daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

phone-number-injections.md (2811B)


      1 ---
      2 title: "Phone Number Injections"
      3 section: "Web Pentesting"
      4 sectionSlug: "pentesting-web"
      5 sourcePath: "src/pentesting-web/phone-number-injections.md"
      6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/pentesting-web/phone-number-injections.md"
      7 sha: "188de82beb54e70956b2952367a0af91d26758b8"
      8 isIndex: false
      9 modified: true
     10 license: "CC-BY-NC-4.0"
     11 ---
     12 
     13 # Phone Number Injections
     14 
     15 Applications often treat a phone number as a simple string even though a `tel` URI may contain semicolon-delimited parameters such as `ext`, `isub`, and `phone-context`.<sup>[[1]](#references)</sup> If an application accepts these suffixes but different components validate, store, render, or forward them inconsistently, the suffix may reach an injection sink or bypass controls based on exact string comparison. Test for XSS, SQL injection, SSRF, parser discrepancies, and downstream telephony issues only where the application's data flow makes the corresponding sink plausible.<sup>[[2]](#references)</sup>
     16 
     17 <figure><img src="https://raw.githubusercontent.com/HackTricks-wiki/hacktricks/188de82beb54e70956b2952367a0af91d26758b8/src/images/image%20%28461%29.png" alt="Structure of a telephone URI with a global or local number and optional parameters"><figcaption>Telephone URI structure and common optional parameters.</figcaption></figure>
     18 
     19 <figure><img src="https://raw.githubusercontent.com/HackTricks-wiki/hacktricks/188de82beb54e70956b2952367a0af91d26758b8/src/images/image%20%28941%29.png" alt="Examples of malicious phone-number parameters targeting XSS, SSRF, OTP rate limits, and telephony parsers"><figcaption>Potential issues caused by inconsistent handling of phone-number parameters.</figcaption></figure>
     20 
     21 ## OTP Rate-Limit Bypass
     22 
     23 If a rate limiter keys attempts by the exact submitted string but the delivery provider normalizes multiple parameterized values to the same destination, an attacker may rotate suffixes to obtain separate attempt counters for one account. The figure illustrates the concept with changing `ext` values; successful exploitation depends on the application's and provider's normalization behavior.<sup>[[2]](#references)</sup>
     24 
     25 <figure><img src="https://raw.githubusercontent.com/HackTricks-wiki/hacktricks/188de82beb54e70956b2952367a0af91d26758b8/src/images/image%20%28116%29.png" alt="OTP spraying example that rotates telephone URI extension values to obtain separate rate-limit counters"><figcaption>Conceptual OTP spraying through inconsistent phone-number normalization.</figcaption></figure>
     26 
     27 ## References
     28 
     29 - [1] [RFC 3966 - The `tel` URI for Telephone Numbers](https://www.rfc-editor.org/rfc/rfc3966.html)
     30 - [2] [NahamCon EU 2022 - RTFR (Read The Bleeping RFC), securinti](https://www.youtube.com/watch?v=4ZsTKvfP1g0)