overview.md (8028B)
1 --- 2 title: "Login Bypass" 3 section: "Web Pentesting" 4 sectionSlug: "pentesting-web" 5 sourcePath: "src/pentesting-web/login-bypass/README.md" 6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/pentesting-web/login-bypass/README.md" 7 sha: "188de82beb54e70956b2952367a0af91d26758b8" 8 isIndex: true 9 modified: true 10 license: "CC-BY-NC-4.0" 11 --- 12 13 # Login Bypass 14 15 ## **Bypass regular login** 16 17 See [Proxmox VE](/hacktricks/network-services-pentesting/pentesting-web/proxmox-ve#root-cause-chain) for a product-specific example of authentication state confusion. 18 19 If you find a login page, test the following authentication and authorization failure modes.<sup>[[3]](#references)</sup> 20 21 - Check for **comments** inside the page (scroll down and to the right?) 22 - Check if you can **directly access the restricted pages** 23 - Check to **not send the parameters** (do not send any or only 1) 24 - Check the **PHP comparisons error:** `user[]=a&pwd=b` , `user=a&pwd[]=b` , `user[]=a&pwd[]=b` 25 - **Change the content type to JSON** and send JSON values, including Boolean values. 26 - If you get a response saying that POST is not supported you can try to send the **JSON in the body but with a GET request** with `Content-Type: application/json` 27 - Check for a Node.js object-parsing issue with payloads such as `password[password]=1`.<sup>[[1]](#references)</sup> 28 - In a vulnerable `mysqljs/mysql` construction, the object can produce a condition similar to: `SELECT id, username, LEFT(password, 8) AS snipped_password, email FROM accounts WHERE username = 'admin' AND password = password = 1;`. The chained comparison may evaluate as true. 29 - If you can send a JSON object you can send `"password":{"password": 1}` to bypass the login. 30 - Remember that to bypass this login you still need to **know and send a valid username**. 31 - Adding the `"stringifyObjects": true` option when calling `mysql.createConnection` prevents this specific object-to-SQL behavior, but parameterized queries and strict schema validation should still be used. 32 - Check credentials: 33 - [**Default credentials**](https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/generic-hacking/brute-force.md#default-credentials) of the technology/platform used 34 - **Common combinations** (root, admin, password, name of the tech, default user with one of these passwords). 35 - Create a dictionary using **Cewl**, **add** the **default** username and password (if there is) and try to brute-force it using all the words as **usernames and password** 36 - **Brute-force** using a bigger **dictionary (**[**Brute force**](https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/generic-hacking/brute-force.md#http-post-form)**)** 37 38 ### SQL Injection authentication bypass 39 40 [Here you can find several tricks to bypass the login via **SQL injections**](../sql-injection/index.html#authentication-bypass). 41 42 In the following page you can find a **custom list to try to bypass login** via SQL Injections: 43 44 45 [Sql Login Bypass](/hacktricks/pentesting-web/login-bypass/sql-login-bypass) 46 47 ### No SQL Injection authentication bypass 48 49 [Here you can find several tricks to bypass the login via **No SQL Injections**](/hacktricks/pentesting-web/nosql-injection#basic-authentication-bypass)**.** 50 51 As the NoSQL Injections requires to change the parameters value, you will need to test them manually. 52 53 ### XPath Injection authentication bypass 54 55 [Here you can find several tricks to bypass the login via **XPath Injection.**](/hacktricks/pentesting-web/xpath-injection#authentication-bypass) 56 57 ```text 58 ' or '1'='1 59 ' or ''=' 60 ' or 1]%00 61 ' or /* or ' 62 ' or "a" or ' 63 ' or 1 or ' 64 ' or true() or ' 65 'or string-length(name(.))<10 or' 66 'or contains(name,'adm') or' 67 'or contains(.,'adm') or' 68 'or position()=2 or' 69 admin' or ' 70 admin' or '1'='2 71 ``` 72 73 ### LDAP Injection authentication bypass 74 75 [Here you can find several tricks to bypass the login via **LDAP Injection.