daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

sniff-leak.md (1536B)


      1 ---
      2 title: "Sniff Leak"
      3 section: "Web Pentesting"
      4 sectionSlug: "pentesting-web"
      5 sourcePath: "src/pentesting-web/xss-cross-site-scripting/sniff-leak.md"
      6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/pentesting-web/xss-cross-site-scripting/sniff-leak.md"
      7 sha: "188de82beb54e70956b2952367a0af91d26758b8"
      8 isIndex: false
      9 modified: true
     10 license: "CC-BY-NC-4.0"
     11 ---
     12 
     13 # Sniff Leak
     14 
     15 ## Leak Script Content by Interpreting It as UTF-16
     16 
     17 If a `text/plain` response lacks the `X-Content-Type-Options: nosniff` header, a browser may accept it as a script. In the cited challenge, an attacker-controlled prefix supplies a UTF-16 byte-order mark and valid JavaScript bytes. The remaining secret is then decoded as valid identifier characters, allowing the script to expose it through a property of `window`.<sup>[[1]](#references)</sup>
     18 
     19 ## Leak Content by Treating It as an ICO Image
     20 
     21 In a related challenge, a crafted prefix makes the response parse as an ICO image and positions one secret byte in the image-width field. Loading successive variants as cross-origin images and reading their `width` reveals the secret one byte at a time.<sup>[[2]](#references)</sup>
     22 
     23 ## References
     24 
     25 - [1] [UIUCTF 2022 Writeup – "modernism" (UTF-16 content-sniffing leak)](https://blog.huli.tw/2022/08/01/en/uiuctf-2022-writeup/#modernism21-solves)
     26 - [2] [UIUCTF 2022 Writeup – "precisionism" (ICO content-sniffing leak)](https://blog.huli.tw/2022/08/01/en/uiuctf-2022-writeup/#precisionism3-solves)