requests and Responses</h3>
<p>A sample of HTTP request-response can be seen as shown below:</p>
<p><strong>Request:</strong></p>
<figure>
    <img loading="lazy" src="/images/application-security-foundations/Sample-Request.webp"
         alt="Figure 1: : Sample HTTP Request by Client"/> <figcaption>
            <p>Figure 1: : Sample HTTP Request by Client</p>
        </figcaption>
</figure>

<p><strong>Response:</strong></p>
<figure>
    <img loading="lazy" src="/images/application-security-foundations/sample-response.webp"
         alt="Figure 2: : Sample HTTP Response form Server"/> <figcaption>
            <p>Figure 2: : Sample HTTP Response form Server</p>
        </figcaption>
</figure>

<p>I can see this is a lot of data to digest, don&rsquo;t worry, with the
overwhelming information you see on the response screenshot. You don&rsquo;t
need to remember everything. This is to get you acclimated to the type
of data you&rsquo;ll see from now on and focus only on what we need the most.</p>
<p>We will come back to technical in a bit. Let&rsquo;s go ahead and learn more
about HTTP.</p>
<h3 id="http-is-a-stateless-protocol">HTTP is a Stateless Protocol</h3>
<p>As the name suggests, the stateless protocol does not maintain the state
of a transaction. Stateless protocols are typically used in low-level
communication applications, where data packets can be sent without any
notifications. An example of a stateless protocol is TCP.</p>
<p>This means you get the response back once a request is sent and the
connection closes. It will not be able to link or relate to any previous
requests.</p>
<ol>
<li>
<p>Example of HTTP/1.0 and below versions</p>
<div class="highlight"><pre tabindex="0" class="chroma"><code class="language-bash" data-lang="bash"><span class="line"><span class="cl"><span class="nv">$nc</span> demo.testfire.net <span class="m">80</span>
</span></span><span class="line"><span class="cl">GET / HTTP/1.0
</span></span><span class="line"><span class="cl">Host: www.demo.testfire.net
</span></span><span class="line"><span class="cl">
</span></span><span class="line"><span class="cl">HTTP/1.1 <span class="m">200</span> OK
</span></span><span class="line"><span class="cl">Server: Apache-Coyote/1.1
</span></span><span class="line"><span class="cl">Set-Cookie: <span class="nv">JSESSIONID</span><span class="o">=</span>DF622CC21A2727AC5DD745D1A5B007BF<span class="p">;</span> <span class="nv">Path</span><span class="o">=</span>/<span class="p">;</span>
</span></span><span class="line"><span class="cl">HttpOnly
</span></span><span class="line"><span class="cl">Content-Type: text/html<span class="p">;</span><span class="nv">charset</span><span class="o">=</span>ISO-8859-1
</span></span><span class="line"><span class="cl">Date: Wed, <span class="m">27</span> Jul <span class="m">2022</span> 07:48:18 GMT
</span></span><span class="line"><span class="cl">Connection: close
</span></span></code></pre></div><p>I am using a tool called net cat (nc) here to demonstrate a
stateless example by sending the custom request and waiting for the
response from the server. If you observe closely, the server sends
the last line <strong>Connection: close</strong>.</p>
<p><em><strong>Connection</strong></em>: header above tells that the TCP connection can be
closed once after sending the HTTP response.</p>
<p>But from HTTP/1.1 and above, the TCP connection will not be closed
and will wait for the next request to be received and processed.</p>
<div class="highlight"><pre tabindex="0" class="chroma"><code class="language-bash" data-lang="bash"><span class="line"><span class="cl">$ nc demo.testfire.net <span class="m">80</span>
</span></span><span class="line"><span class="cl">GET / HTTP/1.1
</span></span><span class="line"><span class="cl">Host: demo.testfire.net
</span></span><span class="line"><span class="cl">
</span></span><span class="line"><span class="cl">HTTP/1.1 <span class="m">200</span> OK
</span></span><span class="line"><span class="cl">Server: Apache-Coyote/1.1
</span></span><span class="line"><span class="cl">Set-Cookie: <span class="nv">JSESSIONID</span><span class="o">=</span>D7190756165E5E1B4986094B7A17630F<span class="p">;</span> <span class="nv">Path</span><span class="o">=</span>/<span class="p">;</span> HttpOnly
</span></span><span class="line"><span class="cl">Content-Type: text/html<span class="p">;</span><span class="nv">charset</span><span class="o">=</span>ISO-8859-1
</span></span><span class="line"><span class="cl">Transfer-Encoding: chunked
</span></span><span class="line"><span class="cl">Date: Wed, <span class="m">27</span> Jul <span class="m">2022</span> 07:54:31 GMT
</span></span></code></pre></div><p>In the above request/response, you can see the <em>Transfer-Encoding:
chunked</em>, which means the connection is not closed, and it is
waiting for the next request to process.</p>
<p><em><strong>Transfer-Encoding</strong></em>: header is used to specify the type of
encoding used on the data sent in the message body in a series of
chunks.</p>
<p>For now, remember that the above concepts will be helpful while
discussing advanced HTTP attacks.</p>
<figure>
        <img loading="lazy" src="/images/application-security-foundations/HTTP-HTTPS.webp"
             alt="Figure 3: : HTTP vs HTTPS"/> <figcaption>
                <p>Figure 3: : HTTP vs HTTPS</p>
            </figcaption>
    </figure>

</li>
</ol>
<h3 id="http-vs-https">HTTP vs HTTPS</h3>
<p>HTTP (Hypertext Transfer Protocol) and HTTPS (Hypertext Transfer
Protocol Secure) underlying working concepts are similar. HTTPS is a
secure version of HTTP that uses SSL or TLS security certificates.</p>
<p>The HTTP protocol is outdated and not secure. The HTTPS protocol is more
modern and has encryption codes to protect user information.</p>
<p>A few of the drawbacks of HTTP are detailed below:</p>
<ol>
<li>HTTP transmits messages in <strong>clear text</strong>, meaning that anyone on
the network can view all of your requests, responses, and sensitive
information like usernames, passwords, and card information.</li>
<li>Not only above, if your data goes through any of the Proxy
connections, then a <strong>copy of your request and response is also
stored now on the proxy server</strong>. How the admin uses the information
is beyond our control, and it would be hard to track the attacker.</li>
<li>In some browsers where the cache is enabled, the copy of your
request will also be in the cache. This is challenging when the
session token or sensitive information is passed in the URL.</li>
</ol>
<p>This is where HTTPS protects us with privacy and integrity from all
kinds of snooping or <a href="https://en.wikipedia.org/wiki/Man-in-the-middle_attack?ref=raghu.io">Man in the Middle
(MITM)</a>
attacks.</p>
<p>Lastly, the default port for <strong>HTTP is 80</strong>, and <strong>HTTPS is 443</strong>. It
can also be changed based on requirements.</p>
<h2 id="breakdown-of-the-http-components">Breakdown of the HTTP components</h2>
<p>Let&rsquo;s dig a bit deeper and learn more about the HTTP syntax, methods,
and headers. This section helps us in reviewing request-response
messages and confirm whether vulnerability exists or not.</p>
<p>Take some time to understand and get well acquainted.</p>
<h3 id="http-syntax">HTTP Syntax</h3>
<p>We came to understand that HTTP is a simple message-based protocol that
contains request and response messages.</p>
<p>Let&rsquo;s try to understand more about the request.</p>
<ol>
<li>
<p>A Typical Request Message:</p>
<figure class="mx-auto block text-center">
        <img loading="lazy" src="/images/application-security-foundations/http_request_syntax.webp"
             alt="Figure 4: HTTP Request Sections"/> <figcaption>
                <p>Figure 4: HTTP Request Sections</p>
            </figcaption>
    </figure>

<p>HTTP request contains two sections, Headers, and Body. The header
and body are separated by an empty line.</p>
<p>The body section can vary based on the type of HTTP method. For
example, the GET HTTP method doesn&rsquo;t contain any body information,
but the POST method does contain.</p>
<!--list-separator-->
<ul>
<li>
<p><strong>1. Headers</strong>:</p>
<div class="highlight"><pre tabindex="0" class="chroma"><code class="language-http" data-lang="http"><span class="line"><span class="cl"><span class="nf">POST</span> <span class="nn">/members/api/send-magic-link/</span> <span class="kr">HTTP</span><span class="o">/</span><span class="m">2</span>
</span></span></code></pre></div><p>In the above line, the first one POST is called a verb. It&rsquo;s one
of the HTTP methods commonly used for posting data onto the
server.</p>
<p>Followed by the URL path <em><strong>members/api/send-magic-link</strong></em>, the
page which the client is trying to access/post.</p>
<p>Lastly, <strong>HTTP/2</strong> is the protocol and its version used for
communication.</p>
<p>Each header in the message body is placed on a separate line. The
next header is Host.</p>
<div class="highlight"><pre tabindex="0" class="chroma"><code class="language-text" data-lang="text"><span class="line"><span class="cl">Host: securityarray.io
</span></span></code></pre></div><p><strong>Host</strong> header contains the domain name of the server to whom the
request must be sent.</p>
<p>Next, followed by other headers.</p>
</li>
</ul>
<!--list-separator-->
<ul>
<li>
<p><strong>2. Body</strong>:</p>
<p>HTTP Body section contains the additional supporting information
for the above-specified POST header information. Below is an
example of the <a href="https://www.json.org/?ref=raghu.io">JavaScript Object Notation
(JSON)</a> type of data
passed to the server in the message body.</p>
<div class="highlight"><pre tabindex="0" class="chroma"><code class="language-text" data-lang="text"><span class="line"><span class="cl">{&#34;name&#34;:&#34;Raghu&#34;,&#34;email&#34;:&#34;example@securityarray.io&#34;,&#34;requestSrc&#34;:&#34;portal&#34;}
</span></span></code></pre></div><p>The message body can also be plain text or HTML or XML data based
on the type of content being transmitted.</p>
<p><strong>A Typical Response Message</strong></p>
<figure class="mx-auto block text-center">
          <img loading="lazy" src="/images/application-security-foundations/http_response_syntax.webp"
               alt="Figure 5: HTTP Response"/> <figcaption>
                  <p>Figure 5: HTTP Response</p>
              </figcaption>
      </figure>

<p>HTTP Response message will look similar to the above, containing
the Headers and Body separated by an empty line.</p>
<div class="highlight"><pre tabindex="0" class="chroma"><code class="language-http" data-lang="http"><span class="line"><span class="cl"><span class="kr">HTTP</span><span class="o">/</span><span class="m">2</span> <span class="m">201</span> <span class="ne">Created</span>
</span></span></code></pre></div><p>The first line specifies the server acknowledgement back to the
client using HTTP/2 protocol, and the next <strong>201</strong> is a status
code specifying the type of action taken by the web server for the
request sent.</p>
<p>Here, it has created the content on the server. Therefore, we
received <strong>201 Created</strong>.</p>
<p>By this, I can confirm the content I have posted is created on the
server, and it acknowledges back, followed by other HTTP headers
and message body, and next if any.</p>
<p>The HTTP message body is later beautified and displayed back to
the user on a web browser in a human-readable way.</p>
<figure class="mx-auto block text-center">
          <img loading="lazy" src="/icons/policies-procedures.webp"
               alt="Figure 6: : HTTP Methods"/> <figcaption>
                  <p>Figure 6: : HTTP Methods</p>
              </figcaption>
      </figure>

</li>
</ul>
</li>
</ol>
<h2 id="http-methods-and-its-purpose">HTTP Methods and Its Purpose</h2>
<p>The methods indicate the purpose for which the client has initiated the
request and what is expected by the client to consider it a successful
result.</p>
<p>Let&rsquo;s walk through the different HTTP methods available.</p>
<ol>
<li><strong>GET</strong> is used to retrieve the resource from the web server, and it
doesn&rsquo;t contain a message body. The URLs that you observe in the
browser URL bar are all GET requests.</li>
<li><strong>HEAD</strong> is very similar to the GET, but it only sends the header
section.</li>
<li><strong>POST</strong> method performs a specific operation with the provided
message body. Like creating or updating. It is recommended to use
POST for sending sensitive information like username, password, card
info, etc. As the message body cannot be seen by intermediate
resources like proxies.</li>
<li><strong>PUT</strong> is most commonly used for updating the data and also for
uploading the content to the server.</li>
<li><strong>DELETE</strong> is used to remove a resource on the server, which is
allowed only for users with authorized privileges.</li>
<li><strong>CONNECT</strong> is used to establish a tunnel to the server</li>
<li><strong>OPTIONS</strong> is used to request a list of HTTP methods enabled on the
server.</li>
<li><strong>TRACE</strong> is used for diagnostic purposes. Whenever you send a
request using TRACE, you should be able to see the same contents in
response as were sent in the request.</li>
</ol>
<figure class="mx-auto block text-center">
    <img loading="lazy" src="/icons/Information.webp"
         alt="Figure 7: HTTP Headers"/> <figcaption>
            <p>Figure 7: HTTP Headers</p>
        </figcaption>
</figure>

<h2 id="understanding-http-headers">Understanding HTTP Headers</h2>
<p>In HTTP, there are many headers, each intended for a specific purpose.
We will be covering some headers, and if you would like to learn about
the complete list of headers, the best source is RFCs
(<a href="https://datatracker.ietf.org/doc/html/rfc2616?ref=raghu.io">HTTP/1.1</a>,
<a href="https://datatracker.ietf.org/doc/html/rfc7540?ref=raghu.io">HTTP/2</a>)</p>
<p>Some headers you can observe in both Request and Response are given
below.</p>
<p><strong>Content-Length</strong> specifies the length of the message body in bytes.</p>
<p><strong>Content-Type</strong> specifies the type of content present in the message
body.</p>
<h3 id="request-headers">Request headers</h3>
<p><strong>User-Agent</strong> specifies the information about your browser or from
other clients from which you are trying to access the web server.</p>
<p><strong>Origin</strong> is used to specify from where the request originated.</p>
<p><strong>Referer</strong> is used to specify the request from which the current URL
originated.</p>
<p><strong>Authorization</strong> is a token used to pass to the server for accessing
privileged resources.</p>
<p><strong>Accept</strong> headers inform the server about content types accepted by the
client.</p>
<p><strong>Accept-Encoding</strong> informs the server about encoding types understood
by the client.</p>
<h3 id="response-headers">Response Headers</h3>
<p><strong>Set-Cookie</strong> is used to set the session cookies on the client side to
identify the sessions and user accounts used for accessing server
resources.</p>
<p><strong>Access-Control-Allow-Origin</strong> indicates whether the resource can be
retrieved via cross-domain Ajax requests.</p>
<p><strong>Cache-Control</strong> passes the instructions to the browser about how the
cache must be handled.</p>
<figure class="mx-auto block text-center">
    <img loading="lazy" src="/icons/checks_300x300.webp"
         alt="Figure 8: Status Codes"/> <figcaption>
            <p>Figure 8: Status Codes</p>
        </figcaption>
</figure>

<h2 id="decoding-http-status-codes">Decoding HTTP Status Codes</h2>
<p>The status codes are used to inform the client about how the request was
handled. The server acknowledges back with the three-digit numerical
codes of how it was processed.</p>
<p>Getting familiar with status codes helps you to review and take action
while performing security assessments.</p>
<figure class="mx-auto block text-center">
    <img loading="lazy" src="/images/application-security-foundations/HTTP-Status-Codes.webp"
         alt="Figure 9: HTTP Status Codes"/> <figcaption>
            <p>Figure 9: HTTP Status Codes</p>
        </figcaption>
</figure>

<p>Let&rsquo;s look at common status codes which we will be encountering
day-to-day.</p>
<p><strong>100 Continue</strong> message sent by the server to continue and keep sending
the message body. Once completed, the server will respond with another
status message.</p>
<p><strong>200 OK</strong> means that the request was successful and that the response
body contains the result of the request.</p>
<p><strong>201 Created</strong> is returned in response to a PUT/POST request to
indicate that the request was successful and created.</p>
<p><strong>301 Moved Permanently</strong> redirects the browser permanently to a
different URL. So the client should use the new URL going ahead in the
future.</p>
<p><strong>302 Found</strong> redirects the browser temporarily to a different URL</p>
<p><strong>304 Not Modified</strong> specifies the browser to use the cached copy as the
client has the latest data of the server.</p>
<p><strong>400 Bad Request</strong> is a client error that indicates that the client
submitted an invalid HTTP request.</p>
<p><strong>401 Unauthorized</strong> indicates that you need to be authenticated to
access the server resource.</p>
<p><strong>403 Forbidden</strong> indicates that you do not have privileges to access
the resource on the server.</p>
<p><strong>404 Not Found</strong> means the requested resource is not present on the
server.</p>
<p><strong>405 Method Not Allowed</strong> means the specified HTTP method in the
request is not supported for the given URL.</p>
<p><strong>500 Internal Server Error</strong> indicates that the server is unable to
process your request, which might be because of some unhandled error
within the server application.</p>
<p><strong>503 Service Unavailable</strong> is displayed when the server is handling a
heavy load and is not able to function. Also, during maintenance hours,
or during migration, or even in case the server crashes.</p>
<h2 id="conclusion">Conclusion</h2>
<p>I hope this short tutorial has provided the foundations for
understanding HTTP protocol and its significance in terms of application
security. It&rsquo;s a lot of information to digest and remember. You could
use this as a reference to get started, and surely, this is going to
help us make better decisions while carrying out security assessments.</p>
<p>I encourage you to continue exploring the HTTP RFCs
(<a href="https://datatracker.ietf.org/doc/html/rfc2616?ref=raghu.io">HTTP/1.1</a>,
<a href="https://datatracker.ietf.org/doc/html/rfc7540?ref=raghu.io">HTTP/2</a>,
<a href="https://datatracker.ietf.org/doc/html/rfc9114">HTTP/3</a>)
for in-depth understanding.</p>
<p>Remember, learning web application security is an ongoing journey, and
each step you take brings you closer to mastering this valuable skill.</p>
<p>Keep exploring!</p>
]]></content:encoded>
    </item>
    <item>
      <title>Challenge 2 - Reflected cross-site scripting attack</title>
      <link>https://raghu.io/challenge-2-reflected-cross-site-scripting-attack/</link>
      <pubDate>Wed, 04 Jan 2023 15:29:55 +0000</pubDate>
      <guid>https://raghu.io/challenge-2-reflected-cross-site-scripting-attack/</guid>
      <description>You will learn about a reflected XSS and how it differs from the stored XSS. Also, I will walk you through exploiting reflected XSS.</description>
      <content:encoded><![CDATA[<p>Welcome back to learning Cross-Site Scripting(XSS) vulnerability with
the Kurukshetra app built by
<a href="https://github.com/D4rk36/Kurukshetra?ref=raghu.io">d4rk36</a>.</p>
<p>In this article, we shall learn about the reflected XSS and how it
differs from the stored XSS.</p>
<p>Before we start, ensure the lab is running if you have not set up your
lab yet.</p>
<h2 id="types-of-cross-site-scripting-xss">Types of Cross-Site-Scripting (XSS)</h2>
<figure>
    <img loading="lazy" src="Types-Of-XSS.png"/> 
</figure>

<figure>
    <img loading="lazy" src="/icons/application.png"/> 
</figure>

<h2 id="how-reflected-xss-work">How Reflected XSS Work?</h2>
<p>The server processes the malicious input code supplied from the client
side, and the same malicious code is injected and then returned to the
client in an HTTP response without proper validations.</p>
<p>The browser renders the response content, assuming it was supplied by
the application server, which can be trusted, and the injected malicious
code also gets executed.</p>
<p>The significant difference that can be observed when compared to stored
cross-site scripting is, in reflected XSS, the malicious code is just
appended back in the HTTP response and executed immediately. It is not
stored anywhere in the database.</p>
<p>For the same reason, the impact of reflected XSS is reduced compared to
the stored cross-site scripting vulnerability.</p>
<figure>
    <img loading="lazy" src="/icons/lab.png"/> 
</figure>

<h2 id="practicals---reflected-xss">Practicals - Reflected XSS</h2>
<p>Post setting up the lab, visit <a href="http://localhost:8066">http://localhost:8066</a>. The application
should be loaded as shown below and Navigate to &ldquo;<a href="http://localhost:8066/ch02.php">XSS Challenge
2</a>.&rdquo;</p>
<figure class="mx-auto block text-center">
    <img loading="lazy" src="XSS-Challenge-2-Page.png"
         alt="Figure 1: Kurukshetra XSS Challenge 2 Page"/> <figcaption>
            <p>Figure 1: Kurukshetra XSS Challenge 2 Page</p>
        </figcaption>
</figure>

<p>Before you start assessing, take some time to understand how the
application functionality works.</p>
<p>Let&rsquo;s go ahead and give it a try with the similar payload used in the
stored XSS.</p>
<figure class="mx-auto block text-center">
    <img loading="lazy" src="xss-payload.png"
         alt="Figure 2: XSS Payload"/> <figcaption>
            <p>Figure 2: XSS Payload</p>
        </figcaption>
</figure>

<p>Once appending the payload, click the &ldquo;<strong>Submit</strong>&rdquo; button, as shown in
the screenshot below.</p>
<figure class="mx-auto block text-center">
    <img loading="lazy" src="CH2-XSS-Payload-Injection.png"
         alt="Figure 3: XSS Payload Injection"/> <figcaption>
            <p>Figure 3: XSS Payload Injection</p>
        </figcaption>
</figure>

<p>Immediately observe the alert pop-up message, which will be displayed
below.</p>
<figure class="mx-auto block text-center">
    <img loading="lazy" src="CH2-XSS-Payload-Injection-Alert.png"
         alt="Figure 4: XSS Payload Alert Message"/> <figcaption>
            <p>Figure 4: XSS Payload Alert Message</p>
        </figcaption>
</figure>

<p>Click &ldquo;<strong>OK</strong>&rdquo; and observe the page loads normally.</p>
<p>To verify and confirm the vulnerability, right-click and select &ldquo;<strong>view
page source</strong>&rdquo; and search for the above-injected payload.</p>
<figure class="mx-auto block text-center">
    <img loading="lazy" src="CH2-XSS-Payload-Injection-HTML-Source.png"
         alt="Figure 5: XSS Payload HTML Code Verify"/> <figcaption>
            <p>Figure 5: XSS Payload HTML Code Verify</p>
        </figcaption>
</figure>

<p>The proof-of-concept script code aligns correctly with the HTML response
received, and all the characters are displayed back as given in the
input field.</p>
<p><strong>Yay!!</strong> Now, we can confirm we have successfully exploited the
reflected XSS.</p>
<p>Now, a point to remember here is that as this is not stored in the
database, it gets executed only when the malicious code is injected. At
all other times, the application usually behaves as expected.</p>
<p>In Stored XSS, the malicious payload gets executed whenever any user
visits the injected application functionality.</p>
<figure>
    <img loading="lazy" src="/icons/report.png"/> 
</figure>

<h2 id="summary">Summary</h2>
<p>This article covered how to identify reflected XSS and how it works,
including reusing the same XSS payload without much tweaking.</p>
<p>Keep learning!! :D</p>
]]></content:encoded>
    </item>
    <item>
      <title>Challenge 3 - XSS bypass blacklist HTML tags</title>
      <link>https://raghu.io/challenge-3-xss-bypass-blacklist-html-tags/</link>
      <pubDate>Fri, 13 Jan 2023 05:21:34 +0000</pubDate>
      <guid>https://raghu.io/challenge-3-xss-bypass-blacklist-html-tags/</guid>
      <description>Using the XSS fundamentals learned will look at how poorly implemented input validations can be bypassed with a custom-crafted xss payload.</description>
      <content:encoded><![CDATA[<p>Welcome back to learning Cross-Site Scripting(XSS) with the Kurukshetra.
An app built by
<a href="https://github.com/D4rk36/Kurukshetra?ref=raghu.io">d4rk36</a>.</p>
<p>Before we start, ensure the Kurukshetra lab is up and running if you
have not set up your lab yet. Feel free to refer back to the below link.</p>
<p>We walked through stored and reflected XSS in a previous couple of
articles. In today&rsquo;s article with those foundations, let&rsquo;s dive into the
practical labs and start learning.</p>
<figure>
    <img loading="lazy" src="Types-Of-XSS.png"/> 
</figure>