**](/hacktricks/pentesting-web/ldap-injection#login-bypass) 76 77 ```text 78 * 79 *)(& 80 *)(|(& 81 pwd) 82 *)(|(* 83 *))%00 84 admin)(&) 85 pwd 86 admin)(!(&(| 87 pwd)) 88 admin))(|(| 89 ``` 90 91 ### Remember Me 92 93 If the page has "**Remember Me**" functionality check how is it implemented and see if you can abuse it to **takeover other accounts**. 94 95 ### Redirects 96 97 Pages usually redirect users after login. Check whether the destination can be altered to cause an [**Open Redirect**](/hacktricks/pentesting-web/open-redirect), especially when authorization codes or other secrets could be sent through the redirect flow. 98 99 ### Client-side authentication & authorization bypass in SPAs 100 101 Some applications only protect routes/actions in the **frontend** (route guards, hidden buttons, `localStorage` / `sessionStorage`, feature flags, or JSON fields such as `role`, `groups`, `is_active`, `PluginId`, `TimeoutStatus`). If the **backend APIs don't re-check authentication and authorization**, you can often unlock the whole UI or perform the action directly.<sup>[[2]](#references)</sup> 102 103 Quick workflow: 104 105 1. **Read the JS bundle** (`main.js`, chunks, source maps) and search for `authRequired`, `beforeEach`, `isUserLoggedIn`, `localStorage`, `sessionStorage`, `userInfo`, `token`, `exp`, `role`, `groups`, `is_active`, `PluginId`, `TimeoutStatus`. 106 2. **Locate the trust boundary**: identify whether the SPA only checks that a storage key exists, a date is in the future, or a JSON field is truthy. 107 3. **Forge the expected state** in DevTools or intercept proxy traffic to modify the relevant response fields. 108 4. **Validate impact server-side** by performing the hidden action or calling the API directly. If the server accepts it, this is a real auth/authz bypass, not just a cosmetic UI issue. 109 110 Common patterns: 111 112 - **Storage-only login check**: if `isUserLoggedIn()` only checks `localStorage.getItem("token")` and whether `tokenExpiry` is in the future, set both values manually and reload. 113 - **JWT-like parsing without verification**: if frontend code only splits `token` on `.`, base64url-decodes the payload, and reads claims like `_id` or `exp`, any syntactically valid JWT-like value with the expected claims may satisfy the SPA unless the backend verifies it. 114 - **Truthy-object resolver**: if a route resolver only checks `if (userInfo)`, `sessionStorage.setItem("userInfo", JSON.stringify({}))` is often enough because `{}` is valid JSON and truthy. 115 - **Response-driven authorization**: intercept endpoints such as `GetSessionInfo` / `GetNotifications` and replace `null` / `false` values in fields like `Groups`, `PluginId`, or `UserCanUpdate*`; also try removing logout indicators such as `"TimeoutStatus":"Timeout"`. 116 - **UI-only privilege flags**: flip booleans such as `is_active`, `canEdit`, `isAdmin`, or feature flags in profile/account responses to reveal hidden functionality, then try the newly exposed write action. 117 118 ## Other Checks 119 120 - Check if you can **enumerate usernames** abusing the login functionality. 121 - Check the intended autocomplete policy for password and sensitive inputs. The valid value for disabling ordinary form autocomplete is `autocomplete="off"`, not `false`, although browsers and password managers may still offer credential storage. Use purpose-specific tokens such as `current-password`, `new-password`, and `one-time-code` where appropriate.<sup>[[4]](#references)</sup> 122 123 ## Automatic Tools 124 125 - [HTLogin](https://github.com/akinerkisa/HTLogin) 126 127 ## References 128 129 - [1] [Finding an unseen SQL injection by bypassing escape functions in mysqljs/mysql](https://flattsecurity.medium.com/finding-an-unseen-sql-injection-by-bypassing-escape-functions-in-mysqljs-mysql-90b27f6542b4) 130 - [2] [Client-side Authentication Bypass](https://kuldeep.io/posts/client-side-authentication-bypass/) 131 - [3] [OWASP Authentication Cheat Sheet](https://cheatsheetseries.owasp.org/cheatsheets/Authentication_Cheat_Sheet.html) 132 - [4] [MDN - HTML `autocomplete` attribute](https://developer.mozilla.org/en-US/docs/Web/HTML/Attributes/autocomplete)