some-same-origin-method-execution.md (3612B)
1 --- 2 title: "SOME - Same Origin Method Execution" 3 section: "Web Pentesting" 4 sectionSlug: "pentesting-web" 5 sourcePath: "src/pentesting-web/xss-cross-site-scripting/some-same-origin-method-execution.md" 6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/pentesting-web/xss-cross-site-scripting/some-same-origin-method-execution.md" 7 sha: "188de82beb54e70956b2952367a0af91d26758b8" 8 isIndex: false 9 modified: true 10 license: "CC-BY-NC-4.0" 11 --- 12 13 # SOME - Same Origin Method Execution 14 15 ## Same Origin Method Execution 16 17 Sometimes an application provides only constrained JavaScript execution, such as control of a callback identifier that the server inserts into a script response. 18 19 If that execution occurs in a page with a useful DOM, it may invoke sensitive methods or click controls. The vulnerable callback endpoint itself, however, is often a minimal document with no valuable UI. 20 21 SOME bridges that gap: the constrained script runs in a same-origin auxiliary window and uses its `window.opener` reference to reach a more interesting document in the opener.<sup>[[1]](#references)</sup> 22 23 Basically, the attack flow is the following: 24 25 - Find a **callback that you can abuse** (potentially limited to \[\w\\.\_]). 26 - If it is not limited and arbitrary JavaScript is possible, treat it as ordinary XSS. 27 - Make the **victim open a page** controlled by the **attacker** 28 - The **page will open itself** in a **different window** (the new window will have the object **`opener`** referencing the initial one) 29 - The **initial page** will load the **page** where the **interesting DOM** is located. 30 - The **second page** will load the **vulnerable page abusing the callback** and using the **`opener`** object to **access and execute some action in the initial page** (which now contains the interesting DOM). 31 32 > [!CAUTION] 33 > A window reference can survive navigation of the referenced browsing context, although same-origin policy checks are evaluated against the documents' current origins. Modern isolation features such as `Cross-Origin-Opener-Policy` and `rel=noopener` can sever the relationship. 34 > 35 > To dereference the opener's DOM, the auxiliary page and the opener's current document must be **same-origin**. The chain therefore needs same-origin script execution, such as the vulnerable callback endpoint itself. 36 37 ### Exploitation 38 39 - Use the SOME Generator to build a PoC for this attack class.<sup>[[3]](#references)</sup> 40 - Use the targeting tool to derive a clickable element's DOM method path.<sup>[[4]](#references)</sup> 41 42 ### Example 43 44 - The SOME Playground provides a deliberately vulnerable example.<sup>[[5]](#references)</sup> 45 - In this example the server generates JavaScript from the callback parameter: `<script>opener.{callback_content}</script>`. That is why the callback itself does not need to repeat `opener`. 46 - Also check this CTF writeup: [https://ctftime.org/writeup/36068](https://ctftime.org/writeup/36068)<sup>[[2]](#references)</sup> 47 48 ## References 49 50 - [1] [HITB 2017 AMS, "Everybody Wants Some – Advance Same Origin Method Execution"](https://conference.hitb.org/hitbsecconf2017ams/sessions/everybody-wants-some-advance-same-origin-method-execution/) 51 - [2] [SOME - Same Origin Method Execution CTF writeup (CTFtime)](https://ctftime.org/writeup/36068) 52 - [3] [SOME Playground — PoC Generator](https://www.someattack.com/Playground/SOMEGenerator) 53 - [4] [SOME Playground — Targeting Tool](https://www.someattack.com/Playground/targeting_tool) 54 - [5] [SOME Playground — Vulnerable example](https://www.someattack.com/Playground/)