<figure>
    <img loading="lazy" src="/icons/lab.png"/> 
</figure>

<h2 id="practicals---reflected-xss">Practicals - Reflected XSS</h2>
<p>Post setting up the lab, visit <a href="http://localhost:8066">http://localhost:8066</a> and ensure it&rsquo;s
accessible, then navigate to &ldquo;XSS Challenge 3&rdquo;.</p>
<figure class="mx-auto block text-center">
    <img loading="lazy" src="Kurukshetra-XSS-Challenge-3-Page.png"
         alt="Figure 1: Kurukshetra XSS Challenge Page 3"/> <figcaption>
            <p>Figure 1: Kurukshetra XSS Challenge Page 3</p>
        </figcaption>
</figure>

<p>Let&rsquo;s try it with the XSS payload used in our previous articles and
observe how the application behaves.</p>
<h3 id="payload-try-1-classic">Payload Try 1: Classic</h3>
<figure class="mx-auto block text-center">
    <img loading="lazy" src="Classic-XSS-String.png"
         alt="Figure 2: Classic XSS Payload"/> <figcaption>
            <p>Figure 2: Classic XSS Payload</p>
        </figcaption>
</figure>

<p><strong>Output</strong>:</p>
<figure class="mx-auto block text-center">
    <img loading="lazy" src="XSS-Challenge-3-Initial-Payload-Result.png"
         alt="Figure 3: Initial XSS Payload Result"/> <figcaption>
            <p>Figure 3: Initial XSS Payload Result</p>
        </figcaption>
</figure>

<p>From the above observations, the application no longer gives pop-up
messages but instead prints out the partial string from our given
payload. Which indicates that our XSS payload is no longer working.</p>
<p>To evaluate further, click &ldquo;<strong>View page source</strong>&rdquo; to understand how our
injected payload string is loaded in the HTML response body.</p>
<figure>
    <img loading="lazy" src="Page-Source-Code.png"/> 
</figure>

<p>I can see that there is some kind of filter kept in place by the
application that removes the word &ldquo;<strong>script</strong>,&rdquo; which breaks the HTML
syntax, and the browser treats the following data as just text and
displays back the partial string.</p>
<p>Can we assume that the vulnerability is fixed? <strong>No</strong></p>
<p>The developer leveraged a technique called
&ldquo;<a href="https://en.wikipedia.org/wiki/Blacklist_%28computing%29?ref=raghu.io">Blacklisting</a>&rdquo;
to secure the application from exploiting the XSS vulnerability.
However, this approach has limitations, and it can still be bypassed.</p>
<figure>
    <img loading="lazy" src="/icons/info.png"/> 
</figure>

<ol>
<li>
<p>TIP - 1</p>
<p>HTML is case-insensitive, which means we can try it by changing it
to upper case or small case letters or even combining small and
upper case letters together, as given below.</p>
<figure>
        <img loading="lazy" src="HTML-Case-Insensitive.png"/> 
    </figure>

</li>
</ol>
<h3 id="payload-try-2-case-insensitive">Payload Try 2: Case-Insensitive</h3>
<figure>
    <img loading="lazy" src="HTML-Case-Insensitve-Payload.png"/> 
</figure>

<p><strong>Output</strong>:</p>
<figure class="mx-auto block text-center">
    <img loading="lazy" src="XSS-Challenge-3-Initial-Payload-Result2.png"
         alt="Figure 4: Second XSS Payload Result"/> <figcaption>
            <p>Figure 4: Second XSS Payload Result</p>
        </figcaption>
</figure>

<p>It looks like this technique also failed. The application seems to be
filtering out the lowercase and uppercase script tags that were
inserted.</p>
<figure>
    <img loading="lazy" src="/icons/thinking.png"/> 
</figure>

<ol>
<li>
<p>TIP - 2</p>
<p>Javascript functions can be triggered for execution in multiple
different ways, not necessarily that only the HTML script tag is
needed all the time.</p>
<p>One of the ways to execute the javascript &ldquo;<strong>alert()</strong>&rdquo; function is
using the HTML SVG tag, which is generally used for loading the
vector graphics file on the HTML pages.</p>
<p><strong>Example:</strong></p>
<figure>
        <img loading="lazy" src="xss-payload-3.png"/> 
    </figure>

<p>The HTML Attribute &ldquo;<strong>onload</strong>&rdquo; is one of the special words used to
control the behavior.</p>
<p>In the above example, the HTML attribute &ldquo;<strong>onload</strong>&rdquo; is assigned to
a javascript function &ldquo;<strong>alert()</strong>&rdquo; which runs immediately when the
HTML SVG tag is loaded.</p>
<p>Let&rsquo;s go ahead and check out the things in action.</p>
</li>
</ol>
<h3 id="payload-try-3-html5-tags">Payload Try 3: HTML5 Tags</h3>
<figure>
    <img loading="lazy" src="xss-payload-3.png"/> 
</figure>

<p><strong>Output</strong>:</p>
<figure>
    <img loading="lazy" src="XSS-Challenge-3-Second-Payload-Result.png"/> 
</figure>

<p>This attempt also failed, as the application filters out multiple HTML
tag strings. i.e., svg, script, img, etc.</p>
<p>From the above example, we can see that the HTML attribute &ldquo;<strong>onload</strong>&rdquo;
is being loaded without any filters and displayed back as keyed in.</p>
<figure>
    <img loading="lazy" src="/icons/lost.png"/> 
</figure>

<ol>
<li>
<p>TIP - 3</p>
<p>Not all HTML tag strings can be blacklisted. Some might break the
entire HTML page itself and application functionality.</p>
<p>For example, the HTML Body tag is needed most to load the page&rsquo;s
content. HTML Style tag, which is used to beautify the page, etc.</p>
<p>We shall improvise the previously used payload with the HTML Body
tag.</p>
</li>
</ol>
<h3 id="payload-try-4-html5-tags">Payload Try 4: HTML5 Tags</h3>
<figure>
    <img loading="lazy" src="xss-payload-four.png"/> 
</figure>

<p><strong>Output: pop-up message</strong></p>
<figure class="mx-auto block text-center">
    <img loading="lazy" src="XSS-Challenge-3-Fourth-Payload-Alert.png"
         alt="Figure 5: Fourth XSS Payload Alert"/> <figcaption>
            <p>Figure 5: Fourth XSS Payload Alert</p>
        </figcaption>
</figure>

<p><strong>yay!!!</strong> 🎉 This time, our XSS payload worked, and the application
displayed the pop-up message.</p>
<p>To further confirm, Click &ldquo;<strong>OK</strong>,&rdquo; then right-click and select the
&ldquo;<strong>View page source</strong>&rdquo; code to see how our payload was injected and
aligned with the HTML response code.</p>
<figure class="mx-auto block text-center">
    <img loading="lazy" src="XSS-Challenge-3-Fourth-Payload-Source.png"
         alt="Figure 6: Fourth XSS Payload HTML Page Source"/> <figcaption>
            <p>Figure 6: Fourth XSS Payload HTML Page Source</p>
        </figcaption>
</figure>

<p>You should be able to find out that our injected payload is rightly
aligned, HTML attribute onload event is triggered immediately. Therefore
it indeed executed the javascript code.</p>
<p>Through this, we have successfully solved the XSS challenge 3.</p>
<figure>
    <img loading="lazy" src="/icons/report.png"/> 
</figure>

