daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

overview.md (8028B)


      1 ---
      2 title: "Login Bypass"
      3 section: "Web Pentesting"
      4 sectionSlug: "pentesting-web"
      5 sourcePath: "src/pentesting-web/login-bypass/README.md"
      6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/pentesting-web/login-bypass/README.md"
      7 sha: "188de82beb54e70956b2952367a0af91d26758b8"
      8 isIndex: true
      9 modified: true
     10 license: "CC-BY-NC-4.0"
     11 ---
     12 
     13 # Login Bypass
     14 
     15 ## **Bypass regular login**
     16 
     17 See [Proxmox VE](/hacktricks/network-services-pentesting/pentesting-web/proxmox-ve#root-cause-chain) for a product-specific example of authentication state confusion.
     18 
     19 If you find a login page, test the following authentication and authorization failure modes.<sup>[[3]](#references)</sup>
     20 
     21 - Check for **comments** inside the page (scroll down and to the right?)
     22 - Check if you can **directly access the restricted pages**
     23 - Check to **not send the parameters** (do not send any or only 1)
     24 - Check the **PHP comparisons error:** `user[]=a&pwd=b` , `user=a&pwd[]=b` , `user[]=a&pwd[]=b`
     25 - **Change the content type to JSON** and send JSON values, including Boolean values.
     26   - If you get a response saying that POST is not supported you can try to send the **JSON in the body but with a GET request** with `Content-Type: application/json`
     27 - Check for a Node.js object-parsing issue with payloads such as `password[password]=1`.<sup>[[1]](#references)</sup>
     28   - In a vulnerable `mysqljs/mysql` construction, the object can produce a condition similar to: `SELECT id, username, LEFT(password, 8) AS snipped_password, email FROM accounts WHERE username = 'admin' AND password = password = 1;`. The chained comparison may evaluate as true.
     29   - If you can send a JSON object you can send `"password":{"password": 1}` to bypass the login.
     30   - Remember that to bypass this login you still need to **know and send a valid username**.
     31   - Adding the `"stringifyObjects": true` option when calling `mysql.createConnection` prevents this specific object-to-SQL behavior, but parameterized queries and strict schema validation should still be used.
     32 - Check credentials:
     33   - [**Default credentials**](https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/generic-hacking/brute-force.md#default-credentials) of the technology/platform used
     34   - **Common combinations** (root, admin, password, name of the tech, default user with one of these passwords).
     35   - Create a dictionary using **Cewl**, **add** the **default** username and password (if there is) and try to brute-force it using all the words as **usernames and password**
     36   - **Brute-force** using a bigger **dictionary (**[**Brute force**](https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/generic-hacking/brute-force.md#http-post-form)**)**
     37 
     38 ### SQL Injection authentication bypass
     39 
     40 [Here you can find several tricks to bypass the login via **SQL injections**](../sql-injection/index.html#authentication-bypass).
     41 
     42 In the following page you can find a **custom list to try to bypass login** via SQL Injections:
     43 
     44 
     45 [Sql Login Bypass](/hacktricks/pentesting-web/login-bypass/sql-login-bypass)
     46 
     47 ### No SQL Injection authentication bypass
     48 
     49 [Here you can find several tricks to bypass the login via **No SQL Injections**](/hacktricks/pentesting-web/nosql-injection#basic-authentication-bypass)**.**
     50 
     51 As the NoSQL Injections requires to change the parameters value, you will need to test them manually.
     52 
     53 ### XPath Injection authentication bypass
     54 
     55 [Here you can find several tricks to bypass the login via **XPath Injection.**](/hacktricks/pentesting-web/xpath-injection#authentication-bypass)
     56 
     57 ```text
     58 ' or '1'='1
     59 ' or ''='
     60 ' or 1]%00
     61 ' or /* or '
     62 ' or "a" or '
     63 ' or 1 or '
     64 ' or true() or '
     65 'or string-length(name(.))<10 or'
     66 'or contains(name,'adm') or'
     67 'or contains(.,'adm') or'
     68 'or position()=2 or'
     69 admin' or '
     70 admin' or '1'='2
     71 ```
     72 
     73 ### LDAP Injection authentication bypass
     74 
     75 [Here you can find several tricks to bypass the login via **LDAP Injection.**](/hacktricks/pentesting-web/ldap-injection#login-bypass)
     76 
     77 ```text
     78 *
     79 *)(&
     80 *)(|(&
     81 pwd)
     82 *)(|(*
     83 *))%00
     84 admin)(&)
     85 pwd
     86 admin)(!(&(|
     87 pwd))
     88 admin))(|(|
     89 ```
     90 
     91 ### Remember Me
     92 
     93 If the page has "**Remember Me**" functionality check how is it implemented and see if you can abuse it to **takeover other accounts**.
