client side webapp vulnerabilities

31
>> 0 >> 1 >> 2 >> 3 >> 4 >> #CPCO7 @SeguridadBlanca

Upload: dedalo-sb

Post on 05-Jul-2015

1.702 views

Category:

Internet


6 download

DESCRIPTION

This are my slides of my Client Side WebApp Vulnerabilities presentation in #CPCO7

TRANSCRIPT

Page 1: Client Side WebApp Vulnerabilities

>> 0 >> 1 >> 2 >> 3 >> 4 >>

#CPCO7

@SeguridadBlanca

Page 2: Client Side WebApp Vulnerabilities

>> 0 >> 1 >> 2 >> 3 >> 4 >>

¿Quien Soy?

Camilo Galdos AkA Dedalo

Hacker, Security Researcher en:Twitter, Apple, Microsft, Paypal, Ebay, Nokia

y Netflix.Paranoid y No-Fear.

Page 3: Client Side WebApp Vulnerabilities

>> 0 >> 1 >> 2 >> 3 >> 4 >>

Client Side WebApps Vulnerabilities

Page 4: Client Side WebApp Vulnerabilities

>> 0 >> 1 >> 2 >> 3 >> 4 >>

¿Qué es el DOM?

Page 5: Client Side WebApp Vulnerabilities

>> 0 >> 1 >> 2 >> 3 >> 4 >>

¿Que es Xss?

Un cross site scripting es un tipo de inseguridad informática mediante la cual se puede ejecutar código script en la página.

Page 6: Client Side WebApp Vulnerabilities

>> 0 >> 1 >> 2 >> 3 >> 4 >>

Tipos de Xss:

Tipo 1: Persistente.Tipo2: Reflejado.

Tipo 0: DOM-Based.

Page 7: Client Side WebApp Vulnerabilities

>> 0 >> 1 >> 2 >> 3 >> 4 >>

Xss Reflejado

Los xss reflejados son aquellos en los cuales el vector de ataque no se queda guardado

en ninguna base de datos o sessión.

Page 8: Client Side WebApp Vulnerabilities

>> 0 >> 1 >> 2 >> 3 >> 4 >>

¿Como se ve un Reflejado?

<?php

Echo $_GET['x'];

?>

Page 9: Client Side WebApp Vulnerabilities

>> 0 >> 1 >> 2 >> 3 >> 4 >>

Xss Basado en DOM

Los Xss basados en DOM son aquellos que no requieren intersacción con el Servidor, se

ejecutan en Local. En el Javascript.

Page 10: Client Side WebApp Vulnerabilities

>> 0 >> 1 >> 2 >> 3 >> 4 >>

¿Cómo se ve un DOM-Based?

Page 11: Client Side WebApp Vulnerabilities

>> 0 >> 1 >> 2 >> 3 >> 4 >>

¿Cómo se buscan?

Basado en Sinks

Page 12: Client Side WebApp Vulnerabilities

>> 0 >> 1 >> 2 >> 3 >> 4 >>

document.URL

document.documentURI

document.URLUnencoded

document.baseURI

document.location

location.href

location.search

location.hash

location.pathname

window.cookie

window.referrer

window.name

Page 13: Client Side WebApp Vulnerabilities

>> 0 >> 1 >> 2 >> 3 >> 4 >>

¿FrameWorks?

Page 14: Client Side WebApp Vulnerabilities

>> 0 >> 1 >> 2 >> 3 >> 4 >>

Jquery Sinksadd()

append()

after()

before()

html()

prepend()

replaceWith()

wrap()

wrapAll()

Page 15: Client Side WebApp Vulnerabilities

>> 0 >> 1 >> 2 >> 3 >> 4 >>

Page 16: Client Side WebApp Vulnerabilities

>> 0 >> 1 >> 2 >> 3 >> 4 >>

Justo cuando creías entender

Llegó Dedalo con trucos ninja.

Vamos mas allá del “><img src=x onerror=prompt(1337)>

Page 17: Client Side WebApp Vulnerabilities

>> 0 >> 1 >> 2 >> 3 >> 4 >>

Mirando Mas allá de lo evidente

Page 18: Client Side WebApp Vulnerabilities

>> 0 >> 1 >> 2 >> 3 >> 4 >>

Exploiting 1<?php

<script>Document.write(

Echo htmlspecialchars($_GET['x']););

</script>

?>

Page 19: Client Side WebApp Vulnerabilities

>> 0 >> 1 >> 2 >> 3 >> 4 >>

Y se pone mejor.

Page 20: Client Side WebApp Vulnerabilities

>> 0 >> 1 >> 2 >> 3 >> 4 >>

Evitando llegar al waf.

Document.write(Location.hash)

http://localhost/xss2.php#<script>alert(3331337)</script>

Page 21: Client Side WebApp Vulnerabilities

>> 0 >> 1 >> 2 >> 3 >> 4 >>

Ninja Tricks

<body/onload=id=/al/.source+/ert/.source;onerror=this[id];throw+1337

Page 22: Client Side WebApp Vulnerabilities

>> 0 >> 1 >> 2 >> 3 >> 4 >>

Reflejado basado en Flash

Cross Site Flashing

Page 23: Client Side WebApp Vulnerabilities

>> 0 >> 1 >> 2 >> 3 >> 4 >>

Métodos Inseguros

getURL(var,'_self');

Web.com/file.swf?var=javascript:alert(1)

Page 24: Client Side WebApp Vulnerabilities

>> 0 >> 1 >> 2 >> 3 >> 4 >>

Otros MétodosloadVariables()

loadMovie()

getURL()

loadMovie()

loadMovieNum()

FScrollPane.loadScrollContent()

LoadVars.load

LoadVars.send

XML.load ( 'url' )

LoadVars.load ( 'url' )

Sound.loadSound( 'url' , isStreaming );

NetStream.play( 'url' );

htmlText

Page 25: Client Side WebApp Vulnerabilities

>> 0 >> 1 >> 2 >> 3 >> 4 >>

¿Cómo Encuentro?

Page 26: Client Side WebApp Vulnerabilities

>> 0 >> 1 >> 2 >> 3 >> 4 >>

DOM: Como los machos

F12 || Dom King Kong

Page 27: Client Side WebApp Vulnerabilities

>> 0 >> 1 >> 2 >> 3 >> 4 >>

¿XSF? A lo macho

Showmycode.com

Page 28: Client Side WebApp Vulnerabilities

>> 0 >> 1 >> 2 >> 3 >> 4 >>

XSF a lo bruto

XSFF

http://github.com/dedal0

Page 29: Client Side WebApp Vulnerabilities

>> 0 >> 1 >> 2 >> 3 >> 4 >>

DEMOS!!!

Page 30: Client Side WebApp Vulnerabilities

>> 0 >> 1 >> 2 >> 3 >> 4 >>

Necesitas usar tu lógica de programador... Si no programas... ni cagando eres un buen

pentester.

Page 31: Client Side WebApp Vulnerabilities

>> 0 >> 1 >> 2 >> 3 >> 4 >>

Gracias!!! Preguntas?

@[email protected]

Blog.dedalo.in