<h2 id="summary">Summary</h2>
<p>In this article, we learned how poorly implemented validations can still
be bypassed by improving the payload and trying different possible
combinations. The blacklisting approach is helpful for a quick fix but
is not foolproof, which must be updated whenever a new payload has been
reported. Additionally, we covered many tips and techniques that can
help you improvise your XSS identification skillset.</p>
<p>Keep learning!! :D</p>
]]></content:encoded>
    </item>
    <item>
      <title>How to Install Wordfence: Step-by-step guide</title>
      <link>https://raghu.io/how-to-install-wordfence/</link>
      <pubDate>Fri, 15 Mar 2024 04:02:29 +0000</pubDate>
      <guid>https://raghu.io/how-to-install-wordfence/</guid>
      <description>This step-by-step guide on how to install the Wordfence plugin will enable the standard recommended security settings for your WordPress website quickly and keep it safe from potential threats.</description>
      <content:encoded><![CDATA[<p>Looking to improve the security of your WordPress website? This
step-by-step guide will walk you through how to install the Wordfence
security plugin, a powerful plugin for WordPress. Tool to secure your
WordPress site from potential threats.</p>
<h2 id="what-is-wordfence">What is Wordfence?</h2>
<p>Wordfence is a security plugin for WordPress that helps secure your
website from various online threats. It has an application firewall,
malware scanner, and many other features designed to keep your website
safe and secure. With over 5+ million active installations, Wordfence is
one of the most popular security plugins for WordPress.</p>
<h3 id="key-features-and-benefits">Key features and benefits</h3>
<ul>
<li><strong>Application Firewall:</strong> It has a web application firewall that can
identify and block malicious traffic before it reaches your website.</li>
<li><strong>Malware Scanner:</strong> The plugin scans your website for known malware
and helps keep your website free from viruses.</li>
<li><strong>Brute Force Attack Protection:</strong> Wordfence helps protect your
website from brute force attacks by rate-limiting login attempts and
enforcing strong passwords.</li>
<li><strong>Two-Factor Authentication:</strong> The plugin also offers two-factor
authentication, an extra layer of security for admin user accounts.</li>
</ul>
<h2 id="pre-installation-steps">Pre-Installation Steps</h2>
<p>Before installing Wordfence, it&rsquo;s important to take a few
pre-installation steps to ensure a smooth and secure process.</p>
<p>In this article, we will focus only on the free version of Wordfence.</p>
<h3 id="backup-your-wordpress-website">Backup your WordPress website</h3>
<p>It&rsquo;s always a good practice to create a backup of your WordPress website
before installing any new plugins. This ensures that you can restore
your website to its previous state in case anything goes wrong during
the installation process.</p>
<h3 id="update-wordpress-and-all-plugins">Update WordPress and all plugins</h3>
<p>Ensure your WordPress core installation and all other plugins are up to
date. Running the latest versions of WordPress and plugins helps ensure
compatibility and security.</p>
<h2 id="installing-wordfence">Installing Wordfence</h2>
<p>Log into your WordPress admin account, navigate to &ldquo;<strong>Plugins</strong>&rdquo; -&gt;
&ldquo;<strong>Add Plugins</strong>&rdquo;, and search for &ldquo;<strong>Wordfence</strong>&rdquo;.</p>
<figure>
<img src="Installing-Wordfence-fs8-1.png" />
<figcaption>Install Wordfence Plugin</figcaption>
</figure>
<h3 id="getting-wordfence-license">Getting Wordfence License</h3>
<p>After installation, click on the &ldquo;<strong>Activate</strong>&rdquo; button to ensure the
plugin is enabled. You will see a page stating that the plugin has been
successfully installed and requesting that you &ldquo;<strong>Get your Wordfence
license.</strong>&rdquo;</p>
<figure>
<img src="Wordfence-Registration-Page-1.png" />
<figcaption>Wordfence License Request Page</figcaption>
</figure>
<p>Even to access the free features of Wordfence, we need to register with
a valid email address to get the activation code.</p>
<p>It will take you to the Wordfence website, where you can choose from the
different packages offered by Wordfence.</p>
<p>In our case, for demo purposes, we shall go ahead with the &ldquo;<strong>Free</strong>&rdquo;
license that is available.</p>
<figure>
<img src="Wordfence-Get-Free-License-fs8.png" />
<figcaption>Requesting for Free License</figcaption>
</figure>
<p>Wordfence requests you to re-confirm and highlights that you will be
missing out on the latest exploit protection in real-time.</p>
<blockquote>
<p>The malware scanning rules are updated monthly in a free version, and
Real-time protection is available in a premium version.</p>
</blockquote>
<p>You can try it with the free version and upgrade it based on your
requirements. For the demo, we go ahead with a free one.</p>
<blockquote>
<p>I have no association with Wordfence, just for educational purposes.</p>
</blockquote>
<p>Click on &ldquo;<strong>I&rsquo;m OK waiting 30 days for protection from new threats</strong>&rdquo; to
continue.</p>
<figure>
<img src="Wordfence-Alert-fs8.png" />
<figcaption>Wordfence Free Version Registration -
Confirmation</figcaption>
</figure>
<p>Enter your email address. Subscribe if you would like to receive the
latest information about the vulnerabilities and check the terms and
conditions. Then click on the &ldquo;<strong>Register</strong>&rdquo; button.</p>
<figure>
<img src="Wordfence-Register-Email-fs8.png" />
<figcaption>Email Sign Up</figcaption>
</figure>
<h3 id="activating-wordfence-license">Activating Wordfence License</h3>
<p>Next, you will receive an activation link and instructions for setting
up the plugin.</p>
<figure>
<img src="Wordfence-License-Activation-Link-fs8-1.png" />
<figcaption>Wordfence License Activation</figcaption>
</figure>
<p>Click on the &ldquo;<strong>Install My License Automatically</strong>&rdquo; button. The license
information will be automatically filled in on your WordPress website
(if you are logged in).</p>
<figure>
<img src="Wordfence-License-Fillup-fs8.png" />
<figcaption>Wordfence with License Information keyed in</figcaption>
</figure>
<p>Click on the &ldquo;Install License&rdquo; button. By this, we have successfully
installed the free version of WordPress. A confirmation dialog will be
shown below.</p>
<figure>
<img src="Wordfence-Free-License-Installed-Message-fs8.png" />
<figcaption>Wordfence Successfully Installed</figcaption>
</figure>
<h3 id="wordfence-dashboard">Wordfence Dashboard</h3>
<p>Click on the &ldquo;<strong>Go to Dashboard</strong>&rdquo; button, and it will take you to
Wordfence Dashboard.</p>
<figure>
<img src="Wordfence-Dashboard-fs8.png" />
<figcaption>Wordfence Dashboard</figcaption>
</figure>
<p>Finally, the &ldquo;<strong>Wordfence Protection Activated</strong>&rdquo; on your website with
standard recommended settings.</p>
<p>Just make sure to enable the &ldquo;<strong>auto-updates,</strong>&rdquo; so you don&rsquo;t need to
update every time manually.</p>
<h3 id="wordfence-scan">Wordfence Scan</h3>
<p>When you install the Wordfence plugin, the standard scan options are
enabled, which is good enough to enable standard security features for
your site. In the above Wordfence Screenshot, click on the &ldquo;<strong>Manage
Scan</strong>&rdquo; link.</p>
<figure>
<img src="manage-scan-fs8.png" />
<figcaption>Wordfence Manage Scan</figcaption>
</figure>
<p>As covered above, the &ldquo;<strong>Standard Scan</strong>&rdquo; is enabled once you activate
the &ldquo;Wordfence&rdquo; plugin.</p>
<p>Additional options, like &ldquo;<strong>High Sensitivity</strong>,&rdquo; can be used to scan and
check if you think your website might be compromised. You can always
click on the &ldquo;<strong>All Options</strong>&rdquo; link on the left side menu and check the
settings that have been enabled.</p>
<p>Go ahead and scan your website for security risks. 😃</p>
<p>I hope the above information is helpful in securing your site. I will be
coming up with options to harden your WordPress website soon.</p>
<h3 id="wordfence-help">Wordfence Help</h3>
<p>Check out the Wordfence site for more help information.</p>
<p><a href="https://www.wordfence.com/help/">Wordfence Help Center</a></p>
<h2 id="conclusion">Conclusion</h2>
<p>Securing the WordPress website is an important factor for website
owners. With the increasing attacks on WordPress, proactive measures
like this help secure your online assets.</p>
<p>Wordfence is a feature-rich WordPress security plugin that is available
for free. It provides a wide range of features to enhance your website&rsquo;s
security, such as checking for malware, firewall protection, Two-Factor
Authentication, etc.</p>
<p>You will be able to see the security posture of your WordPress Site.
Don&rsquo;t wait until it&rsquo;s too late. Enable it now to reduce security
attacks.</p>
]]></content:encoded>
    </item>
    <item>
      <title>WordPress Scan for Vulnerabilities: A Comprehensive Guide for Site Security</title>
      <link>https://raghu.io/wordpress-scan-for-vulnerabilities-a-comprehensive-guide-for-site-security/</link>
      <pubDate>Mon, 05 Feb 2024 17:17:03 +0000</pubDate>
      <guid>https://raghu.io/wordpress-scan-for-vulnerabilities-a-comprehensive-guide-for-site-security/</guid>
      <description>WordPress scan for vulnerabilities article will guide you with step-by-step approaches and examples that can be implemented on your website to scan and identify vulnerabilities. Also, additional information about security measures, tools, and plugins is available.</description>
      <content:encoded><![CDATA[<p>WordPress scan for vulnerabilities article will guide you with
step-by-step approaches and examples that can be implemented on your
website to scan and identify vulnerabilities. Additionally, you will
discover the importance of performing regular scans and reducing
potential risks by implementing the suitable security measures, tools,
and plugins available. Empower yourself with the knowledge and tools to
maintain a secure and resilient WordPress website.</p>
<h2 id="understanding-the-importance-of-vulnerabilities-scans">Understanding the Importance of Vulnerabilities Scans</h2>
<p>In today&rsquo;s digital age, the attack landscape for WordPress sites is
constantly evolving. Cybercriminals are always looking for new ways to
exploit vulnerabilities and compromise the security of websites. As a
WordPress website owner, securing the business and customer data hosted
on your website is crucial.</p>
<p>Below are statistics of the most infected CMS websites in 2022 by
<a href="https://sucuri.net/reports/2022-hacked-website-report/">Sucuri</a>.</p>
<figure>
<img src="sucuri-threat-report.png" />
<figcaption><strong><strong>Source</strong></strong>: <a
href="https://sucuri.net/reports/2022-hacked-website-report/">Sucuri</a></figcaption>
</figure>
<p><strong>Evolving Landscape of WordPress Vulnerabilities in Cyber Security</strong></p>
<p>Cyber threats are becoming more sophisticated than ever. Coming to
WordPress, new vulnerabilities are primarily discovered in third-party
plugins, and some are in themes and WordPress core. Attackers leverage
these vulnerabilities to gain unauthorized access to your website,
spread malware, steal sensitive information, or even disrupt the
functionality of your site. As a result, proactive measures can help you
to address these vulnerabilities before they are exploited.</p>
<p>Below are statistics on vulnerabilities based on WordPress components by
<a href="https://wpscan.com/statistics/">wpscan</a>.</p>
<figure>
<img src="Wordpress-Vulnerable-Components-Statistics-1.png" />
<figcaption><strong><strong>Vulnerable WordPress Components.
Source</strong></strong>: <a
href="https://wpscan.com/statistics/">WPScan</a></figcaption>
</figure>
<p><strong>Risks of ignoring security measures</strong>
<br>
Ignoring security measures for your WordPress site can have severe
consequences. A compromised website can lead to a loss of customer
trust, damage to your brand&rsquo;s reputation, and potential legal and
financial implications.</p>
<p>Additionally, the time and resources required to recover from a security
breach can substantially impact your business operations and revenue.</p>
<p><strong>Benefits of proactive vulnerability scanning</strong>
<br>
Proactively scanning your WordPress site for vulnerabilities offers
several benefits.</p>
<ul>
<li>It allows you to identify and address potential security risks before
malicious actors exploit them.</li>
<li>Vulnerability scans also help you maintain compliance with security
standards and regulations.</li>
<li>It demonstrates your commitment to protecting user data and
maintaining a secure online environment.</li>
</ul>
<h2 id="choosing-the-right-tools-or-plugins-for-vulnerabilities-scans">Choosing the Right Tools or Plugins for Vulnerabilities Scans</h2>
<p>When performing vulnerability scans for your WordPress site, choosing
the right tools or using the recommended security plugins is crucial.
Going ahead, I will cover different options available to scan a website
for security flaws. Pick the one that matches your requirements and
capabilities.</p>
<h3 id="popular-vulnerability-scanning-tools">Popular vulnerability scanning tools</h3>
<p>There are numerous vulnerability scanning tools and plugins designed
specifically for WordPress security. Some popular options include
plugin-based software such as Jetpack Protect, Wordfence, Sucuri
Security, Shield Security, etc. Advanced scanners like Nuclie Scan,
WPScan, CMSeek, etc. These tools offer varying levels of security by
helping you detect vulnerabilities, malware scanning, firewall
protection, and security hardening, and even about how to address
vulnerabilities.</p>
<blockquote>
<p>For this post, our scope would be limited to identifying
vulnerabilities using various tools and taking necessary action based
on identified findings.</p>
</blockquote>
<h3 id="factors-to-consider-when-selecting-a-scanning-tool-or-plugin">Factors to consider when selecting a scanning tool or plugin</h3>
<p>Below are some of the factors that can help select a WordPress security
scanner, i.e. plugin based or online tool:</p>
<ul>
<li>How frequently is the vulnerability database being updated?</li>
<li>What level of support and documentation is available?</li>
<li>Does the tool offer additional specific features like securing login,
APIs, enabling firewalls, notifications, Two-Factor Authentication,
etc?</li>
<li>What is the expected budget vs the tool cost structure?</li>
<li>How effective is it in identifying the vulnerabilities?</li>
<li>Does it support automation and regular interval scans?</li>
<li>How many of your websites need to be protected?</li>
<li>How big is your application, and how many custom-coded functionalities
are used?</li>
</ul>
<p>Above are a few points that help you to select the one that aligns with
your website&rsquo;s security needs. It&rsquo;s important to choose a tool that
provides comprehensive scanning capabilities and is regularly updated to
address new threats.</p>
<h3 id="comparing-free-vs-paid-scanning-options">Comparing free vs. paid scanning options</h3>
<p>While most examples covered in this article will use the free
vulnerability scanning tools available, it&rsquo;s important to weigh the
benefits before investing in a paid solution. Paid options often provide
advanced features, dedicated support, and enhanced protection, making
them a worthwhile investment for the security of your WordPress site.</p>
<h2 id="preliminary-steps-before-performing-a-vulnerabilities-scan">Preliminary Steps Before Performing a Vulnerabilities Scan</h2>
<p>Now that you understand the importance of vulnerability scanning, the
most important step is to ensure your data is safe and ready to restore
at any point in time. </p>
<h3 id="backup-all-your-wordpress-site">Backup all your WordPress site</h3>
<p>Before carrying out any security checks, the first thing to do is to
ensure that a complete website backup is taken and can be easily
restored. This precautionary measure will be helpful in case any
unexpected issues arise. Therefore, data integrity should never be
compromised.</p>
<p>Additionally, the backup should be hosted on a separate server,
different from the one where you are performing the security scan.</p>
<h3 id="update-your-wordpress-site-before-the-scan">Update your WordPress site before the scan</h3>
<p>In most cases, a simple solution to fix the vulnerabilities would be to
update the plugins, theme, and WordPress core. Of course, if you have
customized any of the code, you might need to check the compatibility
before updating.</p>
<p>This step can save efforts and can avoid dealing with vulnerabilities to
which the vendor has already provided patches. Therefore, our results
will be more accurate.</p>
<hr>
<h2 id="step-by-step-guide-to-perform-vulnerabilities-scan">Step-by-Step Guide to Perform Vulnerabilities Scan</h2>
<p>In this section, we will explore a variety of WordPress vulnerability
scanners (i.e., free or partially free) that are readily accessible on
the Internet. We will begin with those that are easy to use and then
move to advanced CLI scanners.</p>
<blockquote>
<p>I have no association with any of the tool vendors that are used
below. All the information provided here is only for educational
purposes.</p>
</blockquote>
<hr>
<h2 id="using-wpsec-automated-wordpress-scanner-online">Using <a href="https://wpsec.com/">WPSEC</a>: Automated WordPress Scanner (Online)</h2>
<p>WPSec is one of the WordPress security scanners out there on the
internet. You can perform a WordPress vulnerability scan online. There
is no need to set up any tools. Start right with the scan.</p>
<p>WPSec is an automated tool that instantly scans your WordPress website
for vulnerabilities. It is an advanced vulnerability scanner that
utilizes WPScanner and custom technology to continuously update its
database with the latest security features and bug fixes.</p>
<p>The tool offers both free and paid plans. For demo purposes, we will use
a free plan.</p>
<blockquote>
<p>Remember to scan only the website you own or have written permission
to.</p>
</blockquote>
<p>Visit the site <a href="https://wpsec.com/"><a href="https://wpsec.com">https://wpsec.com</a></a>, provide the
URL of the WordPress website that you own, and click on the &ldquo;<strong>Start
Scan</strong>&rdquo; button. I will be using my test website as an example here.</p>
<figure>
<img src="WPSEC-InitiateScan.png" />
<figcaption>Using WPSEC to Initiate the Scan</figcaption>
</figure>
<p>It takes a few minutes or less to scan the site, and it immediately
displays the risk information if your website contains any vulnerable
WordPress components.</p>
<figure>
<img src="WPSEC-Vulnerability-Report.png" />
<figcaption>WPSEC WordPress Quick Vulnerability Report</figcaption>
</figure>
<p>On my website, I can see that it displays the message &ldquo;<strong>Your WordPress
website is vulnerable to attack!</strong>&rdquo; and the Risk Factor is <strong>1.8</strong>,
which indicates that security flaws exist and can be used to compromise
the site.</p>
<p>To access the vulnerabilities report and to carry out regular interval
scans, one must register using a valid email address of the same domain.
You can give an email address and click the &ldquo;<strong>Send</strong>&rdquo; button to
complete the &ldquo;<strong>Sign Up</strong>&rdquo; process.</p>
<p>Upon successfully logging into the application, authenticated users will
have a dashboard displaying the total number of WordPress sites added to
their WPSEC account.</p>
<p>On the left side of the tab, click on the &ldquo;<strong>View Reports</strong>&rdquo; link as
displayed below.</p>
<figure>
<img src="WPSEC-View-Reports.png" />
<figcaption>WPSEC - View Reports</figcaption>
</figure>
<p>From the above screen, we can see that my site status is displayed as
&ldquo;<strong>Vulnerable</strong>&rdquo; and can see the scan reports in web, PDF and JSON
formats. Only &ldquo;<strong>web</strong>&rdquo; reports are available in the free edition, and
another type of report would require you to upgrade to a premium
account.</p>
<p>Click on the &ldquo;<strong>Web</strong>&rdquo; report and scroll down to the &ldquo;<strong>Plugins &amp;
Themes</strong>&rdquo; section, where you can find the information on identified
vulnerabilities that could potentially impact the site.</p>
<figure>
<img src="WPSEC-Plugin-and-Themes.png" />
<figcaption>WPSEC Plugins &amp; Themes Section</figcaption>
</figure>
<p>Toggle on the &ldquo;<strong>WP-Booking-System</strong>&rdquo; vulnerable plugin highlighted in
red, and the additional vulnerability information is displayed. It
displays the &ldquo;<strong>Reflected Cross-Site-Scripting Vulnerability</strong>&rdquo; present
in the plugin being used.</p>
<p>Just click on the link, and it will take you to another page displaying
more detailed information about the vulnerability and proof of concept
(POC) on how it can be exploited.</p>
<figure>
<img src="WPSEC-Vulnerabilty-Description.png" />
<figcaption>WPSEC XSS Vulnerability Description</figcaption>
</figure>
<p>From the security analyst&rsquo;s point of view, the above information can
help to verify and confirm the vulnerability.</p>
<p>Attackers use the same vulnerability by modifying the above code to
redirect genuine users to a malicious website, steal session cookies, to
log keystrokes, for phishing, etc.</p>
<p>From a website owner&rsquo;s perspective, Based on the above recommendations,
the following vulnerability can be fixed by upgrading the
&ldquo;<strong>WP-Booking-System</strong>&rdquo; plugin to its latest version, i.e. &ldquo;<strong>2.0.15</strong>&rdquo;.
Therefore, we must update the wp-booking-system plugin to the latest
version to avoid security impact.</p>
<p>Identify similar security vulnerabilities early and fix them as early as
possible. If you use the custom code, make sure the code is patched as
per recommendations.</p>
<p><strong>Scheduling</strong> is one of the built-in features offered by the WPSEC in
the free version, which you can continuously monitor and get regular
updates about the vulnerabilities found.</p>
<figure>
<img src="WPSEC-Schedule.png" />
<figcaption>Scheduling the WordPress scans in regular
intervals</figcaption>
</figure>
<p>To verify, navigate to the &ldquo;<strong>Schedule</strong>&rdquo; section and ensure the regular
scan frequency is set to &ldquo;<strong>Weekly</strong>&quot;. </p>
<p>One of the things I found about this tool is it reported fewer
vulnerabilities compared to other tools. We need to wait and watch if
more coverage will be addressed in future scan results.</p>
<p>You could repeat the steps you learnt to find WordPress vulnerabilities
on your websites.</p>
<hr>
<h2 id="using-jetpack-protect-wordpress-malware-and-security-scanning-plugin">Using <a href="https://jetpack.com/protect/">Jetpack Protect</a>: WordPress Malware and Security Scanning (Plugin)</h2>
<h2></h2>
<p>A WordPress plugin that can help you scan for malware and security
vulnerabilities associated with WordPress Core, themes and plugins.</p>
<p>This would be the second tool that we would be using to scan for
WordPress threats.</p>
<blockquote>
<p>The Jetpack Protect plugin differs from the Jetpack plugin and is
offered separately by the Jetpack team. It is important to note that
there is no dependency between the Jetpack Protect plugin and the
Jetpack plugin.</p>
</blockquote>
<figure>
<img src="About-Jetpack-Protect.png" />
<figcaption>Jetpack Protect total vulnerabilities as of Feb 2024.
<strong><strong>Source</strong></strong>: <a
href="https://jetpack.com/protect/#">Jetpack Website</a></figcaption>
</figure>
<p>The plugin is simple and easy to use.</p>
<p>Jetpack Protect is a totally free plugin that uses the data from
<a href="https://wpscan.com/">WPScan</a>. It is one of the most popular tools used
in the security industry to carry out vulnerability scans on WordPress
websites.</p>
<p>Let&rsquo;s jump right into setting up the plugin.</p>
<p>Log into your WordPress website admin dashboard, Navigate to the plugins
section and click the &ldquo;<strong>Add New Plugin</strong>&rdquo; button.</p>
<figure>
<img src="WordPress-Dashboard-Plugin-Install.png" />
<figcaption>WordPress Add New Plugin</figcaption>
</figure>
<p>The website loads a plugin page and displays all commonly installed
plugins.</p>
<figure>
<img src="Search_jetpack-protect-and-install.png" />
<figcaption>Install Jetpack Protect Plugin</figcaption>
</figure>
<p>Search for the &ldquo;<strong>Jetpact Protect</strong>&rdquo; plugin and click on the &ldquo;<strong>Install
Now</strong>&rdquo; button.</p>
<p>Ensure that you install the plugin offered by the &ldquo;<a href="https://wordpress.org/plugins/jetpack-protect/">Automattic - Jetpack
Security team.</a>&rdquo;</p>
<figure>
<img src="Jetpact-protect-activate.png" />
<figcaption>Activate Jetpack Protect</figcaption>
</figure>
<p>Once installed, click on the &ldquo;<strong>Activate</strong>&rdquo; button as displayed above.</p>
<p>After activation, you will be taken to a subscription page. For
demonstration purposes, I will click on the &ldquo;<strong>Start for free</strong>&rdquo; button
to go ahead. Feel free to explore the premium options as well.</p>
<figure>
<img src="Jetpack-free-plan-select.png" />
<figcaption>Jetpack Protect - Free Plan</figcaption>
</figure>
<p>Once activated, it will immediately start scanning your site for
vulnerabilities. It might take a couple of minutes.</p>
<figure>
<img src="Jetpack-protect-started-scanning.png" />
<figcaption>Jetpack Protect Started Security Scan</figcaption>
</figure>
<p>After successful completion, all the identified threats are displayed,
as shown below.</p>
<figure>
<img src="Jetpack-protect-results.png" />
<figcaption>Jetpack Protect - Threats Results</figcaption>
</figure>
<p>The plugin identified <strong>29</strong> threats on my website, listed above in
detail. Additionally, the summary information about each threat is
displayed on the right side, which helps you take the next action needed
to secure your site. </p>
<p>It also displays a green checkmark for plugins, themes, and core if they
are free from threats. </p>
<figure>
<img src="Jetpack-green-tick-for-all-good.png" />
<figcaption>Jetpack Protect - Green Tick for all threat-free
components</figcaption>
</figure>
<p>Jetpack Protect even allows you to set up a &ldquo;<strong>Firewall</strong>&rdquo; for your
site; feel free to explore. I have just enabled the Firewall to prevent
the brute force attacks on my site&rsquo;s login page, as shown below.</p>
<figure>
<img src="Jetpack-protect-firewall.png" />