     94 
     95 ### Redirects
     96 
     97 Pages usually redirect users after login. Check whether the destination can be altered to cause an [**Open Redirect**](/hacktricks/pentesting-web/open-redirect), especially when authorization codes or other secrets could be sent through the redirect flow.
     98 
     99 ### Client-side authentication & authorization bypass in SPAs
    100 
    101 Some applications only protect routes/actions in the **frontend** (route guards, hidden buttons, `localStorage` / `sessionStorage`, feature flags, or JSON fields such as `role`, `groups`, `is_active`, `PluginId`, `TimeoutStatus`). If the **backend APIs don't re-check authentication and authorization**, you can often unlock the whole UI or perform the action directly.<sup>[[2]](#references)</sup>
    102 
    103 Quick workflow:
    104 
    105 1. **Read the JS bundle** (`main.js`, chunks, source maps) and search for `authRequired`, `beforeEach`, `isUserLoggedIn`, `localStorage`, `sessionStorage`, `userInfo`, `token`, `exp`, `role`, `groups`, `is_active`, `PluginId`, `TimeoutStatus`.
    106 2. **Locate the trust boundary**: identify whether the SPA only checks that a storage key exists, a date is in the future, or a JSON field is truthy.
    107 3. **Forge the expected state** in DevTools or intercept proxy traffic to modify the relevant response fields.
    108 4. **Validate impact server-side** by performing the hidden action or calling the API directly. If the server accepts it, this is a real auth/authz bypass, not just a cosmetic UI issue.
    109 
    110 Common patterns:
    111 
    112 - **Storage-only login check**: if `isUserLoggedIn()` only checks `localStorage.getItem("token")` and whether `tokenExpiry` is in the future, set both values manually and reload.
    113 - **JWT-like parsing without verification**: if frontend code only splits `token` on `.`, base64url-decodes the payload, and reads claims like `_id` or `exp`, any syntactically valid JWT-like value with the expected claims may satisfy the SPA unless the backend verifies it.
    114 - **Truthy-object resolver**: if a route resolver only checks `if (userInfo)`, `sessionStorage.setItem("userInfo", JSON.stringify({}))` is often enough because `{}` is valid JSON and truthy.
    115 - **Response-driven authorization**: intercept endpoints such as `GetSessionInfo` / `GetNotifications` and replace `null` / `false` values in fields like `Groups`, `PluginId`, or `UserCanUpdate*`; also try removing logout indicators such as `"TimeoutStatus":"Timeout"`.
    116 - **UI-only privilege flags**: flip booleans such as `is_active`, `canEdit`, `isAdmin`, or feature flags in profile/account responses to reveal hidden functionality, then try the newly exposed write action.
    117 
    118 ## Other Checks
    119 
    120 - Check if you can **enumerate usernames** abusing the login functionality.
    121 - Check the intended autocomplete policy for password and sensitive inputs. The valid value for disabling ordinary form autocomplete is `autocomplete="off"`, not `false`, although browsers and password managers may still offer credential storage. Use purpose-specific tokens such as `current-password`, `new-password`, and `one-time-code` where appropriate.<sup>[[4]](#references)</sup>
    122 
    123 ## Automatic Tools
    124 
    125 - [HTLogin](https://github.com/akinerkisa/HTLogin)
    126 
    127 ## References
    128 
    129 - [1] [Finding an unseen SQL injection by bypassing escape functions in mysqljs/mysql](https://flattsecurity.medium.com/finding-an-unseen-sql-injection-by-bypassing-escape-functions-in-mysqljs-mysql-90b27f6542b4)
    130 - [2] [Client-side Authentication Bypass](https://kuldeep.io/posts/client-side-authentication-bypass/)
    131 - [3] [OWASP Authentication Cheat Sheet](https://cheatsheetseries.owasp.org/cheatsheets/Authentication_Cheat_Sheet.html)
    132 - [4] [MDN - HTML `autocomplete` attribute](https://developer.mozilla.org/en-US/docs/Web/HTML/Attributes/autocomplete)