<figcaption>Jetpack Firewall - Bruteforce Protect</figcaption>
</figure>
<p>The Jetpack protect plugin is one of the effective ways to secure your
website. The plugin is well-suited for website owners because of its
simplicity and ease of use.</p>
<h2 id="wpscan-cli">WPScan CLI</h2>
<p>Using the Jetpack plugin is a good option when you have admin access to
the WordPress website.</p>
<p>WPScan CLI will be used for one-time scans or security assessments. The
advantage of a CLI scan is that it can be used to perform specific
checks based on the use case, such as checking only for vulnerable
plugins or themes, leaking usernames or config backups, etc.</p>
<p>Its installation is straightforward. To set it up locally, you can use
the gem package manager, docker, or brew. Check out <a href="https://github.com/wpscanteam/wpscan/wiki/WPScan-User-Documentation#installation">WPScan
Installation</a>.</p>
<p>As I have a Gem installed on my system, I will use the Gem to install
it.</p>
<h3 id="wpscan-cli-installation-using-gem">WPScan CLI Installation: (Using Gem)</h3>
<div class="highlight"><pre tabindex="0" class="chroma"><code class="language-bash" data-lang="bash"><span class="line"><span class="cl">gem install wpscan
</span></span></code></pre></div><p><strong>Output:</strong></p>
<div class="captioned-content">
<div class="caption">
<p>WPScan Installation Log</p>
</div>
<div class="highlight"><pre tabindex="0" class="chroma"><code class="language-bash" data-lang="bash"><span class="line"><span class="cl">Fetching public_suffix-5.0.5.gem
</span></span><span class="line"><span class="cl">Successfully installed public_suffix-5.0.5
</span></span><span class="line"><span class="cl">Successfully installed wpscan-3.8.25
</span></span><span class="line"><span class="cl">Parsing documentation <span class="k">for</span> public_suffix-5.0.5
</span></span><span class="line"><span class="cl">Installing ri documentation <span class="k">for</span> public_suffix-5.0.5
</span></span><span class="line"><span class="cl">Parsing documentation <span class="k">for</span> wpscan-3.8.25
</span></span><span class="line"><span class="cl">Done installing documentation <span class="k">for</span> public_suffix, wpscan after <span class="m">0</span> seconds
</span></span><span class="line"><span class="cl"><span class="m">2</span> gems installed
</span></span></code></pre></div></div>
<p>The WPScan CLI tool uses the <a href="https://wpscan.com/api">WordPress Vulnerability Database
API</a> to retrieve WordPress vulnerability data in
real-time. The <strong>–api-token</strong> option requires supplying an API token,
which can be obtained by registering an account on
<a href="https://wpscan.com/register">WPScan.com</a>.</p>
<p>You can use the CLI tool without an API token as well. Only the
vulnerability information will be missing.</p>
<blockquote>
<p>WPScan CLI - The free plan allows 25 API requests per day, which would
meet our requirements. I have already obtained my API token.</p>
</blockquote>
<h3 id="wpscan-using-cli">WPScan using CLI</h3>
<div class="highlight"><pre tabindex="0" class="chroma"><code class="language-bash" data-lang="bash"><span class="line"><span class="cl">$ wpscan --url https://wptest.securityarray.io/ -e vp,vt --plugins-detection mixed --api-token <span class="nv">$WPSCAN_API_TOKEN</span>
</span></span></code></pre></div><ul>
<li>&ldquo;<strong>–url</strong>&rdquo;: The target website to scan for vulnerabilities.</li>
<li>&ldquo;<strong>-e</strong>&rdquo;: Enumerating only for vulnerable plugins and templates.</li>
<li>&ldquo;<strong>–plugins-detection</strong>&rdquo;: Using both passive and aggressive ways to
detect valid plugins on the website.</li>
<li>&ldquo;<strong>–api-token</strong>&rdquo;: Stored WPScan API token in environment variables and
used it for the scan. (You can directly place your API Token Here).</li>
</ul>
<p><strong>Output Log (Log is stripped.)</strong></p>
<div class="captioned-content">
<div class="caption">
<p>WPScan CLI Log</p>
</div>
<div class="highlight"><pre tabindex="0" class="chroma"><code class="language-bash" data-lang="bash"><span class="line"><span class="cl"><span class="o">[</span>+<span class="o">]</span> URL: https://wptest.securityarray.io/ <span class="o">[</span>xx.xxx.xx.xxx<span class="o">]</span>
</span></span><span class="line"><span class="cl">...
</span></span><span class="line"><span class="cl"><span class="o">[</span>+<span class="o">]</span> ninja-forms
</span></span><span class="line"><span class="cl"> <span class="p">|</span> Location: https://wptest.securityarray.io/wp-content/plugins/ninja-forms/
</span></span><span class="line"><span class="cl"> <span class="p">|</span> Last Updated: 2024-03-29T15:38:00.000Z
</span></span><span class="line"><span class="cl"> <span class="p">|</span> Readme: https://wptest.securityarray.io/wp-content/plugins/ninja-forms/readme.txt
</span></span><span class="line"><span class="cl"> <span class="p">|</span> <span class="o">[</span>!<span class="o">]</span> The version is out of date, the latest version is 3.8.2
</span></span><span class="line"><span class="cl"> <span class="p">|</span>
</span></span><span class="line"><span class="cl"> <span class="p">|</span> Found By: Known Locations <span class="o">(</span>Aggressive Detection<span class="o">)</span>
</span></span><span class="line"><span class="cl"> <span class="p">|</span>  - https://wptest.securityarray.io/wp-content/plugins/ninja-forms/, status: <span class="m">200</span>
</span></span><span class="line"><span class="cl"> <span class="p">|</span>
</span></span><span class="line"><span class="cl"> <span class="p">|</span> <span class="o">[</span>!<span class="o">]</span> <span class="m">2</span> vulnerabilities identified:
</span></span><span class="line"><span class="cl"> <span class="p">|</span>
</span></span><span class="line"><span class="cl"> <span class="p">|</span> <span class="o">[</span>!<span class="o">]</span> Title: Ninja Forms Contact Form &lt; 3.8.1 - Publicly Accessible Form Submission Export via CSRF
</span></span><span class="line"><span class="cl"> <span class="p">|</span>     Fixed in: 3.8.1
</span></span><span class="line"><span class="cl"> <span class="p">|</span>     References:
</span></span><span class="line"><span class="cl"> <span class="p">|</span>      - https://wpscan.com/vulnerability/9107e702-e5ef-4328-8265-2a6b98092b3a
</span></span><span class="line"><span class="cl"> <span class="p">|</span>      - https://cve.mitre.org/cgi-bin/cvename.cgi?name<span class="o">=</span>CVE-2024-2113
</span></span><span class="line"><span class="cl"> <span class="p">|</span>      - https://www.wordfence.com/threat-intel/vulnerabilities/id/3ebfc9f5-abb7-47bc-bd38-f60df1cccb5d
</span></span><span class="line"><span class="cl"> <span class="p">|</span>
</span></span><span class="line"><span class="cl"> <span class="p">|</span> <span class="o">[</span>!<span class="o">]</span> Title: Ninja Forms Contact Form &lt; 3.8.1 - Author+ Stored XSS
</span></span><span class="line"><span class="cl"> <span class="p">|</span>     Fixed in: 3.8.1
</span></span><span class="line"><span class="cl"> <span class="p">|</span>     References:
</span></span><span class="line"><span class="cl"> <span class="p">|</span>      - https://wpscan.com/vulnerability/c89ce032-c361-49e2-8ed0-c806bf399d96
</span></span><span class="line"><span class="cl"> <span class="p">|</span>      - https://cve.mitre.org/cgi-bin/cvename.cgi?name<span class="o">=</span>CVE-2024-2108
</span></span><span class="line"><span class="cl"> <span class="p">|</span>      - https://www.wordfence.com/threat-intel/vulnerabilities/id/6a6eb430-cf86-4e13-a4f7-173fada9fddf
</span></span><span class="line"><span class="cl"> <span class="p">|</span>
</span></span><span class="line"><span class="cl"> <span class="p">|</span> Version: 3.8.0 <span class="o">(</span>80% confidence<span class="o">)</span>
</span></span><span class="line"><span class="cl"> <span class="p">|</span> Found By: Readme - Stable Tag <span class="o">(</span>Aggressive Detection<span class="o">)</span>
</span></span><span class="line"><span class="cl"> <span class="p">|</span>  - https://wptest.securityarray.io/wp-content/plugins/ninja-forms/readme.txt
</span></span><span class="line"><span class="cl">
</span></span><span class="line"><span class="cl">...
</span></span></code></pre></div></div>
<p>The scans will take a few minutes to complete, and once they are
completed, you can check the identified vulnerabilities displayed above.</p>
<hr>
<h2 id="using-wordfence-security-plugin">Using Wordfence Security Plugin</h2>
<p>Like Jetpack, Wordfence is another security plugin with many more
features that can help scan your WordPress site for known
vulnerabilities and malware.</p>
<p>Check out the below bookmark to learn more about the WordFence Security
Plugin.</p>
<p><a href="/how-to-install-wordfence/">How to Install Wordfence</a></p>
<hr>
<h3 id="offline-tools"><strong>Offline Tools</strong></h3>
<p>In this article, we covered a couple of WordPress vulnerability scanners
that are user-friendly and beneficial for website owners. Moving
forward, we will discuss one of the customizable vulnerability scanners
commonly used by security professionals. Website owners can also
consider trying it out for their websites.</p>
<h2 id="using-nuclei-customizable-vulnerability-scanner">Using <a href="https://github.com/projectdiscovery/nuclei">nuclei</a>: Customizable Vulnerability Scanner</h2>
<p>Nuclei is a fast and customizable vulnerability scanner that identifies
vulnerabilities based on the YAML-based rules. Nucli is a CLI tool built
with Golang, and you would need a Golang installed to run from your
local system.</p>
<p>Nuclei alone cannot find vulnerabilities, as it&rsquo;s just an engine that
runs any given rules. These rule sets are called as
<a href="https://github.com/projectdiscovery/nuclei-templates">nuclei-templates</a>.
By default, the nuclei tool downloads the templates on the first run, so
you don&rsquo;t need to download them separately. Both nuclei and nuclei
templates are open-source and freely available on GitHub. </p>
<p>To keep things minimal, I will focus only on running the scans on my
local demo website. To learn more about the installation and usage of
the nuclei tool, check out
<a href="https://github.com/projectdiscovery/nuclei">here</a>.</p>
<p><strong>Default Nuclei Templates vs External Templates</strong></p>
<p>Yes, we can run nuclei scans with the default templates. Default
templates are the collection of community contributions with a wide
range of vulnerability identification rule sets. Compared to the default
one
&ldquo;<a href="https://github.com/topscoder/nuclei-wordfence-cve">nuclei-wordfence-cve</a>&rdquo;
templates, which have more WordPress vulnerability identification
templates that are taken from the Wordfence reports.</p>
<p>The effectiveness of the Nuclie scanner is directly tied to the quality
of the nuclei-templates. The better templates you can find, the better
the vulnerabilities. Some security professionals would prefer to write
their custom templates.</p>
<p><strong>Nuclei Scan with Nuclei Wordfence CVE Templates</strong></p>
<p><strong>Command:</strong></p>
<div class="highlight"><pre tabindex="0" class="chroma"><code class="language-Bash" data-lang="Bash"><span class="line"><span class="cl">nuclei -u https://wptest.local -t nuclei-wordfence-cve/ -o results.txt
</span></span></code></pre></div><ul>
<li>&ldquo;<strong>nuclei</strong>&rdquo; is the command used to trigger the scan.</li>
<li>&ldquo;<strong>-u</strong>&rdquo; is the option used to specify the URL of a website which you
want the tool to scan for. </li>
<li>&ldquo;<strong>-t</strong>&rdquo; is to specify a file or folder of templates that need to be
used for scanning the given target.</li>
<li>&ldquo;<strong>-o</strong>&rdquo; is to write the results output to a text file, which can be
used further. Check out help information, as other types of results
are also available.</li>
</ul>
<p><strong>Results:</strong></p>
<figure>
<img src="Nuclei-Scan-Results.png" />
<figcaption>Nuclei Scan Results</figcaption>
</figure>
<p>The scan is completed, and a few <strong>critical</strong>, <strong>high</strong>, and
<strong>medium-severity</strong> vulnerabilities have been identified on my website.</p>
<p><strong>Command to run Nuclei with default templates</strong></p>
<p><strong>Command:</strong></p>
<div class="highlight"><pre tabindex="0" class="chroma"><code class="language-Bash" data-lang="Bash"><span class="line"><span class="cl">nuclei -u https://wptest.local -o results.txt -tags wordpress
</span></span></code></pre></div><ul>
<li>&ldquo;<strong>-tags</strong>&rdquo; is the command to run specific tag-based templates only.
Here, in our command, I am using the keyword called &ldquo;<strong>wordpress</strong>&rdquo;.</li>
</ul>
<p>From the huge list of default templates, only the WordPress-based
templates will be loaded for scanning. Give it a try and observe how the
vulnerabilities&rsquo; results differ.</p>
<p>Now, we need to take the CVE IDs and search across Google to find more
about that vulnerability and how it can be exploited/mitigated.</p>
<p><strong>For Example: CVE-2023-52134</strong></p>
<figure>
<img src="CVE-Search.png" />
<figcaption>Searching for CVE on Google</figcaption>
</figure>
<p>Going through the search results, I will select the first one from the
<a href="https://nvd.nist.gov/vuln/detail/CVE-2023-52134">National Vulnerability
Database</a>.</p>
<img loading="lazy" src="/wordpress-scan-for-vulnerabilities-a-comprehensive-guide-for-site-security/CVE_Details-NVD.png"><p>Other Reference:
<a href="https://wpscan.com/vulnerability/eef61b02-2f18-4140-9778-46e52a1664c4/">https://wpscan.com/vulnerability/eef61b02-2f18-4140-9778-46e52a1664c4/</a></p>
<p>From the above description, we can understand that the vulnerability is
in the improper handling of the SQL queries in the &ldquo;<strong>geo-my-wp</strong>&rdquo;
plugin, which leads to an <strong>SQL injection</strong> and is fixed in version
<strong>4.0.3</strong>.</p>
<p>As part of the security assessment, it can be taken further ahead for
exploitation or can be reported directly based on the version
information.</p>
<p>We have covered a huge base of different ways to scan WordPress
vulnerability scanners to help you get started in identifying
vulnerabilities.</p>
<hr>
<h2 id="addressing-vulnerabilities-and-implementing-security-measures">Addressing Vulnerabilities and Implementing Security Measures</h2>
<p>Knowing about the common vulnerabilities in WordPress sites is essential
for effectively addressing and mitigating potential security risks.</p>
<p><strong>Interpreting the scan results</strong></p>
<p>Once the scan is complete, review all the results and identify
potentially impactful security threats. Start addressing all the
critical ones that require immediate attention, then move to high
severity, followed by medium and low vulnerabilities to secure your
site. </p>
<p><strong>Implementing security measures to prevent future vulnerabilities</strong></p>
<p>When addressing the vulnerabilities identified, follow best practices
such as updating WordPress core, themes, and plugins.</p>
<p>Sometimes, we may not have the fix released by the vendor. This is where
configuring a web application firewall is an additional line of defence
to protect against common attack vectors.</p>
<p>In addition to addressing identified vulnerabilities, implementing
security measures such as regular backups, SSL/TLS encryption, and
security headers can help prevent future vulnerabilities and enhance the
overall security posture of your WordPress site.</p>
<p>WordPress even offers to enable auto-updates of plugins, which can be
updated regularly.</p>
<hr>
<h2 id="enhancing-the-securing-of-wordpress-sites">Enhancing the Securing of WordPress Sites</h2>
<p>Check out the article below, which provides step-by-step instructions on
how to secure your WordPress websites.</p>
<p><a href="/enhancing-the-security-of-wordpress-sites-best-practices-and-tips/">Enhancing the Security of WordPress
Sites</a></p>
<hr>
<h2 id="automating-vulnerabilities-scans-for-ongoing-protection">Automating Vulnerabilities Scans for Ongoing Protection</h2>
<p>To maintain a secure and resilient WordPress site, it&rsquo;s essential to
automate vulnerability scans for ongoing protection. The manual approach
may not be feasible all the time.</p>
<h3 id="the-importance-of-regular-and-automated-scans">The importance of regular and automated scans</h3>
<p>Regular and automated vulnerability scans ensure your WordPress site is
continuously monitored for potential security risks. By scheduling scans
at regular intervals, you can stay ahead of emerging threats and
proactively address vulnerabilities.</p>
<h3 id="utilizing-alerts-and-notifications-for-immediate-action">Utilizing alerts and notifications for immediate action</h3>
<p>Configure alerts and notifications within your WordPress security
scanner, if available. This helps you to receive immediate notifications
of any identified vulnerabilities.  It allows you to address security
issues and prevent potential exploitation immediately.</p>
<hr>
<h2 id="analyzing-your-wordpress-security-needs">Analyzing your WordPress security needs:</h2>
<p><br>
<strong>Using WordPress security plugin (DIY)</strong></p>
<p>Website owners who would like to do it themselves can use any WordPress
security scan plugins to get started.</p>
<p>As the requirements grow or you need to handle sensitive customer data
or when managing multiple websites that require dedicated time to focus
on business, seeking professional assistance might be beneficial to
reduce the potential impact of data breaches on your business. Here, you
could opt for an online subscription or hire a professional service.</p>
<h3 id="seeking-professional-vulnerability-management-services">Seeking professional vulnerability management services</h3>
<p>Professional vulnerability management services offer a wide range of
expertise, advanced tools, and proactive monitoring to identify and
address potential security threats, providing peace of mind and enhanced
protection for your website.</p>
<hr>
<img loading="lazy" src="/wordpress-scan-for-vulnerabilities-a-comprehensive-guide-for-site-security/idea.png"><h2 id="conclusion">Conclusion</h2>
<p>The above information can help you empower yourself with proactive
WordPress security scanning measures to maintain a secure and resilient
website. For website owners, I would recommend to get started with
Jetpack Protect. Security Professionals or Ethical hackers who want to
conduct vulnerability assessments, starting with the wpscan and Nuclie
scans, would be a good start. By understanding the importance of regular
vulnerability scans, choosing the right tools or plugins, and
implementing best practices, you can take control of your website&rsquo;s
security.</p>
<hr>
<h2 id="additional-references">Additional References</h2>
<p>Check out the bookmark below to learn more about the additional
WordPress website security scanners online.</p>
<p><a href="https://www.wpbeginner.com/showcase/best-wordpress-vulnerability-scanners-online/">14 Best WordPress Security Scanners for Detecting Malware and
Hacks</a> -
A comprehensive list of WordPress security scanners by WPBeginner.</p>
<h2></h2>
]]></content:encoded>
    </item>
    <item>
      <title>Bug Bounty vs Pentest: Making an Informed Decision on Security Testing</title>
      <link>https://raghu.io/bug-bounty-vs-pentest-making-an-informed-decision-on-security-testing/</link>
      <pubDate>Sun, 14 Jan 2024 03:29:08 +0000</pubDate>
      <guid>https://raghu.io/bug-bounty-vs-pentest-making-an-informed-decision-on-security-testing/</guid>
      <description>Both bug bounty and pentest play crucial roles in identifying and addressing security vulnerabilities, but they differ in their approaches. Understanding these differences helps you choose which type of security testing best suits for organizations or hackers who want to get into security testing.</description>
      <content:encoded><![CDATA[<p>It looks like you want to know better about what bug bounty is and how
it differs from pentest for your security needs. This article will break
down the differences, benefits, and drawbacks of each to help you make
an informed decision. Whether you&rsquo;re a beginner in security, a project
manager, or a security professional, this article will help you choose
the right approach for your specific security needs.</p>
<h2 id="introduction-to-bug-bounty-and-pentest">Introduction to Bug Bounty and Pentest</h2>
<p>In today&rsquo;s digital landscape, where cyber threats constantly evolve,
organizations increasingly turn to security testing, and we keep on
hearing about the words bug bounty programs and pentests to enhance
security measures.</p>
<p>Both bug bounty and pentest play crucial roles in identifying and
addressing security vulnerabilities, but they differ in their
approaches. Understanding these differences helps you choose which type
of security testing best suits for organizations or hackers who want to
get into security testing.</p>
<figure>
<img src="BugBounty-vs-Pentest-Definetion.png" />
<figcaption>Bug Bounty vs Pentest</figcaption>
</figure>
<h2 id="bug-bounty-explained">Bug Bounty Explained</h2>
<h3 id="what-is-bug-bounty">What is Bug Bounty?</h3>
<p>Individual organizations implement a program to reward external security
researchers for identifying and reporting security bugs in their
applications and systems.</p>
<p>This program helps organizations uncover the security gaps that haven&rsquo;t
been considered or missed in their security assessments. Addressing the
reported security findings in the early stages helps to strengthen the
organization&rsquo;s critical applications and systems before malicious actors
exploit them.</p>
<p>Depending on the organization&rsquo;s policies, they even acknowledge and
reward the researchers for responsibly disclosing the security flaws in
their systems. The rewards might vary, like incentives, hall-of-fame
credits, points, s, etc.</p>
<p>This process is also known as <strong>crowdsource security testing</strong> or
<strong>Vulnerability Reward Programs</strong> (VRPs), which invites all independent
security researchers around the world to participate in the program.
This approach also enables organizations to tap into a global talent
pool of cybersecurity experts and leverage their diverse skill sets to
uncover potential security flaws.</p>
<h3 id="how-bug-bounty-programs-work">How Bug Bounty Programs Work?</h3>
<ol>
<li>
<p>Organizations define the scope of their bug bounty program, which
includes the systems, applications, guidelines, rewards structure,
and types of vulnerabilities eligible for rewards.</p>
</li>
<li>
<p>Independent Security Researchers (aka Bug bounty hunters) then
conduct security testing within the specified scope and report any
discovered vulnerabilities to the organization&rsquo;s security team.</p>
</li>
<li>
<p>Upon successful validation, the security bug is triaged.
Post-triaging, the organization rewards the bug bounty hunter
according to a predetermined bounty structure.</p>
</li>
</ol>
<p><em>Remember, if everyone reports the same bug, only the first person to
report will receive the bounty.</em></p>
<h3 id="what-are-bug-bounty-platforms">What are Bug Bounty Platforms?</h3>
<p>A central hub that manages multiple organizations&rsquo; Bug Bounty programs
and a pool of bug bounty hunters.</p>
<p>Bug bounty platforms bridge organizations and bug bounty hunters by
establishing clear guidelines and policies for researchers, streamlining
the vulnerability management process, facilitating efficient
communication, timely resolution of reported security issues, and
rewarding researchers.</p>
<p>They oversee the entire bug bounty program life cycle, making each party
understand their roles and responsibilities in a well-organized and
efficient way.</p>
<p>It&rsquo;s a less hindering process for organizations and Security Enthusiasts
who are getting started.</p>
<p>Examples: <a href="https://www.hackerone.com/">HackerOne</a>,
<a href="https://www.bugcrowd.com/">BugCrowd</a>,
<a href="https://www.intigriti.com/">Intigrity</a>,
<a href="https://bounty.github.com/">Github</a></p>
<p>Refer
<a href="https://github.com/EdOverflow/bugbounty-cheatsheet/blob/master/cheatsheets/bugbountyplatforms.md">here</a>
for information about more platforms.</p>
<h3 id="who-can-start-a-bug-bounty-program">Who can start a Bug Bounty program?</h3>
<p>Any organization that decides to minimize security risks and secure its
digital data from attackers can start a bug bounty program.</p>
<p>Currently, reputed organizations ranging from government entities,
e-commerce platforms, software solutions, logistics companies, finance
organizations, open-source programs, etc, all run bug bounty programs.</p>
<p>If you ever feel that managing security vulnerabilities is daunting,
don&rsquo;t hesitate to utilize Bug Bounty platforms. They are readily
available to provide assistance and support.</p>
<p>Bug Bounty programs are instrumental in reducing unknown threats.</p>
<p>Examples: <a href="https://bughunters.google.com/">Google Bug Hunters</a>, <a href="https://www.facebook.com/whitehat">Meta
(aka Facebook)</a>,
<a href="https://www.microsoft.com/en-us/msrc/bounty">Microsoft</a></p>
<h3 id="who-can-participate-in-a-bug-bounty-program">Who can participate in a Bug Bounty program?</h3>
<p>Well, there are no hard rules. Anyone with internet access having
experience/interest in learning security testing can jump into the
program and try it.<br>
<br>
The Bug Bounty program is available for different security streams, web
applications, mobile applications, binary applications, source code
review, IOT, etc. Feel free to choose the one that is of most interest
to you.</p>
<h3 id="key-features-of-bug-bounty">Key Features of Bug Bounty</h3>
<ul>
<li><strong>Global Talent Pool</strong>: Bug bounty programs allow organizations to
access a diverse community of security researchers with varying
expertise and perspectives.</li>
<li><strong>Continuous Testing</strong>: Bug bounty programs enable ongoing security
testing, as researchers can continuously search for vulnerabilities,
providing a proactive approach to security. </li>
<li><strong>Cost-Effective</strong>: Organizations only pay for valid vulnerabilities
identified, making bug bounty programs a cost-effective security
testing solution.</li>
</ul>
<figure>
<img src="hacker--1-.png" />
<figcaption>Penetration Testing</figcaption>
</figure>
<h2 id="pentest-explained">Pentest Explained </h2>
<h3 id="heading">\</h3>
<p>What is Pentest?</p>
<p>Penetration testing, often abbreviated as pentest or pentesting, is a
simulated cyber-attack on a computer system, network, or web application
to identify security weaknesses. This assessment thoroughly evaluates an
organization&rsquo;s IT infrastructure by deliberately attempting to exploit
weaknesses in a controlled environment.</p>
<p>Penetration testing is conducted by the organization&rsquo;s internal staff or
in collaboration with reputable service providers in the market.</p>
<p>It aims to identify security gaps and provides actionable insights to
improve the organization&rsquo;s overall security.</p>
<h3 id="types-of-pentesting">Types of Pentesting</h3>
<p>There are various types of penetration testing, including network
penetration testing, web application penetration testing, mobile
application penetration testing, etc. Each type focuses on specific
areas of an organization&rsquo;s IT infrastructure and applications, providing
a comprehensive assessment of security vulnerabilities.</p>
<h3 id="key-features-of-pentest">Key Features of Pentest</h3>
<ul>
<li><strong>Comprehensive Testing</strong>: Pentesting offers a holistic evaluation of
an organization&rsquo;s security posture by simulating real-world attack
scenarios across different systems and applications.</li>
<li><strong>Controlled Environment</strong>: Pentests are conducted in a controlled
environment, allowing organizations to manage the testing process and
minimize potential disruptions to their operations.</li>
<li><strong>Detailed Reporting</strong>: Pentest reports provide in-depth insights into
identified vulnerabilities and actionable recommendations to mitigate
security risks.</li>
</ul>
<h3 id="importance-of-security-testing">Importance of Security Testing</h3>
<p>Both bug bounty programs and penetration testing are crucial components
of a comprehensive security strategy. They help organizations
proactively identify and address vulnerabilities before malicious actors
can exploit them, thereby reducing the risk of a data breach. By
conducting security testing, organizations can enhance their overall
security posture and build trust with their customers and stakeholders.</p>
<figure>
<img src="arrows--1-.png" />
<figcaption>Understanding the Differences</figcaption>
</figure>
<h2 id="understanding-the-differences">Understanding the Differences</h2>
<h3 id="heading-1">\</h3>
<p>Approach and Methodology</p>
<p>Bug bounty programs rely on the collective expertise of a global
community of researchers, leveraging their diverse approaches and
methodologies to uncover vulnerabilities. In contrast, penetration
testing follows a structured methodology and best practices, often
tailored to the specific needs and requirements of the organization.</p>
<h3 id="scope-and-coverage">Scope and Coverage</h3>
<p>Bug bounty programs offer a broader scope, allowing researchers to test
various systems and applications using a wide range of techniques.
However, the scope of a penetration test can be customized to focus on
specific areas of concern within an organization&rsquo;s IT infrastructure.
(Say like test only network devices, mobile applications, biometric
devices, etc.)</p>
<h3 id="cost-and-resource-allocation">Cost and Resource Allocation</h3>
<p>Bug bounty programs operate on a pay-for-results model, where
organizations only pay for valid vulnerabilities identified. On the
other hand, penetration testing typically involves upfront costs,
time-bound, and resource allocation for engaging a specialized security
testing team or service provider. </p>
<h3 id="scalability">Scalability</h3>
<p>The vulnerability reward program (VRPs) enables organizations to quickly
initiate large-scale security testing for their internet-facing
applications with limited resources. In contrast, penetration testing
requires a substantial team, time, and knowledgeable resources to
establish a trusted platform at scale.</p>
<figure>
<img src="BugBounty-vs-Pentest-Benefits-1.png" />
<figcaption>Benefits of Bug Bounty vs Pentest</figcaption>
</figure>
<h2 id="benefits-of-bug-bounty">Benefits of Bug Bounty</h2>
<h3 id="heading-2">\</h3>
<p>Diverse Skill Set</p>
<p>Bug bounty programs enable organizations to harness the diverse skill
sets and perspectives of a global community of security researchers,
providing a wide range of expertise in identifying vulnerabilities.</p>
<h3 id="continuous-testing">Continuous Testing</h3>
<p>Bug bounty programs facilitate ongoing security testing, allowing
organizations to identify and address vulnerabilities as new threats
emerge continuously.</p>
<p>The moment when a
<a href="https://en.wikipedia.org/wiki/Zero-day_%28computing%29">zero-day</a>
vulnerability is first known to the community, the bounty hunters would
be the first to try it out on organization systems or applications they
were working on and raise the security flaw immediately within a few
hours. This trend can generally spotted where their incentives are
generally high.</p>
<h3 id="cost-effective">Cost-Effective</h3>
<p>Bug bounty programs offer a cost-effective approach to security testing,
as organizations only pay for valid and unique vulnerabilities
identified by researchers.</p>
<h3 id="researchers-verification">Researchers Verification</h3>
<p>Some organizations that host bounty programs under the managed Bug
Bounty platforms even request to verify the details of the security
researchers before allowing them into the bug bounty program. This is an
additional measure taken care of by the platforms themselves and helps
to build trust.</p>
<h2 id="benefits-of-pentest">Benefits of Pentest</h2>
<h3 id="heading-3">\</h3>
<p>Comprehensive Testing</p>
<p>Penetration testing provides a comprehensive evaluation of an
organization&rsquo;s security posture, identifying vulnerabilities across
different systems and applications.</p>
<p>Generally, penetration testing is carried out either by the
organization&rsquo;s internal security team or by the external service
provider to secure the business&rsquo;s critical assets from external
attackers.</p>
<p>When an internal team performs pen-testing, they might have access to
the application architecture diagrams, documentation, development team
support, and source code to provide extensive coverage.</p>
<p>Every possibility of security risk identified is documented, from low
severity to high-severity issues in the applications or in
network-connected devices. Based on risk assessment, impactful security
vulnerabilities are addressed as a priority.</p>
<h3 id="controlled-environment">Controlled Environment</h3>
<p>Pentests are conducted in a controlled environment, allowing
organizations to manage the testing process and minimize potential
disruptions to their operations.</p>
<p>In some cases, penetration testing is performed on non-production
environments to minimize the impact on customers, which would be an
exact replica of what would be going into production.</p>
<p>All the security assessments are carried out in stages and segregated
into specific groups like network security, web security, mobile
security, etc.</p>
<h3 id="detailed-reporting">Detailed Reporting</h3>
<p>Pentest reports offer detailed insights into identified vulnerabilities,
along with actionable recommendations to strengthen the organization&rsquo;s
security defenses.</p>
<p>Business stakeholders review and direct the teams to take action to
minimize the security risks, ranging from high-impact to low-impact
business risks. Also, monitor the security health of their organization.</p>
<p>Overall, the organization&rsquo;s security posture will be known with this
approach.</p>
<h3 id="compliances-and-best-practices">Compliances and Best Practices</h3>
<p>Penetration testing is also essential for meeting industry regulations,
best practices, and standards. Based on the data criticality, it must be
carried out at regular intervals.</p>
<hr>
<figure>
<img src="BugBounty-vs-Pentest-Drawbacks.png" />
<figcaption>Drawbacks of Bug Bounty vs Pentest</figcaption>
</figure>
<h2 id="drawbacks-of-bug-bounty">Drawbacks of Bug Bounty</h2>
<h3 id="heading-4">\</h3>
<p>Limited Control</p>
<p>Organizations have limited control over the testing process in bug
bounty programs, as researchers operate independently and may or may not
adhere to specific testing guidelines.</p>
<p>In Bug bounty programs, even though organizations define a detailed
scope of requirements of what is allowed and what is not, like using
automated tools or looking out for specific categories of
vulnerabilities as part of security testing, it depends on individual
security researchers.</p>
<p>Bug bounty hunters are even banned or removed from the program in case
of deviations from the given scope.</p>
<h3 id="public-disclosure-of-vulnerabilities">Public Disclosure of Vulnerabilities</h3>
<p>Poorly managed Bug bounty programs may lead to public disclosure of
vulnerabilities, potentially impacting an organization&rsquo;s reputation.</p>
<p>In bug bounty hunting, a researcher must report a vulnerability and has
to wait for a duration, say 60-90 days, for acknowledgment. Upon not
receiving any communication from the organization for the given time
frame, a researcher might disclose the bug publicly. This generally
happens only in the case of an ineffective program.</p>
<h3 id="variable-results">Variable Results</h3>
<p>The effectiveness of bug bounty programs can vary, as the identification
of vulnerabilities depends on the skills and motivations of
participating researchers.</p>
<p>The participating researchers are from a wide pool of knowledge
backgrounds. It can be a security researcher, a software developer
interested in security, a passionate system administrator, a college
student interested in bug bounties, etc.</p>
<p>Bug bounty hunters, in some cases, focus only on a single target, which
gives them higher chances of finding a bug by carefully monitoring the
changes and immediately reporting the misconfigured ones.</p>
<p>On the other hand, some bounty hunters only take one category of
vulnerability and keep reporting it in each application whenever they
find it.</p>
<p>All the approach varies based on the perspective of the bug bounty
hunter.</p>
<h2 id="drawbacks-of-pentest">Drawbacks of Pentest</h2>
<h3 id="heading-5">\</h3>
<p>Time-Consuming</p>
<p>Penetration testing can be time-consuming, especially for comprehensive
assessments that cover multiple systems and applications within an
organization&rsquo;s IT infrastructure.</p>
<p>It requires multiple parties to be involved, allocating resources, and
shorter time intervals might be provided when in a hurry for production
releases.</p>
<h3 id="limited-scope">Limited Scope</h3>
<p>The scope of a penetration test may be limited based on the specific
areas of concern identified by the organization, potentially overlooking
vulnerabilities in other areas.</p>
<h3 id="higher-cost">Higher Cost</h3>
<p>Engaging in penetration testing typically involves higher upfront costs
and resource allocation compared to bug bounty programs.</p>
<figure>
<img src="decision-making.png" />
<figcaption>Making an Informed Decision</figcaption>
</figure>
<h2 id="making-an-informed-decision">Making an Informed Decision</h2>
<h3 id="heading-6">\</h3>
<p>Assess Your Security Needs</p>
<p>Organizations should assess their specific security needs by considering
factors such as the complexity of their IT infrastructure, the
sensitivity of their data being maintained, and the potential impact of
security vulnerabilities.</p>
<h3 id="considering-budget-and-resources">Considering Budget and Resources</h3>
<p>Budgetary constraints and the availability of a security skillset play a
significant role in determining whether bug bounty programs or
penetration testing is a more viable security testing solution for an
organization.</p>
<h3 id="evaluating-long-term-goals">Evaluating Long-Term Goals</h3>
<p>Organizations should consider their long-term security goals and the
level of control they require over the security testing process when
choosing between bug bounty programs and penetration testing.</p>
<h3 id="for-bug-bounty-hunters">For Bug Bounty Hunters</h3>
<p>Whether you want to learn Bug Bounty or Penetration testing, penetration
testing is much rewarded for building a professional career. If you
would like to do some side hustle and earn some extra bucks, Bug Bounty
might be the best choice. Rarely, a few hackers built a career from Bug
Bounty, but it requires patience and time and has a very steep learning
curve.</p>
<figure>
<img src="idea.png" />
<figcaption>Conclusion</figcaption>
</figure>
<h2 id="conclusion">Conclusion</h2>
<p>In summary, bug bounty programs and penetration tests each offer unique
benefits and drawbacks, catering to different security needs.</p>
<p>Organizations, by carefully evaluating the differences and considering
specific requirements like the scope of testing, the level of control
required, and the budgetary constraints, determine the most suitable
approach for addressing security vulnerabilities, which can help to
enhance your security posture effectively.</p>
<p>For Bug Bounty hunters, consider your skill set and the time available
to choose the one that suits you best. Both required similar skill sets,
but the approaches and efforts vary.</p>
<p>In the ever-evolving cybersecurity landscape, one must adapt to changing
security testing strategies to mitigate risks and protect digital assets
effectively. Whether through bug bounty programs, penetration testing,
or a combination of both, proactive security testing is essential for
safeguarding against potential threats and maintaining a robust security
posture.</p>
]]></content:encoded>
    </item>
    <item>
      <title>Challenge 14: XSS bypass blacklisted JS function</title>
      <link>https://raghu.io/xss-bypass-blacklisted-js-function-challenge-14/</link>
      <pubDate>Tue, 21 Mar 2023 06:30:20 +0000</pubDate>
      <guid>https://raghu.io/xss-bypass-blacklisted-js-function-challenge-14/</guid>
      <description>This article goes into depth discussing an alternative JavaScript function, namely &amp;#34;confirm()&amp;#34;. It serves as an alternative for the JavaScript &amp;#34;alert()&amp;#34; function when the latter is unavailable.</description>
      <content:encoded><![CDATA[<p>Welcome back! In this article, you will learn about one more tip that
can be used while exploiting cross-site scripting.</p>
<p>Before getting started, ensure your Kurukshetra lab is up and running.
Feel free to refer back to the below link.</p>
<p><a href="/xss-explained-learn-cross-site-scripting-with-examples/">XSS Explained - Learn Cross-Site Scripting with
Examples</a></p>
<hr>
<img loading="lazy" src="/xss-bypass-blacklisted-js-function-challenge-14/image-49.png"><h2 id="xss-challenge-walkthrough">XSS Challenge Walkthrough</h2>
<p>Once your Kurukshetra XSS lab environment is up and running, Visit
<a href="http://localhost:8066/"><a href="http://localhost:8066">http://localhost:8066</a></a> and navigate to “<a href="http://localhost:8066/ch14.php">XSS
Challenge 14</a>“.</p>
<figure>
<img src="Kurukshetra-XSS-Challenge-Page-14-fs8.png" />
<figcaption>XSS Challenge Page 14 with payload</figcaption>
</figure>
<p>The above input field labeled “<strong>Try your XSS payload here?</strong>” is
displayed.</p>
<p>Key info is in the classic XSS payload, which has been used throughout
while testing for XSS, and click on the “<strong>Submit</strong>” button.</p>
<p><strong>XSS Payload</strong></p>
<img loading="lazy" src="/xss-bypass-blacklisted-js-function-challenge-14/image-51.png"><p><strong><u>Output:</u></strong></p>
<figure>
<img src="CH14-Input-Result-fs8.png" />
<figcaption>XSS Payload Input Result</figcaption>
</figure>
<p><br>
The application doesn&rsquo;t display any info on the page. Right-click and
select “<strong>View page source</strong>” to analyze how the appended payload got
reflected in the HTML response.</p>
<p><strong>Viewing HTML Source</strong></p>
<figure>
<img src="image-53.png" />
<figcaption>XSS Payload in HTML Source Code</figcaption>
</figure>
<p>In the above output, the javascript “<code>alert()</code>” function is missing.</p>
<p>Let&rsquo;s go ahead and give it a try with an HTML body tag-based XSS payload
to confirm if the “<code>alert()</code>” function is being filtered in the script
tag itself or from all inputs.</p>
<p><strong>XSS Payload 2</strong></p>
<img loading="lazy" src="/xss-bypass-blacklisted-js-function-challenge-14/image-54.png"><p><strong><u>HTML Source Output:</u></strong></p>
<figure>
<img src="image-55.png" />
<figcaption>XSS Payload in HTML Page Source</figcaption>
</figure>
<p>From the above output, it can be confirmed that the JavaScript
“<code>alert()</code>” is being filtered out in all the inputs given.</p>
<p>In the current scenario, the JavaScript function “<code>alert()</code>” is
commonly used by attackers to execute arbitrary code. This type of
blacklisting approach used to prevent XSS attacks involves identifying
and blocking specific strings or functions that could be used by
attackers to inject malicious code into a web application.</p>
<p>The major drawback of this approach is the developers need to update the
impactful functions/commands to the blacklist continuously.</p>
<figure>
<img src="image-56.png" />
<figcaption>Any other JavaScript function to try?</figcaption>
</figure>
<p>By removing or disabling these functions, web developers hope to prevent
attackers from exploiting XSS vulnerabilities in their applications.
However, this approach is often ineffective, as attackers can simply use
alternative methods to execute their payloads, such as using
&ldquo;<strong>confirm()&rdquo;</strong>, &ldquo;<strong>prompt()&rdquo;</strong>, &ldquo;<strong>console.log()&rdquo;</strong> or constructing
their own functions.</p>
<img loading="lazy" src="/xss-bypass-blacklisted-js-function-challenge-14/image-57.png"><h2 id="demo--xss-challenge-14">Demo – XSS Challenge 14</h2>
<p>For the following demo, we will be using the JavaScript “<code>confirm()</code>”
function.</p>
<p>The “<code>confirm()</code>” function in JavaScript is a built-in method that
displays a dialog box with a message and two buttons: “<strong>OK</strong>” and
“<code>Cancel</code>”. It is often used to prompt the user for confirmation
before performing a potentially destructive action, such as deleting
data or navigating away from a page.</p>
<p>I will go ahead and replace the “<code>alert()</code>” function with the
“<code>confirm()</code>” function and update our XSS payload accordingly.</p>
<p><strong>Confirm XSS Payload</strong></p>
<img loading="lazy" src="/xss-bypass-blacklisted-js-function-challenge-14/image-58.png"><p>Now, let&rsquo;s go ahead and input the above XSS payload in the “<strong>XSS Challenge 14</strong>” page.</p>
<figure>
<img src="CH14-XSS-Payload-Input-fs8.png" />
<figcaption>XSS Payload Input with confirm JS function</figcaption>
</figure>
<p>Immediately after clicking on the “<strong>Submit</strong>” button, a pop-up message
will be displayed, as shown below.</p>
<figure>
<img src="CH14-XSS-Payload-Result-fs8.png" />
<figcaption>XSS pop-up message</figcaption>
</figure>
<p>The above screenshot demonstrates the javascript “<code>confirm()</code>” prompt.
Which looks very similar to the “<code>alert()</code>” dialog box with the added
button “<code>Cancel</code>” as a difference.</p>
<p>This also confirms that the application is vulnerable to cross-site
scripting vulnerability.</p>
<p>To verify further, click on the “<strong>OK</strong>” button in the dialog prompt,
right-click, and select “View page source”.</p>
<p><strong><u>Viewing HTML Source</u></strong></p>
<figure>
<img src="image-61.png" />
<figcaption>XSS Payloads HTML Page Source</figcaption>
</figure>
<p>Observe the injected XSS payload is reflected in the HTML source and
executed perfectly.</p>
<p>By this, we can confirm that XSS challenge 14 is successfully solved.</p>
<hr>
<img loading="lazy" src="/xss-bypass-blacklisted-js-function-challenge-14/image-62.png"><h3 id="summary">Summary</h3>
<p>In this article, we demonstrated one of the impacts of the blacklisting
approach where the “<code>confirm()</code>” or other alternative javascript
functions can be abused by attackers in XSS attacks, as they can use it
to trick users into executing arbitrary code or disclosing sensitive
information.</p>
<p>To prevent XSS vulnerabilities in web applications, it&rsquo;s important to
validate and sanitize all user input and implement appropriate content
security policies.</p>
<hr>
<img loading="lazy" src="/xss-bypass-blacklisted-js-function-challenge-14/thank-you.png"><p>Congratulations to all our readers who completed the learning XSS with
the Kurukshetra series! I hope that you enjoyed our vulnerability series
and learned a lot in the process. If you&rsquo;d like to learn more or have
any feedback or suggestions, please don&rsquo;t hesitate to reach out. We&rsquo;d
love to hear from you!</p>
]]></content:encoded>
    </item>
    <item>
      <title>Challenge 13: XSS  in HTML Anchor Tag</title>
      <link>https://raghu.io/xss-in-html-anchor-tag/</link>
      <pubDate>Thu, 16 Mar 2023 06:52:55 +0000</pubDate>
      <guid>https://raghu.io/xss-in-html-anchor-tag/</guid>
      <description>Check out how a security risk can arise from an improperly configured dynamic link generation tag and which can result in XSS exploitation.</description>
      <content:encoded><![CDATA[<p>Welcome back! I hope by now you are familiar with what a CSP is and how
a misconfigured CSP can lead to potential security vulnerabilities like
cross-site scripting.</p>
<p>Before getting started, ensure your Kurukshetra lab is up and running.
Feel free to refer back to the below link.</p>
<p><a href="/xss-explained-learn-cross-site-scripting-with-examples/">XSS Explained - Learn Cross-Site Scripting with
Examples</a></p>
<hr>
<img loading="lazy" src="/xss-in-html-anchor-tag/image-35.png"><h2 id="xss-challenge-walkthrough">XSS Challenge Walkthrough</h2>
<p>Once your Kurukshetra XSS lab environment is up and running, Visit
<a href="http://localhost:8066/"><a href="http://localhost:8066">http://localhost:8066</a></a> and navigate to &ldquo;<a href="http://localhost:8066/ch13.php">XSS
Challenge 13</a>&rdquo;.</p>
<figure>
<img src="Kurukshetra-XSS-Challenge-13-Page-fs8.png" />
<figcaption>XSS Challenge Page 13</figcaption>
</figure>
<p>An input field labeled “<strong>create a link?</strong>” is displayed.</p>
<figure>
<img src="CH13-User-Input-fs8-1.png" />
<figcaption>Input URL</figcaption>
</figure>
<ol>
<li>
<p>In the above input field, give a URL (say
“<a href="http://localhost:8066/ch13.php">http://localhost:8066/ch13.php</a>“) to which you want the
application to create a link for us.</p>
</li>
<li>
<p>Click on the “<strong>Submit</strong>” button.</p>
</li>
</ol>
<figure>
<img src="CH13-Input-Display-Back-fs8-1.png" />
<figcaption>Input Reflected Back</figcaption>
</figure>
<p><br>
Observe the application generated an HTML link for the given URL
displayed above.</p>
<p>From the above application, we can understand that with any given input
text, the application generates a clickable HTML link.</p>
<p>Feel free to try out all the XSS techniques learned so far. You should
be able to solve this challenge right away. 😃</p>
<img loading="lazy" src="/xss-in-html-anchor-tag/image-39.png"><h3 id="xss-in-anchor-tag">XSS in Anchor Tag</h3>
<p>Going ahead, we will cover how the HTML anchor tag can be used to craft
a customized XSS payload.</p>
<p>From the above HTML link generated, right-click and select “<strong>View page source</strong>“, then search for the appended text in the HTML response.</p>
<img loading="lazy" src="/xss-in-html-anchor-tag/image-40.png"><p>From the above screenshot, we can see the given input text is placed
between the “<code>href</code>” in an anchor tag, and the same text is placed
again as the name of the anchor tag.</p>
<p><strong><u>Output:</u></strong></p>
<figure>
<img src="CH13-Input-Display-Back-fs8-2.png" />
<figcaption>Reflected Link</figcaption>
</figure>
<p>I will go ahead and create a crafted XSS payload which is generally
attackers used to trick victims into a trap.</p>
<h3 id="xss-anchor-payload">XSS Anchor Payload</h3>
<img loading="lazy" src="/xss-in-html-anchor-tag/image-42.png"><p>Breaking down the above XSS payload in detail:</p>
<ol>
<li>Leaving the “<code>href</code>” tag empty without a link and closing it with
another pair of double quotes to ensure HTML syntax is maintained.</li>
<li>The “<code>onclick</code>” is an HTML5 attribute used within HTML tags that
specifies a JavaScript function to be executed when the user clicks
on the element. In this case, the function being executed is
“<code>alert(‘xss')</code>“, which displays the alert dialog with the message
“<code>xss</code>“.</li>
<li>&ldquo;<strong>Click for XSS POC&rdquo;</strong> a text message will be displayed for the
anchor tag.</li>
<li>Closing the HTML anchor tag with “<code>&lt;/a&gt;</code>“.</li>
<li>The start of the HTML comment with “<code>&lt;!–</code>” then comments out all
the code after this is parsed as text with no special meaning.</li>
</ol>
<p>Overall the above XSS payload creates a clickable element that, when
clicked, will execute a JavaScript alert dialog with the message
“<code>xss</code>“.</p>
<img loading="lazy" src="/xss-in-html-anchor-tag/image-43.png"><h3 id="xss-demo">XSS Demo</h3>
<p>Go ahead and give it a try with the above-crafted XSS payload.</p>
<figure>
<img src="CH13-XSS-Payload-fs8.png" />
<figcaption>XSS Payload Input</figcaption>
</figure>
<p>In the above screenshot, key in the XSS payload and click on the
&ldquo;<strong>Submit&rdquo;</strong> button.</p>
<figure>
<img src="CH13-XSS-Payload-Link-Reflect-fs8.png" />
<figcaption>XSS Payload Link Reflected Back on Page</figcaption>
</figure>
<p>From the given payload, the application generates an HTML link and
displays it, as shown above. Now click on the “<strong>Click for XSS POC</strong>“.</p>
<figure>
<img src="CH13-XSS-Payload-Link-Alert-fs8.png" />
<figcaption>XSS Alert Message</figcaption>
</figure>
<p>Immediately, a pop-up box is loaded, and a message named “xss” is
displayed. Thus, we have solved XSS challenge 13.</p>
<blockquote>
<p><strong>Note:</strong>
One of the many techniques is covered here. The XSS payload can be
crated in multiple other ways as well.</p>
</blockquote>
<p>Lastly, right-click and select “View page source” to understand how it&rsquo;s
reflected back in the HTML response.</p>
<img loading="lazy" src="/xss-in-html-anchor-tag/image-47.png"><p><br>
From the source code, the XSS payload is appended inside the anchor tag,
and all the HTML code is commented out after the anchor tag.</p>
<p>As mentioned above, the XSS payload allows the attacker to execute
arbitrary JavaScript code on the victim&rsquo;s browser when the element is
clicked. This can result in the theft of sensitive information, such as
session cookies or user credentials, or the takeover of the victim&rsquo;s
account.</p>
<p>By this, we have successfully solved the XSS challenge 13.</p>
<hr>
<img loading="lazy" src="/xss-in-html-anchor-tag/image-48.png"><h2 id="summary"><strong>Summary</strong></h2>
<p>The following article demonstrates how the customized XSS payload allows
an attacker to execute arbitrary JavaScript code.</p>
<p>The code also includes an HTML comment &ldquo;<code>&lt;!--</code>&rdquo;, an attempt to prevent
the malicious code from being easily detected. This technique is known
as “comment hiding”, and attackers often use it to obfuscate their
payloads and evade detection.</p>
<p>To prevent XSS attacks, input validation and output encoding should be
applied, and a Content Security Policy can also be used to mitigate the
risk of the above XSS vulnerability.</p>
]]></content:encoded>
    </item>
    <item>
      <title>Challenge 12: XSS CSP bypass through remote payload</title>
      <link>https://raghu.io/xss-csp-bypass-remote-payload-challenge-12/</link>
      <pubDate>Sat, 11 Mar 2023 06:30:06 +0000</pubDate>
      <guid>https://raghu.io/xss-csp-bypass-remote-payload-challenge-12/</guid>
      <description>Learn how to bypass a misconfigured CSP policy and how it can lead to the successful exploitation of cross-site scripting vulnerability.</description>
      <content:encoded><![CDATA[<p>Welcome back! In an earlier post, we covered how a misconfigured CSP
policy can be bypassed and can lead to XSS vulnerability.</p>
<p>Before getting started, ensure your Kurukshetra lab is up and running.
Feel free to refer back to the below link.</p>
<p><a href="/xss-explained-learn-cross-site-scripting-with-examples/">XSS Explained - Learn Cross-Site Scripting with
Examples</a></p>
<hr>
<img loading="lazy" src="/xss-csp-bypass-remote-payload-challenge-12/image-17.png"><h2 id="xss-challenge-walk-through"><strong>‌XSS Challenge Walk-Through</strong></h2>
<p>Once your Kurukshetra XSS lab environment is up and running, Visit
<a href="http://localhost:8066/"><a href="http://localhost:8066">http://localhost:8066</a></a> and navigate to “<a href="http://localhost:8066/ch12.php">XSS
Challenge 12</a>“.</p>
<figure>
<img src="XSS-Challenge-Page-12-fs8.png" />
<figcaption>XSS Challenge Page 12 with payload</figcaption>
</figure>
<ol>
<li>Click on <a href="http://localhost:8066/ch12.php">“XSS Challenge 12</a>” on the
left side menu.</li>
<li>Input the XSS CSP bypass payload which was used in the previous
demonstration and will observe how the application behaves.</li>
</ol>
<img loading="lazy" src="/xss-csp-bypass-remote-payload-challenge-12/image-19.png"><ol>
<li>Click on the “<strong>Submit</strong>” button.</li>
</ol>
<p><strong><u>Application Output:</u></strong></p>
<figure>
<img src="CH12-Payload-Result-fs8.png" />
<figcaption>XSS Payload Result</figcaption>
</figure>
<ol>
<li>
<p>The application loads normally and displays a text message, &ldquo;<strong>Your
XSS Payload</strong>&rdquo;, without any pop-ups.</p>
</li>
<li>
<p>Right-click and select “<strong>View page source</strong>“, then search for the
injected XSS payload. The HTML response code will be displayed
below.</p>
</li>
</ol>
<img loading="lazy" src="/xss-csp-bypass-remote-payload-challenge-12/image-21.png"><ol>
<li>
<p>At the bottom of the HTML response, the XSS payload was injected as
provided and also aligned rightly with the HTML syntax. But the
javascript code wasn&rsquo;t executed.</p>
</li>
<li>
<p>You might have guessed right! The application&rsquo;s <a href="https://content-security-policy.com/">Content Security
Policy</a> might be blocking our
payload. Let&rsquo;s go ahead and review the current CSP policy set.</p>
</li>
</ol>
<img loading="lazy" src="/xss-csp-bypass-remote-payload-challenge-12/image-22.png"><h3 id="analyzing-the-csp-policy"><strong>Analyzing the CSP policy</strong></h3>
<p>On the following XSS challenge page, Press the “<strong>F12</strong>” button on your
keyboard and a new browser debugger window will be launched.</p>
<p>In browser debugger mode navigate to “<strong>Console</strong>” and observe the CSP
violation messages will be displayed as shown below.</p>
<figure>
<img src="CH12-CSP-Policy-Errors-fs8.png" />
<figcaption>CSP Policy Errors</figcaption>
</figure>
<p>As expected, the browser blocks script code due to CSP violations and
prevents execution.</p>
<p>Will try to understand the application CSP policies, In debugger mode
switch to “<strong>Network</strong>” and reload the challenge page.</p>
<figure>
<img src="CH12-CSP-Policy-View.png" />
<figcaption>Content-Security-Policy View</figcaption>
</figure>
<p>Select the “<strong>ch12.php</strong>” page and scroll to the “<strong>Response Headers</strong>”
section. Observe, the <strong>Content-Security-Policy</strong> header which was set
by the application server.</p>
<img loading="lazy" src="/xss-csp-bypass-remote-payload-challenge-12/image-25.png"><h3 id="understanding-the-csp-policy-implemented"><strong>Understanding the CSP Policy Implemented</strong></h3>
<img loading="lazy" src="/xss-csp-bypass-remote-payload-challenge-12/image-26.png"><p>Breaking down the CSP rules:</p>
<ol>
<li>“<code>script-src</code>“: This directive restricts the sources from which
scripts can be loaded. In our case, it allows scripts to be loaded
only from the <strong>same origin</strong> as the page (i.e. “<code>self</code>“),</li>
<li>Secondly, the scripts can be loaded from <strong><a href="https://facebook.com">https://facebook.com</a></strong>,
<strong><a href="https://google.com">https://google.com</a></strong>, any HTTPS sources (“<code>https</code>“), the
“<code>data</code>” scheme, and any source (<code>*</code>).</li>
<li><strong>child-src</strong>: This directive restricts the nested frame contents
from loading.</li>
<li><strong>report-uri</strong>: This directive specifies a URL to which policy
violation reports should be sent.</li>
</ol>
<p>Overall, CSP policy allows scripts to be loaded only from trusted
sources, including the same origin as the page and specific external
sources like Facebook, Google, and other HTTPS domains.</p>
<img loading="lazy" src="/xss-csp-bypass-remote-payload-challenge-12/image-27.png"><h3 id="why-is-data-directive-based-xss-not-working">Why is &ldquo;data:&rdquo; directive-based XSS not working?</h3>
<div class="highlight"><pre tabindex="0" class="chroma"><code class="language-HTTP" data-lang="HTTP"><span class="line"><span class="cl"><span class="err">Content-Security-Policy: script-src &#39;self&#39; https://facebook.com https://google.com https: data *; child-src &#39;none&#39;; report-uri /Report-parsing-url;
</span></span></span></code></pre></div><p>This is because the CSP policy explicitly disallows scripts to be loaded
from the “<code>data:</code>” scheme, except for the page&rsquo;s own origin (i.e.,
‘<code>self</code>‘ same domain).</p>
<p>In the <strong>script-src</strong> directive, the &ldquo;<strong>data</strong>&rdquo; scheme is listed as a
source along with the wildcard <code>*</code>. However, the wildcard “<code>*</code>”
here does not override the previous &lsquo;<strong>self&rsquo;</strong> directive, meaning that
scripts can only be loaded from the page&rsquo;s own origin via the
“<code>data:</code>” scheme but not from the user-injected external scripts.</p>
<p>Therefore, the “<code>data:</code>” scheme tries to load an external script,
which was blocked by the CSP policy, and the “<code>alert(‘XSS')</code>” payload
doesn&rsquo;t execute.</p>
<p>Is it possible to bypass the limitations set?</p>
<img loading="lazy" src="/xss-csp-bypass-remote-payload-challenge-12/image-28.png"><p>Well, the more you get familiar with the technologies, the more options
you will be able to find.</p>
<p>Closely observe there is another directive named “<code>https:</code>” in
<strong>script-src</strong>. It is configured in such a way that scripts can be
loaded from any of the HTTPS sources.</p>
<div class="highlight"><pre tabindex="0" class="chroma"><code class="language-HTTP" data-lang="HTTP"><span class="line"><span class="cl"><span class="err">Content-Security-Policy: script-src &#39;self&#39; https://facebook.com https://google.com https: data *; child-src &#39;none&#39;; report-uri /Report-parsing-url;
</span></span></span></code></pre></div><p>Yes, one option is setting up your own HTTPS site and pushing an XSS
javascript file onto the server and using it for testing purposes.</p>
<p>It&rsquo;s a long process, but I will be using the publicly available one for
the proof of concept.</p>
<p>Security researchers from <a href="https://github.com/cure53/H5SC">Cure53</a> have
provided the needed resources that can be directly used for security
assessment. The reference link can be found below:</p>
<p><a href="https://github.com/cure53/H5SC">https://github.com/cure53/H5SC</a></p>
<hr>
<img loading="lazy" src="/xss-csp-bypass-remote-payload-challenge-12/image-29.png"><h2 id="demo--csp-bypass">Demo – CSP Bypass</h2>
<p>Let&rsquo;s use the remote “<code>https</code>” javascript payload taken from the H5SC
report, the payload URL is given below.</p>
<p><a href="https://html5sec.org/test.js">https://html5sec.org/test.js</a></p>
<p>Javascript source code in the “<code>test.js</code>” file contains only the
alert() function as given below. If worked, will display a pop-up
message “<code>1</code>“.</p>
<div class="highlight"><pre tabindex="0" class="chroma"><code class="language-JavaScript" data-lang="JavaScript"><span class="line"><span class="cl"><span class="nx">alert</span><span class="p">(</span><span class="mi">1</span><span class="p">)</span>
</span></span></code></pre></div><p>Will append the above URL to the script code so we can key it into the
input field.</p>
<img loading="lazy" src="/xss-csp-bypass-remote-payload-challenge-12/image-30.png"><p>Visit the <a href="http://localhost:8066/ch12.php">XSS Challenge 12</a>, paste the
above payload in the input form field, and click on the &ldquo;Submit&rdquo; button.</p>
<figure>
<img src="CH12-XSS-Payload-Input-fs8.png" />
<figcaption>XSS Payload Input</figcaption>
</figure>
<p>Immediately observe a pop-up box will be loaded with the message
displaying &ldquo;<strong>1&rdquo;</strong>. By this we can confirm we have successfully
exploited the misconfigured CSP.</p>
<figure>
<img src="CH12-XSS-Payload-Alert-fs8-1.png" />
<figcaption>XSS Payload Alert Message</figcaption>
</figure>
<p>In all XSS payloads, we used “<code>alert(‘XSS')</code>“, an <strong>alert()</strong> function
to display text message ‘<code>xss</code>‘ so far, in the above case, the same
alert function was used to display the numeric digit in a pop-up window.</p>
<p>Click “<strong>OK</strong>“, then Right-click and select “<strong>View page source</strong>” to
verify the injected payload.</p>
<img loading="lazy" src="/xss-csp-bypass-remote-payload-challenge-12/image-33.png"><p>Post review can confirm that the XSS payload reflected as given and
executed successfully.</p>
<p>By this, I can say that XSS Challenge 12 has been successfully solved.
<strong>Yayy!!! 🎉.</strong></p>
<p>Use of the “<code>https</code>” sources from any domain can be problematic from a
security perspective, as it allows arbitrary javascript code to be
loaded from any external source and executed directly on the page, which
is generally abused by attackers to perform cross-site scripting (XSS)
attacks.</p>
<hr>
<img loading="lazy" src="/xss-csp-bypass-remote-payload-challenge-12/image-34.png"><h3 id="heading">\</h3>
<p>Summary</p>
<p>A Content Security Policy (CSP) can prevent cross-site scripting (XSS)
attacks by limiting the sources from which scripts can be loaded.</p>
<p>However, if a CSP policy is misconfigured, it can potentially allow XSS
attacks to occur. In the above case, allowing the javascript code to
load from any remote &ldquo;<strong>https&rdquo;</strong> resources can enable attackers to
inject malicious scripts directly into a web page, potentially leading
to XSS attacks.</p>
<p>Therefore, a well-configured CSP policy can block all XSS attacks, and
it is important to ensure that CSP policies are correctly configured and
free from insecure directives.</p>
]]></content:encoded>
    </item>
    <item>
      <title>Challenge 11: XSS CSP bypass through an inline script</title>
      <link>https://raghu.io/xss-csp-bypass-through-inline-script-challenge-11/</link>
      <pubDate>Sat, 04 Mar 2023 06:30:48 +0000</pubDate>
      <guid>https://raghu.io/xss-csp-bypass-through-inline-script-challenge-11/</guid>
      <description>Learn how a misconfigured CSP can be bypassed, potentially leading to the successful exploitation of cross-site scripting vulnerability.</description>
      <content:encoded><![CDATA[<p>Welcome to learning XSS with the Kurukshetra Series.</p>
<p>Before getting started, ensure your Kurukshetra lab is up and running.
Feel free to refer back to the below link.</p>
<p><a href="/xss-explained-learn-cross-site-scripting-with-examples/">XSS Explained - Learn Cross-Site Scripting with
Examples</a></p>
<hr>
<img loading="lazy" src="/xss-csp-bypass-through-inline-script-challenge-11/image.png"><h2 id="xss-challenge-walk-through">‌XSS Challenge Walk-Through</h2>
<p>Once your Kurukshetra XSS lab environment is up and running, Visit
<a href="http://localhost:8066/"><a href="http://localhost:8066">http://localhost:8066</a></a> and navigate to “<a href="http://localhost:8066/ch11.php">XSS
Challenge 11</a>“.</p>
<figure>
<img src="Kurukshetra-XSS-Challenge-11-Page-fs8.png" />
<figcaption>XSS Challenge 11 page with payload</figcaption>
</figure>
<ol>
<li>Click and select the <a href="http://localhost:8066/ch11.php">XSS Challenge
11</a> from the Kurukshetra app.</li>
<li>Fill out our classic XSS payload in the given input field.</li>
<li>Click on the “<strong>Submit</strong>” button.</li>
</ol>
<p><strong>Output:</strong></p>
<figure>
<img src="CH11-XSS-Payload-Output-fs8.png" />
<figcaption>XSS Payload Output</figcaption>
</figure>
<ol>
<li>
<p>The application loads the page as usual and displays a text message,
&ldquo;<strong>Your XSS Payload&rdquo;</strong> without any pop-ups.</p>
</li>
<li>
<p>Right-click and select “<strong>View page source</strong>“, then search for the
injected XSS payload. The HTML response code will be displayed
below.</p>
</li>
</ol>
<figure>
<img src="CH11-XSS-Payload-HTML-Source-fs8.png" />
<figcaption>XSS Payload Result's HTML Page Source</figcaption>
</figure>
<ol>
<li>At the bottom of the HTML response, the payload was injected as
provided and also aligned rightly with the HTML syntax. But our
javascript didn&rsquo;t execute.</li>
</ol>
<p>What might be happening in the background?</p>
<img loading="lazy" src="/xss-csp-bypass-through-inline-script-challenge-11/image-4.png"><p>In the above screenshot, if the HTML output encoding is used, then the
output must be displayed as “<code>&amp;lt;</code>” or “<code>&amp;gt;</code>” etc. Doesn&rsquo;t look
so. Also, if slash-escape is being used, then the prefix slashes must be
displayed. Even that is not present.</p>
<p>Seems like our XSS payload is injected rightly but unable to execute. A
possible guess is there is some sort of other XSS defense in place.</p>
<p>The web application might have enabled the <a href="https://content-security-policy.com/">Content Security
Policy</a> or other XSS protection
headers. Let&rsquo;s verify and understand what&rsquo;s happening in the background.</p>
<img loading="lazy" src="/xss-csp-bypass-through-inline-script-challenge-11/image-5.png"><p>On the following XSS challenge page, Press the “<strong>F12</strong>” button on your
keyboard and a new browser debugger window will be launched.</p>
<p>In browser debugger mode navigate to “<strong>Console</strong>” and observe the CSP
violation messages will be displayed as shown below.</p>
<figure>
<img src="CH11-CSP-Errors-fs8.png" />
<figcaption>Observe Content-Security-Policy Errors</figcaption>
</figure>
<p>Web Browser clearly indicates some script code tried to execute but it&rsquo;s
not compliant with the CSP policy set. Therefore it was blocked by the
browser from executing.</p>
<p>In debugger mode, switch to &ldquo;<strong>Network</strong>&rdquo; and reload the challenge page.</p>
<figure>
<img src="CH11-CSP-Policy-View-fs8.png" />
<figcaption>Viewing Content-Security-Policy</figcaption>
</figure>
<p>Select the &ldquo;<strong>ch11.php</strong>&rdquo; page and observe on the right side in
&ldquo;<strong>Response Headers</strong>&rdquo; the <strong>Content-Security-Policy</strong> header, which was
set by the web application.</p>
<img loading="lazy" src="/xss-csp-bypass-through-inline-script-challenge-11/image-8.png"><h3 id="understanding-the-csp-implementation">Understanding the CSP implementation</h3>
<img loading="lazy" src="/xss-csp-bypass-through-inline-script-challenge-11/image-9.png"><p>Breaking down the CSP policy defined by the web application</p>
<ol>
<li><strong>script-src</strong>: specifies the sources from which scripts can be
loaded.</li>
</ol>
<ul>
<li><strong><a href="https://facebook.com">https://facebook.com</a></strong>: allows scripts to be loaded from the
domain facebook.com.</li>
<li><strong><a href="https://google.com">https://google.com</a></strong>: allows scripts to be loaded from the domain
google.com.</li>
<li><strong>unsafe-eval</strong>: This allows the <strong>eval()</strong> javascript function and
the Function() constructor to execute dynamically created script code.</li>
<li><strong>&ldquo;data:</strong>&rdquo;: allows the execution of inline scripts (one which is
directly embedded in the HTML) with data URIs.</li>
<li>&ldquo;<code>http://*</code>&rdquo;: Wildcard &ldquo;<code>*</code>&rdquo; means allows scripts to be loaded
from any HTTP sources (poses a security risk).</li>
</ul>
<p><strong>2. child-src</strong>: specifies the sources from which nested browsing
contexts (such as iframes or embedded objects) can be loaded. In this
case, &rsquo;none&rsquo; specifies that no sources are allowed.</p>
<p><strong>3. report-uri</strong>: specifies the URL where a browser should send
violation reports if the policy is breached.</p>
<p>Overall, this CSP allows scripts to be loaded from trusted domains
(facebook.com and google.com), as well as inline scripts and HTTP
sources (which are generally not recommended due to security risks). It
also allows the use of <code>eval()</code> and <code>Function()</code>, which can be used to
exploit XSS attacks. Additionally, it prohibits the loading of nested
browsing contexts and specifies a URL to which violation reports should
be sent.</p>
<img loading="lazy" src="/xss-csp-bypass-through-inline-script-challenge-11/image-10.png"><p>The above CSP policy clearly has some limitations and is not foolproof.
That said, &ldquo;<strong>data:</strong>&rdquo; provided an entryway for us to try creating XSS
inline scripts or load the XSS script code from any of the HTTP domains,
tricking the application by loading from Google, etc.</p>
<img loading="lazy" src="/xss-csp-bypass-through-inline-script-challenge-11/image-11.png"><h2 id="exploiting-xss-using-inline-scripts">Exploiting XSS using Inline scripts</h2>
<p>(i.e., using data directive)</p>
<p>Let&rsquo;s go ahead and find a way to bypass the misconfigured CSP defenses.
For the following demonstrations, we will be using the script-src&rsquo;s
&ldquo;<strong>data:</strong>&rdquo; attribute to craft an XSS payload.</p>
<p>From the documentation script source &ldquo;<strong>data:</strong>&rdquo; can be used for
inserting inline scripts directly into HTML documents.</p>
<p>The &ldquo;<strong>data:</strong>&rdquo; URI scheme allows data to be embedded directly in a URL
or document, using a specific syntax that includes the &ldquo;data:&rdquo; prefix
followed by the MIME type of the data, and the data itself.</p>
<p>Below is an XSS inline script using the &ldquo;data:&rdquo; URI scheme, which can be
included directly, with the MIME type set to &ldquo;text/javascript&rdquo; and an
&ldquo;alert(&lsquo;xss&rsquo;)&rdquo; data.</p>
<figure>
<img src="image-12.png" />
<figcaption>POC for XSS inline script</figcaption>
</figure>
<p>Above code will pop up with an &ldquo;XSS&rdquo; message when the javascript code is
loaded and executed directly on the page.</p>
<p>Visit the &ldquo;<a href="http://localhost:8066/ch11.php">XSS challenge 11</a>&rdquo; page.</p>
<figure>
<img src="CH11-CSP-XSS-Payload-fs8.png" />
<figcaption>CSP-based XSS Payload Input</figcaption>
</figure>
<p>Enter the XSS inline script code in the input field and click on the
&ldquo;<strong>Submit</strong>&rdquo; button.</p>
<p><strong><u>Output:</u></strong></p>
<figure>
<img src="CH11-XSS-Result-fs8.png" />
<figcaption>XSS Alert Message</figcaption>
</figure>
<p>Immediately, we can see a pop-up message displayed on the web page. By
this, we can confirm that we have successfully exploited the XSS
vulnerability. :D</p>
<p>To further confirm, click on the &ldquo;<strong>OK</strong>&rdquo; message, then right-click and
select &ldquo;<strong>View page source</strong>&rdquo;. Search for the injected XSS inline script
code.</p>
<p><strong>HTML Page Source:</strong></p>
<figure>
<img src="image-15.png" />
<figcaption>XSS Payload HTML Page Source</figcaption>
</figure>
<p>Observe this time, our injected script code is reflected back as given
without any output being filtered.</p>
<p>The execution script code confirms we have successfully solved the <a href="http://localhost:8066/ch11.php">XSS
challenge 11</a>. <strong>Yayy!!!.</strong></p>
<p>Use of the &ldquo;<strong>data:</strong>&rdquo; URI scheme for inline scripts can be problematic
from a security perspective, as it allows arbitrary code to be executed
directly on the page, which is generally abused by attackers to perform
cross-site scripting (XSS) attacks.</p>
<hr>
<img loading="lazy" src="/xss-csp-bypass-through-inline-script-challenge-11/image-16.png"><h3 id="summary">Summary</h3>
<p>A Content Security Policy (CSP) policy restricts the types of content
that can be loaded by a web page. When implemented correctly, a CSP can
prevent cross-site scripting (XSS) attacks by limiting the sources from
which scripts can be loaded.</p>
<p>However, if a CSP policy is misconfigured or contains errors, it can
potentially allow XSS attacks to occur. For example, if a policy
includes insecure sources, such as &ldquo;unsafe-inline&rdquo; or &ldquo;data:&rdquo;, it can
enable attackers to inject malicious scripts directly into a web page,
potentially leading to XSS attacks.</p>
<p>Therefore, a well-configured CSP policy can block all XSS attacks, and
it is important to ensure that CSP policies are correctly configured and
free from insecure directives.</p>
]]></content:encoded>
    </item>
    <item>
      <title>Challenge 10: XSS bypass backslash escape</title>
      <link>https://raghu.io/xss-bypass-backslash-escape-challenge-10/</link>
      <pubDate>Tue, 28 Feb 2023 06:30:15 +0000</pubDate>
      <guid>https://raghu.io/xss-bypass-backslash-escape-challenge-10/</guid>
      <description>Check out how the XSS can be exploited in the HTML &amp;lt;div&amp;gt; tags and learn more about &amp;lt;img&amp;gt; tag-based XSS payload.</description>
      <content:encoded><![CDATA[<p>Today&rsquo;s article should be somewhat similar and like a recap. Will look
at how the XSS can be exploited in the HTML <strong>&lt;div&gt;</strong> tags and explore
<strong>&lt;img&gt;</strong> tag-based XSS payload</p>
<p>Before getting started, ensure your Kurukshetra lab is up and running.
Feel free to refer back to the below link.</p>
<p><a href="/xss-explained-learn-cross-site-scripting-with-examples/">XSS Explained - Learn Cross-Site Scripting with
Examples</a></p>
<hr>
<img loading="lazy" src="/xss-bypass-backslash-escape-challenge-10/image-56.png"><h2 id="xss-challenge">‌XSS Challenge</h2>
<p>You reached &ldquo;<a href="http://localhost:8066/ch10.php"><strong>XSS Challenge 10</strong></a>&rdquo;.
Great to see your consistent progress. In the past article, we covered
how the XSS vulnerability does not always need to be exploited using the
same parameter. XSS can also be looked at in other parameters, which
might depend on the param, or it can also be an appending parameter.</p>
<p>Let&rsquo;s get started with XSS Challenge 10. Visit:
<a href="http://localhost:8066/"><a href="http://localhost:8066">http://localhost:8066</a></a> and ensure it&rsquo;s
accessible, then navigate to “<a href="http://localhost:8066/ch10.php">XSS Challenge
10</a>“.</p>
<figure>
<img src="Kurukshetra-XSS-Challenge-Page-10-fs8.png" />
<figcaption>Kurukshetra XSS Challenge Page 10</figcaption>
</figure>
<ol>
<li>Click and select the <a href="https://localhost:8806/ch10.php">XSS Challenge
10</a> from the Kurukshetra app.</li>
<li>Will fill out some random string saying “ABC” in the input field
provided.</li>
<li>Click on the “<strong>Submit</strong>” button.</li>
</ol>
<p><strong><u>Output:</u></strong></p>
<figure>
<img src="CH10-Input-Trail-1-fs8.png" />
<figcaption>Reflection of user input</figcaption>
</figure>
<p>Feel free to experiment with your XSS ideas before going ahead with the
next steps.</p>
<p>Hope you have partially or successfully exploited it.</p>
<hr>
<h3 id="viewing-the-page-source"><strong>Viewing the Page Source</strong></h3>
<p>In the above screenshot, I have keyed the text &ldquo;<strong>ABC&rdquo;</strong> in the input
field. Let&rsquo;s verify how the text is being reflected back in the HTTP
response code.</p>
<p>To do that, &ldquo;Right-click&rdquo; and select “<strong>View Page Source</strong>”, then search
for the inserted string “<strong>ABC</strong>”.</p>
<img loading="lazy" src="/xss-bypass-backslash-escape-challenge-10/image-81.png"><p>Injected text is being reflected back at the bottom of the page, and
this time, it&rsquo;s inserted between the HTML <strong>div</strong> tags with double
quotes appended.</p>
<p>Remember from the previous lessons, we can keep trying out the different
XSS payloads, but at the same time need to gather the list of allowed
characters as well which can help in crafting an XSS payload.</p>
<p>Going ahead, will be trying out all the payloads and narrow down to the
allowed characters.</p>
<p><strong>Payload 1 – Simple XSS</strong></p>
<img loading="lazy" src="/xss-bypass-backslash-escape-challenge-10/image-82.png"><p><strong><u>Browser Output:</u></strong></p>
<figure>
<img src="CH10-XSS-Payload-Result-fs8.png" />
<figcaption>Only a combination of single quotes is
displayed</figcaption>
</figure>
<p><strong><u>Page Source – Output:</u></strong></p>
<figure>
<img src="CH10-Broken-Syntax-fs8.png" />
<figcaption>Broken HTML Syntax</figcaption>
</figure>
<p>Closely observing the closing <code>&lt;/script&gt;</code>, a “<code>\</code>” backslash
is appended and turned the closing script to <code>&lt;\/script&gt;</code>. This breaks
the HTML syntax, as it&rsquo;s expecting the closing script tag.</p>
<h3 id="about-slash-escape">About Slash-Escape</h3>
<p>The backslash escape is a technique used to prevent special characters
from being interpreted as code in web applications. Currently, this
application is using the same to block XSS attacks.</p>
<p>The above technique is good when used in combination with multiple XSS
prevention techniques. (i.e., Defense in Depth).</p>
<p>Also, note that in the above case, the backslash “<code>\</code>” is only
being appended to the slash in the closing script tag, not for any other
special characters, which is an indication of poor XSS mitigation.</p>
<hr>
<img loading="lazy" src="/xss-bypass-backslash-escape-challenge-10/image-85.png"><blockquote>
<p><strong>TIP – 10 Try HTML tags that work without closing tags</strong></p>
<p>Yes, as mentioned in the heading. Not all HTML tags need to have a
compulsory closing tag, and there are some HTML tags that work even if
the closing tag is not provided. (say &lt;IMG&gt;, &lt;SVG&gt; etc.)</p>
</blockquote>
<hr>
<p>This time for a change will go ahead and try the HTML image tag payload
than using the same routine one.</p>
<h2 id="xss-payload--html-image-tag"><strong>XSS Payload – HTML Image Tag</strong></h2>
<figure>
<img src="XSS-Payload-Code-fs8.png" />
<figcaption>Image Tag based XSS Payload</figcaption>
</figure>
<p>Breaking down the above payload into detailed steps.</p>
<ul>
<li>“<code>&lt;img&gt;</code>” is an HTML tag used for embedding images on a web page.</li>
<li>“<code>src</code>” is an attribute of the HTML “<code>&lt;img&gt;</code>” tag that specifies
the URL of the image file from where it needs to be loaded.</li>
<li>“<code>x</code>” is a random value assigned to the “<code>src</code>” attribute
forcibly. As there is no image file named “<code>x</code>“, the browser will
fail to display/load the image.</li>
<li>“<code>onerror</code>” is another attribute of the “<code>&lt;img&gt;</code>” tag that is
called if an error occurs while loading the image.</li>
<li>“<code>alert(‘XSS')</code>” is a JavaScript function that displays an alert
dialog box with the message “XSS”.</li>
</ul>
<p>Putting it all together, when the web page containing this XSS payload
is loaded in the browser, the browser will try to load the image file
“x”. As the image file cannot be loaded due to non-existent, the onerror
attribute is triggered and the JavaScript code <strong>alert(‘XSS&rsquo;)</strong> is
executed, which displays a pop-up message “XSS”.</p>
<hr>
<figure>
<img src="image-86.png" />
<figcaption>Demo</figcaption>
</figure>
<p><strong>Demo – HTML Image Tag XSS Payload</strong>
I will go ahead and insert the “&lt;img&gt;” tag-based payload and verify
how the application behaves.</p>
<figure>
<img src="CH10-XSS-Payload-Input-fs8.png" />
<figcaption>XSS Payload Input</figcaption>
</figure>
<p><strong><u>Output:</u></strong></p>
<figure>
<img src="CH10-XSS-Alert-Message-fs8.png" />
<figcaption>XSS Alert Message</figcaption>
</figure>
<p><strong>Wow!! 🎉</strong> an XSS pop-up message. This confirms that our payload
worked.</p>
<p>Lastly, let us go ahead and further verify by viewing the page source.
Click “OK”,</p>
<p>Right-click on the page and select “<strong>View Page Source</strong>“. Then, search
for the injected string.</p>
<p><strong>HTML Response</strong></p>
<img loading="lazy" src="/xss-bypass-backslash-escape-challenge-10/image-89.png"><p>Observe, the payload is rightly aligned between the div tag and
backslash and is no longer breaking the HTML syntax. By this, we have
successfully solved the <a href="http://localhost:8066/ch10.php">XSS challenge
10</a>.</p>
<hr>
<img loading="lazy" src="/xss-bypass-backslash-escape-challenge-10/image-90.png"><h3 id="summary">Summary</h3>
<p>The following article covered one of the poorly implemented XSS fixes of
escaping using backslash for special characters. That, too, only escapes
the closing script tag. These limitations can be bypassed using HTML
image tags and other ways. Therefore a &ldquo;Defense-in-Depth&rdquo; approach is
needed to mitigate XSS vulnerability at multiple layers.</p>
]]></content:encoded>
    </item>
    <item>
      <title>Challenge 9: XSS in the hidden input field</title>
      <link>https://raghu.io/xss-in-hidden-input-field-challenge-9/</link>
      <pubDate>Fri, 24 Feb 2023 06:42:44 +0000</pubDate>
      <guid>https://raghu.io/xss-in-hidden-input-field-challenge-9/</guid>
      <description>Check out how the XSS can also be exploited in hidden input parameter fields with examples.</description>
      <content:encoded><![CDATA[<p>Welcome Back!! 😃</p>
<p>In today&rsquo;s article, let&rsquo;s check out how the XSS can also be exploited in
hidden input parameter fields.</p>
<p>Before getting started, ensure your Kurukshetra lab is up and running.
Feel free to refer back to the below link.</p>
<p><a href="/xss-explained-learn-cross-site-scripting-with-examples/">XSS Explained - Learn Cross-Site Scripting with
Examples</a></p>
<hr>
<p>The previous article covered how the limited character set can be
leveraged to exploit the XSS vulnerability and why the single defense
mechanism might not fully mitigate XSS vulnerability.</p>
<img loading="lazy" src="/xss-in-hidden-input-field-challenge-9/image-72.png"><h2 id="practicals"><strong>Practicals</strong></h2>
<p>Visit <a href="http://localhost:8066/"><a href="http://localhost:8066">http://localhost:8066</a></a> and ensure it&rsquo;s
accessible, then navigate to “<a href="http://localhost:8066/ch09.php">XSS Challenge
9</a>“.</p>
<figure>
<img src="Kurukshetra-XSS-Challenge-9-Page-fs8.png" />
<figcaption>Kurukshetra XSS Challenge 9 Page</figcaption>
</figure>
<p>The above page looks similar to the challenges we solved earlier.</p>
<p>Take some time and give it a try with all the XSS skills acquired so far
before going any further.</p>
<p>As you guessed, I will go ahead and try out the classic XSS payload to
verify how the application responds.</p>
<p><strong><u>Payload Try 1: Classic</u></strong></p>
<img loading="lazy" src="/xss-in-hidden-input-field-challenge-9/image-74.png"><p><strong><u>Output:</u></strong></p>
<figure>
<img src="CH9-XSS-Payload-Trail-1-fs8.png" />
<figcaption>XSS Payload Trail 1</figcaption>
</figure>
<p>Input the XSS payload and click on the “<strong>Submit</strong>” button. Immediately,
the application echoes out the output as given, and there are no pop-up
messages this time.</p>
<p>This confirms that our payload didn&rsquo;t work. Right-click and select
&ldquo;<strong>View page source</strong>&rdquo; to understand how our payload is being reflected
back in the HTML response.</p>
<p><strong><u>HTML Page Source:</u></strong></p>
<figure>
<img src="CH9-XSS-Payload-Trail-1-Source-fs8.png" />
<figcaption>XSS Payload Trail 1 HTML Page Source View</figcaption>
</figure>
<p>Referring to the above screenshot, an HTML input tag named &ldquo;<strong>xss&rdquo;</strong>
accepts the value and echoes out at the bottom of the code after
encoding the special chars.</p>
<img loading="lazy" src="/xss-in-hidden-input-field-challenge-9/image-77.png"><p>You might be thinking from the previous article that we used the
built-in &ldquo;<strong>HTML attributes&rdquo;</strong> to bypass the encoding and execute the
XSS payload. The same logic can be applied here.</p>
<p>A big <strong>No.</strong> Why?</p>
<p><strong>Challenge 8 – HTML Output:</strong></p>
<figure>
<img src="xss-challenge-8-kurukshetra-fs8-1.png" />
<figcaption>XSS Challenge 8 - Page Source Output</figcaption>
</figure>
<p><strong>Challenge 9 – HTML Output:</strong></p>
<figure>
<img src="xss-challenge-9-kurukshetra-fs8.png" />
<figcaption>XSS Challenge 9 - Page Source Output</figcaption>
</figure>
<p>The major difference between XSS Challenge 8 and Challenge 9 is that in
Challenge 8, the encoded output was injected inside the HTML input tag,
while in Challenge 9, the encoded output is displayed outside of form
HTML tags.</p>
<p>As shown in the above challenge 9 screenshots, even though the HTML
attributes can be injected, as they fall outside the HTML tags, the web
browser would just consider it as text without any special flags.</p>
<p>Therefore, the XSS payload will not work here.</p>
<hr>
<img loading="lazy" src="/xss-in-hidden-input-field-challenge-9/image-78.png"><blockquote>
<p><strong>TIP – 9 Try other params or check for appending values</strong></p>
<p>Yes, the XSS need not always need to be exploited in the same param
value location, it could be checked on the other supporting param
which may use the same value for processing. Also, it can be located
in param values where input values are appended or depended on.</p>
</blockquote>
<hr>
<p><strong>Challenge 9 – HTML source Output</strong></p>
<figure>
<img src="xss-challenge-9-kurukshetra-fs8-1.png" />
<figcaption>XSS Challenge 9 - Page Source Output</figcaption>
</figure>
<p>Paying a bit more attention to our Challenge 9 HTML response, we can see
there is another HTML input tag used of type &ldquo;<strong>hidden&rdquo;</strong>.</p>
<p>In HTML, the hidden input type stores pieces of user data without
displaying it to the user on the frontend. Web browsers generally hide
it, and you can find this data by <strong>viewing page sources</strong> or by using
intercepting proxies like BurpSuite or OWASP ZAP.</p>
<img loading="lazy" src="/xss-in-hidden-input-field-challenge-9/bug.png"><p>Let&rsquo;s go ahead and try the XSS payloads in the hidden fields.</p>
<p>It can be done in multiple ways, as covered in previous articles, such
as using a browser debugger or using intercepting proxies. I will be
using the BurpSuite proxy for usability.</p>
<h2 id="execution-steps"><strong>Execution Steps</strong></h2>
<ol>
<li>Configure and Launch the Burpsuite tool.</li>
<li>Navigate to the &ldquo;<a href="http://localhost:8066/ch09.php">XSS Challenge 9</a>&rdquo;
page.</li>
<li>Enable the BurpSuite interception proxy to intercept the request
before it is sent to the server. To do that, Navigate to BurpSuite
&ldquo;<strong>Proxy&rdquo;</strong> -&gt; &ldquo;<strong>Intercept&rdquo;</strong> -&gt; Toggle the &ldquo;<strong>Intercept is
off&rdquo;</strong> button to enable &ldquo;<strong>Intercept on</strong>&rdquo;.</li>
<li>On the <a href="http://localhost:8066/ch09.php">Challenge 9</a> page, key in
the random input value(say &ldquo;<strong>Test XSS&rdquo;</strong>) and click on the
&ldquo;<strong>submit&rdquo;</strong> button.</li>
<li>The intercepted request will be displayed as shown below:</li>
</ol>
<figure>
<img src="Intercept-Request-fs8.png" />
<figcaption>Intercepted request with hidden tag being
passed</figcaption>
</figure>
<ol>
<li>
<p>Observe that in line 22, the input param and its values are being
passed in the request body section.</p>
</li>
<li>
<p>Replace the &ldquo;<strong>hidden&rdquo;</strong> param value from &ldquo;<strong>Is that it&rdquo;</strong> with
classic XSS payload.</p>
</li>
</ol>
<img loading="lazy" src="/xss-in-hidden-input-field-challenge-9/image-82.png"><p>The modified request will be displayed below.</p>
<figure>
<img src="Modified-Intercept-Request-fs8.png" />
<figcaption>Modified Intercept Request with XSS Payload</figcaption>
</figure>
<ol>
<li>
<p>Toggle off the “<strong>Intercept is on</strong>” button to disable the request
interceptions for now and forward the modified request to the
server. Then, switch back to the web browser.</p>
</li>
<li>
<p>Immediately observe an XSS pop-up message, which will be displayed
as shown below. then click on the “<strong>OK</strong>” button.</p>
</li>
</ol>
<figure>
<img src="XSS-Output-fs8.png" />
<figcaption>XSS Output</figcaption>
</figure>
<ol>
<li><strong>Wow!!</strong> It worked out, and we were able to successfully exploit
XSS challenge 9. 😄</li>
</ol>
<p>Lastly, always verify the HTML response code. Right-click and select
&ldquo;<strong>View page source</strong>&rdquo; to verify how the injected XSS payload is
appended.</p>
<figure>
<img src="XSS-Output-Verify-fs8.png" />
<figcaption>HTML Page Source Code</figcaption>
</figure>
<p>I can confirm that the injected XSS payload in the hidden parameter
value field has been passed to the server and reflected back in the
response without any encodings this time.</p>
<p>Hence, our payload was executed. ☺️</p>
<hr>
<img loading="lazy" src="/xss-in-hidden-input-field-challenge-9/report.png"><h3 id="summary"><strong>Summary</strong></h3>
<p>In this article, we&rsquo;ve seen how other parameters can be utilized to
exploit XSS – it doesn&rsquo;t always have to be done within the same param
field.</p>
]]></content:encoded>
    </item>
    <item>
      <title>Challenge 8: XSS bypass improper output encoding</title>
      <link>https://raghu.io/xss-bypass-improper-output-encoding-challenge-8/</link>
      <pubDate>Mon, 20 Feb 2023 04:45:53 +0000</pubDate>
      <guid>https://raghu.io/xss-bypass-improper-output-encoding-challenge-8/</guid>
      <description>Learn how the partially implemented HTML output encoding can be bypassed for exploiting XSS vulnerability using the HTML5 attributes</description>
      <content:encoded><![CDATA[<p>Welcome back to learning Cross-Site Scripting(XSS) with the Kurukshetra
series. An app built by <a href="https://github.com/D4rk36/Kurukshetra">d4rk36</a>.</p>
<p>Before we start, ensure the lab is up and running. If you have not set
up your lab yet. Feel free to refer back to the below link.</p>
<p><a href="/xss-explained-learn-cross-site-scripting-with-examples/">XSS Explained - Learn Cross-Site Scripting with
Examples</a></p>
<hr>
<img loading="lazy" src="/xss-bypass-improper-output-encoding-challenge-8/image-56.png"><h3 id="practicals">Practicals</h3>
<p>Hope by now you are familiar with what an XSS is and how it can be
identified. In this article, you will be learning about how to exploit
XSS when limited characters are allowed.</p>
<p>Post setting up the lab visit <a href="http://localhost:8066">http://localhost:8066</a> and ensure it&rsquo;s
accessible, then navigate to &ldquo;<a href="http://localhost:8066/ch08.php"><strong>XSS Challenge
8</strong></a>&rdquo;.</p>
<figure>
<img src="Kurukshetra-XSS-Challenge-8-Page-fs8.png" />
<figcaption>Kurukshetra XSS Challenge 8 page</figcaption>
</figure>
<p>From the above screenshot, I can see that the application is requesting
the input value in the &ldquo;Try Your XSS payload?&rdquo; field.</p>
<p>Feel free to try and experiment with different payloads.</p>
<p>Initially, I will go ahead and try out our classic XSS payload, which
has been used throughout our series.</p>
<p><strong><u>Payload Try 1: Classic</u></strong></p>
<img loading="lazy" src="/xss-bypass-improper-output-encoding-challenge-8/image-45.png"><p><strong><u>Output:</u></strong></p>
<figure>
<img src="CH8-XSS-Payload-Trail-1-fs8.png" />
<figcaption>XSS Payload Trail 1</figcaption>
</figure>
<p>After keying in the payload value and clicking on the &ldquo;<strong>Submit</strong>&rdquo;
button. Looks like nothing happened.</p>
<p>No pop-ups and no partial or filtered messages. Interesting!</p>
<p>Let&rsquo;s go ahead and view the HTML source code received from the server to
understand what is happening in the background.</p>
<p>Right-click and select &ldquo;<strong>View page source</strong>&rdquo;, then search for the
injected payload string.</p>
<figure>
<img src="image-59.png" />
<figcaption>HTTP Response</figcaption>
</figure>
<p>From the above screenshot, it could be understood that output encoding
has been applied to injected XSS payload which prevents execution of the
script tag.</p>
<p>Try out and verify all the XSS payloads which have been discussed
throughout the series. Using IMG tag XSS, SVG tag-based XSS, etc.</p>
<hr>
<img loading="lazy" src="/xss-bypass-improper-output-encoding-challenge-8/image-60.png"><blockquote>
<p><strong>Tip 8 - Use allowed characters to build XSS payload</strong></p>
<p>As the heading says, you can keep on trying out any number of HTML
tags and verify which XSS payload works. Or another better option
could be to find out the list of allowed characters with multiple
trials and errors and craft one using the allowed list of characters.</p>
</blockquote>
<hr>
<img loading="lazy" src="/xss-bypass-improper-output-encoding-challenge-8/image-61.png"><h3 id="identifying-allowed-characters">Identifying Allowed Characters</h3>
<p>Using previous XSS payload output can confirm the javascript <strong>alert()</strong>
function is allowed, next single quotes &ldquo;<strong>&rsquo;</strong>&rdquo; are allowed, &ldquo;<strong>/</strong>&rdquo;
slash is allowed, and lastly alphabets are allowed too.</p>
<p>Now need to find out, how the allowed list of characters can be used and
make the XSS payload work.</p>
<img loading="lazy" src="/xss-bypass-improper-output-encoding-challenge-8/image-62.png"><p>Remember the XSS payload used in &ldquo;<a href="/xss-using-html-attribute-challenge-4/">Challenge
4</a>&rdquo;, Using HTML5
Attribute.</p>
<img loading="lazy" src="/xss-bypass-improper-output-encoding-challenge-8/image-63.png"><p>In the above XSS payload, can see that most of the characters are
allowed, but we haven&rsquo;t verified double quotes &ldquo;&rdquo;.</p>
<p>Quickly will go ahead and verify if the double quotes are allowed in the
input field. By injecting and viewing the page source code.</p>
<p><u>Output 2:</u></p>
<img loading="lazy" src="/xss-bypass-improper-output-encoding-challenge-8/image-64.png"><p>Now, can confirm that double quotes are also allowed as injected without
any encoding or escaping. Nice!</p>
<p>Let&rsquo;s understand the XSS payload before trying it out.</p>
<figure>
<img src="image-65.png" />
<figcaption>XSS HTML Attribute Payload</figcaption>
</figure>
<p>Our motto is to rightly align the XSS payload in HTML response code and
make it executable.</p>
<p>All the injected payload characters are inserted within the HTML input
tag within the value field.</p>
<p>If the input is keyed in like <strong>onmouseover=alert(&lsquo;xss&rsquo;)</strong> without
quotes, it would be treated as text, and all the HTML attributes will
not be of much help here. For the same reason, we use the extra quotes
to properly align inside the input value field.</p>
<ol>
<li>A double quote for closing the value section</li>
<li><strong>onmouseover</strong> is one of the HTML attributes that can be used with
HTML tags. The moment the mouse hovers over the code, the given
javascript <strong>alert()</strong> function gets triggered.</li>
<li>Another double quote to make sure the remaining double quote of the
value field is aligned with HTML syntax.</li>
</ol>
<p>Enter the above-improvised payload in the input field and click on the
&ldquo;<strong>Submit</strong>&rdquo; button.</p>
<p><strong>Output 3:</strong></p>
<figure>
<img src="CH8-Page-fs8.png" />
<figcaption>XSS Challenge Page 8</figcaption>
</figure>
<p>For a moment, things seemed like nothing had happened, and the
application behaved normally as expected. As seen before.</p>
<p>Hover over your mouse onto the input field and observe, immediately a
pop-up message is prompted as shown below.</p>
<figure>
<img src="CH8-XSS-Alert-fs8.png" />
<figcaption>XSS Alert Message</figcaption>
</figure>
<p><strong>Waah!! 🎉</strong> Our XSS payload worked. Let&rsquo;s verify the HTML response
code to confirm how the XSS payload is aligned further.</p>
<p>Right-click on the &ldquo;<strong>View page source</strong>&rdquo; and search for the injected
XSS payload string.</p>
<img loading="lazy" src="/xss-bypass-improper-output-encoding-challenge-8/image-69.png"><p>The given payload got rightly aligned and only the allowed list of
characters and HTML attributes have been used to exploit it.</p>
<p>We have successfully solved the XSS challenge 8.</p>
<hr>
<img loading="lazy" src="/xss-bypass-improper-output-encoding-challenge-8/image-70.png"><h3 id="summary"><strong>Summary</strong></h3>
<p>This post demonstrates how generally output encoding is used to prevent
XSS, but that itself is not enough to prevent the XSS vulnerability. The
input HTML attributes and allowed characters can be carefully used to
craft a working payload. To prevent the XSS vulnerability a
Defense-In-Depth approach needs to be leveraged. Like performing output
encoding, sanitizing, using CSP, etc. Which would be covered later.</p>
<p>Keep learning! 😃</p>
]]></content:encoded>
    </item>
    <item>
      <title>Challenge 7: XSS in a dropdown list</title>
      <link>https://raghu.io/xss-in-dropdown-list-challenge-7/</link>
      <pubDate>Fri, 10 Feb 2023 05:40:27 +0000</pubDate>
      <guid>https://raghu.io/xss-in-dropdown-list-challenge-7/</guid>
      <description>Learn how the XSS vulnerability can be found in other params even though it is not editable by the browser using the BurpSuite Proxy tool</description>
      <content:encoded><![CDATA[<p>Welcome back to learning Cross-Site Scripting(XSS) with the Kurukshetra
series. An app built by <a href="https://github.com/D4rk36/Kurukshetra">d4rk36</a>.</p>
<p>Before we start, ensure the lab is up and running, If you have not set
up your lab yet. Feel free to refer back to the below link.</p>
<p><a href="/xss-explained-learn-cross-site-scripting-with-examples/">XSS Explained - Learn Cross-Site Scripting with
Examples</a></p>
<hr>
<img loading="lazy" src="/xss-in-dropdown-list-challenge-7/image-42.png"><h3 id="recap">Recap</h3>
<p>The previous article covered reflected cross-site scripting scenarios
where poor input validation checks can be exploited further.</p>
<p>Also, it demonstrated the impact of missing input validation checks on
the server side. Therefore the input validations must be implemented
well on both the client &amp; server sides.</p>
<hr>
<img loading="lazy" src="/xss-in-dropdown-list-challenge-7/image-43.png"><h3 id="practicals">Practicals</h3>
<p>Post setting up the lab visit <a href="http://localhost:8066">http://localhost:8066</a> and ensure it&rsquo;s
accessible, then navigate to &ldquo;<a href="http://localhost:8066/ch07.php"><strong>XSS Challenge
7</strong></a>&rdquo;.</p>
<figure>
<img src="Kurukshetra-XSS-Challenge-7-Page-fs8.png" />
<figcaption>Kurukshetra XSS Challenge 7 Page</figcaption>
</figure>
<p>Coming to XSS Challenge 7, an input field is given to key in the text
and a drop-down menu option needs to be selected before clicking on the
&ldquo;<strong>Submit</strong>&rdquo; button.</p>
<p>Will try out all the things techniques learned so far about identifying
the XSS vulnerability.</p>
<p><strong><u>Payload Try 1: Classic</u></strong></p>
<img loading="lazy" src="/xss-in-dropdown-list-challenge-7/image-45.png"><p><strong>Output:</strong></p>
<figure>
<img src="CH7-XSS-Payload-Trail-1-fs8.png" />
<figcaption>XSS Payload Trail 1</figcaption>
</figure>
<p>Using our classic payload, select the default option in the drop-down
menu &ldquo;<strong>India</strong>&rdquo;, then click on the &ldquo;<strong>Submit</strong>&rdquo; button.</p>
<p>Immediately, observe that the payload keyed in is displayed as it is.
Right-click and select &ldquo;<strong>View page source</strong>&rdquo; to understand how the
payload is being embedded in the HTML response.</p>
<img loading="lazy" src="/xss-in-dropdown-list-challenge-7/image-47.png"><p>Scrolling to the bottom of the page, I can see that our tags like
&lsquo;<strong>&lt;</strong>&rsquo;, &lsquo;<strong>&gt;</strong>&rsquo; etc.. have been replaced. This changes the meaning of
the HTML format, and the browser considers it as text and displays it
back without executing it as a script.</p>
<hr>
<img loading="lazy" src="/xss-in-dropdown-list-challenge-7/fixed.png"><ol>
<li>
<p>HTML Output Encoding</p>
<p>The above output that we are seeing is called HTML output encoding.</p>
<p>Output encoding is one of the mitigation techniques used to take
user-controlled data and safely display it without interpreting it
as code and considering it as text.</p>
<p>Below is an example XSS payload.</p>
<pre><code>&lt;script&gt;alert(document.domain);&lt;/script&gt;
</code></pre>
<p>HTML-encoded text of the XSS payload will be displayed below.</p>
<pre><code>&amp;lt;script&amp;gt;alert(document.domain);&amp;lt;/script&amp;gt;
</code></pre>
<ul>
<li>&ldquo;&lt;&rdquo; changed to &ldquo;&amp;lt;&rdquo;</li>
<li>&ldquo;&gt;&rdquo; changed to &ldquo;&amp;gt;&rdquo;</li>
</ul>
<p>As the browser parses HTML, JavaScript, CSS, and URL differently.
Each must be encoded depending on the requirements.</p>
<p>URL, HTML, JavaScript, and CSS can be encoded.</p>
<p>The input text field in the application seems to be handled
properly, but we need to find another way to exploit it.</p>
<hr>
<img loading="lazy" src="/xss-in-dropdown-list-challenge-7/image-48.png"><blockquote>
<p><strong>Tip 7 - Try exploring other param values</strong></p>
<p>XSS need not be present all the time in the input text fields, it
can be found in other parameters as well which are parsed and used
by the server.</p>
</blockquote>
<hr>
<img loading="lazy" src="/xss-in-dropdown-list-challenge-7/image-49.png"></li>
<li>
<p>Trying XSS in the &ldquo;location&rdquo; param</p>
<p>I will be using the &ldquo;<strong>BurpSuite</strong>&rdquo; proxy tool going ahead with the
demo. Please make sure your browser is preconfigured with the
BurpSuite and working as expected.</p>
<p>Visit the <a href="http://localhost:8066/ch07.php">Challenge 7</a> page.</p>
<p>Enable the BurpSuite interception proxy to intercept the request
before it is sent to the server. To do that, Navigate to BurpSuite
&ldquo;<strong>Proxy</strong>&rdquo; -&gt; &ldquo;<strong>Intercept</strong>&rdquo; -&gt; Toggle the &ldquo;<strong>Intercept is
off</strong>&rdquo; button.</p>
<figure>
<img src="Intercept-On-fs8.png" />
<figcaption>Toggle BurpSuite Intercept On</figcaption>
</figure>
<p>Fill up the input field value with &ldquo;<strong>Test XSS</strong>&rdquo; and then click on
the &ldquo;<strong>Submit</strong>&rdquo; button.</p>
<figure>
<img src="CH7-User-Input-fs8.png" />
<figcaption>Key in User Input</figcaption>
</figure>
<p>Now in the &ldquo;<strong>BurpSuite</strong>&rdquo; proxy tool, observe the request being
transmitted to the server, is intercepted, and displayed as shown
below.</p>
<figure>
<img src="BurpSuite-Intercepted-Request-fs8-1.png" />
<figcaption>BurpSuite Intercepted Request</figcaption>
</figure>
<p>Observe at the bottom of the request the &ldquo;<strong>xss</strong>&rdquo;, &ldquo;<strong>location</strong>&rdquo;
and &ldquo;<strong>submit</strong>&rdquo; params are being passed to the server.</p>
<p>Remember, in the previous article <a href="/xss-bypass-client-side-blacklist-validation-challenge-6/">Challenge
6</a>,
we sent the modified XSS payload to the server.</p>
<p>In a similar way, this time in the &ldquo;<strong>location</strong>&rdquo; param value append
our classic XSS payload, which will be displayed as shown below.</p>
<figure>
<img src="CH7-Burpsuite-Modified-Request-fs8.png" />
<figcaption>Modified Request with XSS Payload</figcaption>
</figure>
<p>Next, toggle off the &ldquo;<strong>Intercept is on</strong>&rdquo; button to disable the
request interception for now. Immediately switch back to the web
browser.</p>
<figure>
<img src="CH7-BurpSutie-Intercept-Off-fs8.png" />
<figcaption>Intercept Toggle Off</figcaption>
</figure>
<p>Immediately observe that an XSS pop-up message will be displayed, as
shown below.</p>
<figure>
<img src="CH7-XSS-Alert-fs8.png" />
<figcaption>XSS Alert Message</figcaption>
</figure>
<p><strong>YAY!! 🎉</strong> by this, we can confirm the application is still
vulnerable to the cross-site scripting vulnerability.</p>
<p>Click the &ldquo;<strong>OK</strong>&rdquo; button to continue, then right-click and select
&ldquo;<strong>View page source</strong>&rdquo; to very our payload injection. Search for the
payload inserted.</p>
<img loading="lazy" src="/xss-in-dropdown-list-challenge-7/image-54.png"><p>You can find the inserted payload at the bottom of the page. This
time, you can see that our payload is displayed as given without any
output encoding.</p>
<p>By this, we have successfully exploited the XSS challenge 7.</p>
<hr>
<img loading="lazy" src="/xss-in-dropdown-list-challenge-7/image-55.png"></li>
</ol>
<h3 id="summary"><strong>Summary</strong></h3>
<p>The key takeaway from this article is XSS need not necessarily be
exploited from the user input form fields, the XSS vulnerability can be
tested in any param header and value fields that are parsed by the
server.</p>
<p>Keep learning! 😃</p>
]]></content:encoded>
    </item>
    <item>
      <title>Challenge 6: XSS Bypass Client-Side Blacklist Validation</title>
      <link>https://raghu.io/xss-bypass-client-side-blacklist-validation-challenge-6/</link>
      <pubDate>Mon, 06 Feb 2023 11:22:01 +0000</pubDate>
      <guid>https://raghu.io/xss-bypass-client-side-blacklist-validation-challenge-6/</guid>
      <description>Learn why client-side validation cannot be trusted all the time and how it can be tampered with by using BurpSuite as a proxy for exploiting XSS</description>
      <content:encoded><![CDATA[<p>Welcome back to learning Cross-Site Scripting(XSS) with the Kurukshetra
series. An app built by <a href="https://github.com/D4rk36/Kurukshetra">d4rk36</a>.</p>
<p>Before we start, ensure the lab is up and running. If you have not set
up your lab yet. Feel free to refer back to the below link.</p>
<p><a href="/xss-explained-learn-cross-site-scripting-with-examples/">XSS Explained - Learn Cross-Site Scripting with
Examples</a></p>
<hr>
<img loading="lazy" src="/xss-bypass-client-side-blacklist-validation-challenge-6/image.png"><h3 id="practicals">Practicals</h3>
<p>Post setting up the lab visit <a href="http://localhost:8066">http://localhost:8066</a> and ensure it&rsquo;s
accessible, then navigate to &ldquo;<a href="http://localhost:8066/ch06.php"><strong>XSS Challenge
6</strong></a>&rdquo;.</p>
<figure>
<img src="Kurukshetra-XSS-Challenge-6-Page-fs8.png" />
<figcaption>Kurukshetra XSS Challenge Page 6</figcaption>
</figure>
<p>I hope by now you are familiar with what an XSS is and how it can be
exploited. In this article, we shall learn more about identifying XSS
vulnerabilities.</p>
<p>Without much waiting, let&rsquo;s try our classic XSS payload on &ldquo;<a href="http://localhost:8066/ch06.php"><strong>Challenge
6</strong></a>&rdquo; and understand what the result we
are getting.</p>
<p><strong><u>Payload Try 1: Classic</u></strong></p>
<img loading="lazy" src="/xss-bypass-client-side-blacklist-validation-challenge-6/image-2.png"><p><strong>Output:</strong></p>
<figure>
<img src="CH6-XSS-Payload-Trail1-fs8.png" />
<figcaption>XSS Payload Trail 1</figcaption>
</figure>
<p>The output seems to be something familiar. We have seen this type of
output earlier as well.</p>
<p><strong>Yes</strong>, we have seen this type of output when learning about the
reflected cross-site scripting vulnerability in <a href="/challenge-3-xss-bypass-blacklist-html-tags/">Challenge
3</a>. We. Almost the
same, with a slight change.<br>
<br>
Let&rsquo;s explore it.</p>
<hr>
<img loading="lazy" src="/xss-bypass-client-side-blacklist-validation-challenge-6/image-28.png"><h3 id="understanding-application-behaviour">Understanding Application Behaviour</h3>
<p>Below is the output that we received when trying to use a classic XSS
payload.</p>
<figure>
<img src="CH6-XSS-Payload-Trail1-fs8-1.png" />
<figcaption>XSS Payload Trail 1 Result</figcaption>
</figure>
<p>Right-click and select &ldquo;<strong>View page source</strong>&rdquo; to view the HTML source
code. I search and scroll down through the HTML code to understand what
is happening with our input field. You will be able to find the code
snippet as shown below.</p>
<img loading="lazy" src="/xss-bypass-client-side-blacklist-validation-challenge-6/image-24.png"><p>The HTML input tag seems very similar as seen in previous challenges.</p>
<img loading="lazy" src="/xss-bypass-client-side-blacklist-validation-challenge-6/image-22.png"><p>Taking a closer look, whenever we click on the &ldquo;submit&rdquo; button, the HTML
form is running a &ldquo;<strong>filter()&rdquo;</strong> javascript function.</p>
<p>JavaScript is used for adding dynamic capabilities to the page making it
user-friendly.</p>
<p>In the same HTML code, will search for the javascript code.</p>
<img loading="lazy" src="/xss-bypass-client-side-blacklist-validation-challenge-6/image-25.png"><p>Scrolling through the top of the page, I can see a javascript file named
&ldquo;<strong>ch06.js</strong>&rdquo; has been included. Clicking on the file, the javascript
code opens, as shown below.</p>
<img loading="lazy" src="/xss-bypass-client-side-blacklist-validation-challenge-6/image-26.png"><p>We found the &ldquo;<strong>filter()</strong>&rdquo; function javascript code. A blacklisting
approach of input filtering is being used.</p>
<p>You can see the <strong>script, svg,</strong> and <strong>img</strong> HTML tags being stripped
out on the client side by the javascript <strong>filter()</strong> function.</p>
<p>The above code is an example that demonstrates that the client-side
validation check is in place. Remember from the previous article</p>
<blockquote>
<p>Input validation checks need to be applied on both the client and the
server side.</p>
</blockquote>
<hr>
<img loading="lazy" src="/xss-bypass-client-side-blacklist-validation-challenge-6/image-29.png"><blockquote>
<p><strong>Tip 6 - Client Side validations can be bypassed</strong></p>
<p><strong>Yes, you are hearing right.</strong> Every piece of instruction sent from
the client side browser can be tampered with or removed or new data
can also be added.</p>
<p>One way is through using browser addons like i.e. <a href="https://chrome.google.com/webstore/detail/tamper-chrome-extension/hifhgpdkfodlpnlmlnmhchnkepplebkb">Tamper Data for
Chrome</a>
etc. Available for firefox as well.</p>
<p>Another way is using the interceptor proxy tools like
<a href="https://portswigger.net/">BurpSuite</a> or <a href="https://www.zaproxy.org/">OWASP
ZAP</a>. Once configured with the web browser,
they can help to view/modify every request before it is sent to the
server.<br>
<br>
In our demonstrations going ahead, I will be using the &ldquo;<a href="https://portswigger.net/"><strong>BurpSuite
Community</strong></a>&rdquo;
edition. Please refer to the tool documentation which can help you in
getting started.</p>
</blockquote>
<hr>
<img loading="lazy" src="/xss-bypass-client-side-blacklist-validation-challenge-6/image-20.png"><ol>
<li>
<p>Bypassing Client Side validation</p>
<p>Hope by now your web browser is configured and ready to use with the
BurpSuite.</p>
<p>Step 1. Navigate to &ldquo;<a href="http://localhost:8066/ch06.php"><strong>XSS Challenge
6</strong></a>&rdquo;</p>
<figure>
<img src="Kurukshetra-XSS-Challenge-6-Page-fs8-1.png" />
<figcaption>XSS Challenge Page 6</figcaption>
</figure>
<p>Step 2. Enable the BurpSuite interception proxy to intercept the
request before it is sent to the server. To do that, Navigate to
BurpSuite &ldquo;<strong>Proxy</strong>&rdquo; -&gt; &ldquo;<strong>Intercept</strong>&rdquo; -&gt; Toggle the
&ldquo;<strong>Intercept is off</strong>&rdquo; button.</p>
<figure>
<img src="BurpSuite-Intercept-fs8-1.png" />
<figcaption>Toggle BurpSuite Intercept On</figcaption>
</figure>
<p>Step 3. In the XSS challenge 6 page, key in with the classic XSS
Payload, then click on the <strong>submit</strong> button.</p>
<figure>
<img src="CH6-XSS-Payload-Trail-fs8.png" />
<figcaption>XSS Payload Trail</figcaption>
</figure>
<p>Step 4. Observe the intercepted request from your web browser, which
will be displayed below.</p>
<figure>
<img src="BurpSuite-Intercepted-Request-fs8.png" />
<figcaption>BurpSuite Intercepted Request</figcaption>
</figure>
<p>Don&rsquo;t worry about the overwhelming information. This is the RAW
format in which the web browser and server exchange HTTP messages.
The underlined text indicates our input text is being sent in a
URL-encoded format.</p>
<p>Decoded text is nothing but the filtered input value.</p>
<img loading="lazy" src="/xss-bypass-client-side-blacklist-validation-challenge-6/image-34.png"><p>This explains why JavaScript validations strip out our XSS payload
on the client side.</p>
<p>Step 5. Replace the underlined text with our classic XSS payload, as
shown below.</p>
<figure>
<img src="BurpSuite-Modified-Intercepted-Request-fs8.png" />
<figcaption>Modified the Intercepted Request</figcaption>
</figure>
<p>Step 6. Toggle off the &ldquo;<strong>Intercept is on</strong>&rdquo; button to disable the
request interceptions for now. Immediately switch back to the web
browser.</p>
<figure>
<img src="image-36.png" />
<figcaption>Toggle Intercept Off</figcaption>
</figure>
<p>Step 7. Immediately observe that an XSS pop-up message will be
displayed, as shown below. then click on the &ldquo;<strong>OK</strong>&rdquo; button to
continue loading.</p>
<figure>
<img src="image-37.png" />
<figcaption>XSS Alert pop-up</figcaption>
</figure>
<p>The application load back the challenge page normally. To further
confirm click on the &ldquo;<strong>View Page Source</strong>&rdquo; for our injected XSS
payload.</p>
<figure>
<img src="BurpSuite-Modified-Request-HTML-Source-fs8.png" />
<figcaption>Page Source of Modified HTML request</figcaption>
</figure>
<p><strong>YAY!! 🎉</strong> By this, we can confirm the application is still
vulnerable to cross-site scripting vulnerability.</p>
<hr>
<img loading="lazy" src="/xss-bypass-client-side-blacklist-validation-challenge-6/image-40.png"><p>The XSS payload still worked because the input field validation is
only implemented on the client side using JavaScript but not on the
server side.</p>
<p>As there were no filters on the server side, our XSS payload passed
through as an HTTP request to the server and reflected in the HTTP
response as keyed-in.</p>
<hr>
<img loading="lazy" src="/xss-bypass-client-side-blacklist-validation-challenge-6/image-41.png"></li>
</ol>
<h3 id="summary"><strong>Summary</strong></h3>
<p>The important lesson to take away from this article is that for the
developers, the input validations need to be implemented both on the
client side as well as on the server side. For security researchers,
make sure to verify the validation checks are equally implemented on the
server side as well.</p>
<p>Keep learning! 😃</p>
]]></content:encoded>
    </item>
    <item>
      <title>Challenge 5: XSS bypass Client-Side Length Limit</title>
      <link>https://raghu.io/xss-bypass-client-side-length-limit-challenge-5/</link>
      <pubDate>Thu, 02 Feb 2023 05:48:16 +0000</pubDate>
      <guid>https://raghu.io/xss-bypass-client-side-length-limit-challenge-5/</guid>
      <description>Learn why client-side validation cannot be trusted all the time and how it can be tampered with by browser debugging tools for exploiting XSS</description>
      <content:encoded><![CDATA[<p>Welcome back to learning Cross-Site Scripting(XSS) with the Kurukshetra.
An app built by <a href="https://github.com/D4rk36/Kurukshetra">d4rk36</a>.</p>
<p>Before we start, ensure the lab is up and running if you have not set up
your lab yet. Feel free to refer back to the below link.</p>
<p><a href="/xss-explained-learn-cross-site-scripting-with-examples/">XSS Explained - Learn Cross-Site Scripting with
Examples</a></p>
<hr>
<img loading="lazy" src="/xss-bypass-client-side-length-limit-challenge-5/image.png"><h3 id="practicals">Practicals</h3>
<p>Post setting up the lab visit <a href="http://localhost:8066">http://localhost:8066</a> and ensure it&rsquo;s
accessible, then navigate to &ldquo;<a href="http://localhost:8066/ch05.php"><strong>XSS Challenge
5</strong></a>&rdquo;.</p>
<figure>
<img src="Kurkukshetra-XSS-Challenge-5-Page-fs8.png" />
<figcaption>Kurukshetra XSS Challenge 5 page</figcaption>
</figure>
<p>Give it a try with all the payloads we have learned so far.</p>
<p>I will go ahead and give it a try with our classic XSS payload.</p>
<p><strong><u>Payload Try 1: Classic</u></strong></p>
<img loading="lazy" src="/xss-bypass-client-side-length-limit-challenge-5/image-2.png"><p><strong>Output:</strong></p>
<figure>
<img src="CH5-Unable-to-input-fs8.png" />
<figcaption>Unable to key in the input beyond 3 chars</figcaption>
</figure>
<p>Observe that we cannot enter any characters after &ldquo;<strong>&lt;sc</strong>&rdquo;. All the
characters typed after are no longer considered.</p>
<p><em>What might be happening in the background?</em></p>
<p>Let&rsquo;s go ahead and view the page&rsquo;s HTML source code to understand
further. Type &ldquo;<strong>Ctrl + u</strong>&rdquo; or right-click and select &ldquo;<strong>View page
source</strong>&rdquo;.</p>
<p>In the HTML source code, scroll down to the input field and you should
be able to see the code similar to the one below.</p>
<img loading="lazy" src="/xss-bypass-client-side-length-limit-challenge-5/image-4.png"><p>For the current input field where we are trying to enter the values, the
&ldquo;<strong>max length is set to 3</strong>&rdquo;. For the same, we are not able to enter
more than 3 characters in the input field.</p>
<hr>
<figure>
<img src="image-5.png" />
<figcaption>Thinking</figcaption>
</figure>
<p>Can we bypass the length limitations? <strong>Possible.</strong> let&rsquo;s give it a try.</p>
<hr>
<blockquote>
<p><strong>Tip 5 - Client/Server Side validation bypass</strong></p>
<p>In general, input validations for the applications will need to be
validated both on the client side and on the server side.</p>
<p>In some cases, the input validations might be missing on either side.</p>
</blockquote>
<hr>
<img loading="lazy" src="/xss-bypass-client-side-length-limit-challenge-5/image-7.png"><ol>
<li>
<p>Tampering Client Side validation</p>
<p>In our current scenario, we surely know that the length limitations
for the characters are set on the client side. (i.e.
<strong>maxlength=&ldquo;3&rdquo;</strong> )</p>
<p>There are many ways to do it, in this article we shall be using a
simple technique using the browser&rsquo;s inbuilt functionalities.</p>
<p><strong>Output:</strong></p>
<figure>
<img src="CH5-Unable-to-input-fs8-1.png" />
<figcaption>Unable to key in the input beyond 3 chars</figcaption>
</figure>
<p>On the current output page, right-click on the input field and
select &ldquo;<strong>inspect</strong>&rdquo;. (In some cases, you might need to right-click
on the input field and select &ldquo;inspect&rdquo; twice to narrow down to the
exact position of the input HTML code)</p>
<p>Output from the &ldquo;<strong>inspect</strong>&rdquo; will be displayed below.</p>
<figure>
<img src="CH5-Browser-Inspect-fs8.png" />
<figcaption>Open Browser Inspect</figcaption>
</figure>
<p>Double click on the <strong>maxlength=&ldquo;3&rdquo;</strong> value field and change it to
<strong>200</strong> or some bigger value.</p>
<figure>
<img src="CH5-Browser-Inspect-Value-fs8.png" />
<figcaption>In browser Inspect change max length</figcaption>
</figure>
<p>Observe, now the length limitations on the client side are updated
and then click on cross &ldquo;<strong>x</strong>&rdquo; to close the browser debugger.</p>
<p>Let&rsquo;s go ahead and re-try out the classic XSS payload.</p>
<figure>
<img src="CH5-XSS-Payload-fs8.png" />
<figcaption>XSS Payload Trail</figcaption>
</figure>
<p><strong>Output:</strong></p>
<figure>
<img src="CH5-XSS-Payload-Alert-fs8.png" />
<figcaption>XSS Payload Result</figcaption>
</figure>
<p><strong>Yay!!! 🎉 we got an XSS pop-up.</strong></p>
<p>Yes, We have successfully exploited the XSS vulnerability again by
tampering with client-side validation checks.</p>
<blockquote>
<p>One thing to take away from this article is all the validation
checks applied on the input field need to be applied on both
client side and on the server side.</p>
</blockquote>
<hr>
<img loading="lazy" src="/xss-bypass-client-side-length-limit-challenge-5/image-16.png"></li>
</ol>
<h3 id="summary"><strong>Summary</strong></h3>
<p>In this article, we learned how client-side validation can be tampered
with and bypassed to execute the XSS payload. Also, learned that the
input validations need to be equally applied both on the client/server
side.</p>
<p>Keep learning! 😃</p>
]]></content:encoded>
    </item>
    <item>
      <title>Challenge 4: XSS using HTML attribute</title>
      <link>https://raghu.io/xss-using-html-attribute-challenge-4/</link>
      <pubDate>Wed, 18 Jan 2023 07:29:22 +0000</pubDate>
      <guid>https://raghu.io/xss-using-html-attribute-challenge-4/</guid>
      <description>Learn how the XSS payload can be crafted using HTML5 event attributes rather than using the classic &amp;lt;script&amp;gt; tag</description>
      <content:encoded><![CDATA[<p>Welcome back to learning Cross-Site Scripting(XSS) with the Kurukshetra.
An app built by <a href="https://github.com/D4rk36/Kurukshetra">d4rk36</a>.</p>
<p>Before we start, ensure the lab is up and running. If you have not set
up your lab yet. Feel free to refer back to the below link.</p>
<p><a href="/xss-explained-learn-cross-site-scripting-with-examples/">XSS Explained - Learn Cross-Site Scripting with
Examples</a></p>
<hr>
<img loading="lazy" src="/xss-using-html-attribute-challenge-4/lab.png"><h3 id="practicals">Practicals</h3>
<p>After setting up the lab, visit <a href="http://localhost:8066">http://localhost:8066</a> and ensure it&rsquo;s
accessible, then navigate to &ldquo;<a href="http://localhost:8066/ch04.php"><strong>XSS Challenge
4</strong></a>&rdquo;.</p>
<figure>
<img src="Kurukshetra-XSS-Challenge-Page-4-fs8.png" />
<figcaption>Kurukshetra XSS Challenge 4 Page</figcaption>
</figure>
<p>Give it a try with all the payloads you have learned so far.</p>
<p>I will go ahead and give it a try with our classic XSS payload.</p>
<p><strong><u>Payload Try 1: Classic</u></strong></p>
<img loading="lazy" src="/xss-using-html-attribute-challenge-4/image-26.png"><p><strong>Output:</strong></p>
<figure>
<img src="CH4-XSS-Payload1-Trial-fs8.png" />
<figcaption>XSS Payload Trial 1</figcaption>
</figure>
<p>Enter the XSS payload in the input field and click on the &ldquo;<strong>Submit</strong>&rdquo;
button.</p>
<p>This time, we haven&rsquo;t gotten any pop-up messages indicating that our XSS
payload didn&rsquo;t work.</p>
<p>Right-click and select &ldquo;<strong>View page source</strong>&rdquo;, then search for the given
payload to understand what exactly is happing with injected payload.</p>
<img loading="lazy" src="/xss-using-html-attribute-challenge-4/image-28.png"><p>Observe, that our script code given as input, is reflected in the HTTP
response and is correctly placed in between the input value quotes.
Which is working as expected.</p>
<p>All the payload is being treated as a text value and is no longer able
to control the behavior of HTML code.</p>
<p>Can we assume that the vulnerability is fixed? <strong>May be</strong></p>
<img loading="lazy" src="/xss-using-html-attribute-challenge-4/thinking.png"><p>Closely observe that all the characters typed in the input payload are
being injected and reflected in the HTML response without much filtering
or encoding.</p>
<p>It is worth to give a try with other possible ways of exploiting XSS
before we can confirm whether it is fixed or not.</p>
<hr>
<img loading="lazy" src="/xss-using-html-attribute-challenge-4/info.png"><p><strong>TIP - 4</strong></p>
<p>The XSS payloads may not work as given all the time. We need to learn
and find what allowed characters are and a working payload needs to be
carefully crafted out from the allowed list of the character set.</p>
<hr>
<p><strong>Previous HTTP Response Screenshot:</strong></p>
<img loading="lazy" src="/xss-using-html-attribute-challenge-4/image-29.png"><p>In the above, all the given XSS payload is being placed inside the
double quotes. Let&rsquo;s improvise the payload by appending a double quote
before the script tag and see if it can control the HTML response
behavior.</p>
<p><strong>Improvised Payload 1:</strong></p>
<img loading="lazy" src="/xss-using-html-attribute-challenge-4/image-30.png"><p>Enter the above payload in the input field, then click on the
&ldquo;<strong>Submit</strong>&rdquo; button.</p>
<p><strong>Browser Output:</strong></p>
<figure>
<img src="CH4-XSS-Imrprovised-Payload-Trial-fs8.png" />
<figcaption>XSS Improvised Payload Trail Result</figcaption>
</figure>
<p>For the immediate response, click on the &ldquo;<strong>View page source</strong>&rdquo; and
search for the injected payload and how it&rsquo;s being reflected in the HTTP
response.</p>
<img loading="lazy" src="/xss-using-html-attribute-challenge-4/image-32.png"><p>Interestingly, the double quote gets injected and aligns well with the
HTML response code. As we can control the HTML response behavior, This
gives us hint that there is a possibility to exploit reflected XSS
further.</p>
<p>We now have most of the information to craft a working XSS payload.</p>
<hr>
<img loading="lazy" src="/xss-using-html-attribute-challenge-4/image-33.png"><p>The XSS payload here can be crafted in a couple of ways.</p>
<ol>
<li>Trying to use the available/allowed HTML5 event attributes to
execute the reflected XSS. As used in the previous article.</li>
<li>Closing the HTML input form tag, injecting our classic XSS payload,
and commenting out the rest of the code.</li>
</ol>
<p>One way to choose this type of scenario is based on the length
limitations set by the application.</p>
<hr>
<img loading="lazy" src="/xss-using-html-attribute-challenge-4/web-programming128.png"><p>Let&rsquo;s use the first way mentioned above to craft the XSS payload.</p>
<p><strong>Improvised Payload 2: Using HTML5 Attribute</strong></p>
<img loading="lazy" src="/xss-using-html-attribute-challenge-4/image-34.png"><p><strong>onmouseover</strong> is one of the HTML attributes that can be used with HTML
tags, the moment the mouse hovers over the code, the javascript
<strong>alert()</strong> function gets triggered.</p>
<p>Enter the above-improvised payload in the input field and click on the
&ldquo;Submit&rdquo; button.</p>
<p><strong>Output:</strong></p>
<figure>
<img src="CH4-XSS-Onmouseover-Trial-fs8.png" />
<figcaption>XSS Onmouseover Payload Trail</figcaption>
</figure>
<p>For a moment, things seemed like nothing happened, and the application
behaved normally as expected.</p>
<p>Take your mouse, hover over the input field, and observe. Immediately, a
pop-up message is prompted, as shown below.</p>
<figure>
<img src="CH4-XSS-Onmouseover-Alert-fs8.png" />
<figcaption>XSS Onmouseover Payload Result</figcaption>
</figure>
<p><strong>yay!!!</strong>, our XSS payload worked and the application displays the
pop-up message. This confirms that the application is still vulnerable
to the reflected cross-site scripting vulnerability.</p>
<p>Will view the page source code to check how our payload got injected and
changed HTTP response behavior. Right-click and select &ldquo;View page
source&rdquo;, then search for the injected payload string.</p>
<img loading="lazy" src="/xss-using-html-attribute-challenge-4/image-37.png"><p>Observe that the double quote has closed the value field, then appended
the HTML attribute element for the input tag with the &ldquo;<strong>onmouseover&rdquo;</strong>
event along with the javascript code, then closed the double quote to
further align with the HTML code.</p>
<p>We have successfully confirmed that the application is still vulnerable
to cross-site scripting vulnerability.</p>
<hr>
<img loading="lazy" src="/xss-using-html-attribute-challenge-4/web-programming128.png"><p>Let&rsquo;s continue and try out the second method mentioned above to craft
the XSS payload.</p>
<p><strong>Improvised XSS payload 3: Classic XSS with syntax correction</strong></p>
<img loading="lazy" src="/xss-using-html-attribute-challenge-4/image-38.png"><p>The above payload is the same as we used earlier but with minor
modifications.</p>
<p>In prefix, a double code followed by a greater than arrow mark to close
the input form field. Then at the end of the script code append the HTML
comment code, this will comment out all the next code after our HTML
script tag.</p>
<p>Enter the above payload in the input field and give it a try.</p>
<figure>
<img src="CH4-XSS-Second-Method-Payload-Trail-fs8.png" />
<figcaption>Second Method - XSS Payload with Syntax
correction</figcaption>
</figure>
<p><strong>Output:</strong></p>
<p>Immediately, a pop-up message is displayed confirming that the XSS
payload still works.</p>
<figure>
<img src="CH4-XSS-Second-Method-Payload-Alert-fs8.png" />
<figcaption>Second Method - XSS Payload Result</figcaption>
</figure>
<p>Click &ldquo;OK&rdquo;, then Right-click and select &ldquo;<strong>View page source</strong>&rdquo;, then
search for the injected payload string.</p>
<img loading="lazy" src="/xss-using-html-attribute-challenge-4/image-41.png"><p>As expected, observe the HTML input tag is closed, then injected with
our classic XSS payload and followed by commenting out all the rest of
the code after the HTML script tag.</p>
<p>By this, we have successfully exploited the cross-site scripting
vulnerability <strong>challenge 4</strong>.\</p>
<hr>
<figure>
<img src="script-2.png" />
<figcaption>Summary</figcaption>
</figure>
<h3 id="summary"><strong>Summary</strong></h3>
<p>In this article, we learned how poorly implemented validations can still
be bypassed by improving the XSS payload and trying different possible
combinations. Also, there is no need that the default XSS payload needs
to work out of the box, the payload needs to be tweaked based on the
scenarios to make it work.</p>
<p>Keep learning! :D</p>
]]></content:encoded>
    </item>
  </channel>
</rss>
