daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

some-same-origin-method-execution.md (3612B)


      1 ---
      2 title: "SOME - Same Origin Method Execution"
      3 section: "Web Pentesting"
      4 sectionSlug: "pentesting-web"
      5 sourcePath: "src/pentesting-web/xss-cross-site-scripting/some-same-origin-method-execution.md"
      6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/pentesting-web/xss-cross-site-scripting/some-same-origin-method-execution.md"
      7 sha: "188de82beb54e70956b2952367a0af91d26758b8"
      8 isIndex: false
      9 modified: true
     10 license: "CC-BY-NC-4.0"
     11 ---
     12 
     13 # SOME - Same Origin Method Execution
     14 
     15 ## Same Origin Method Execution
     16 
     17 Sometimes an application provides only constrained JavaScript execution, such as control of a callback identifier that the server inserts into a script response.
     18 
     19 If that execution occurs in a page with a useful DOM, it may invoke sensitive methods or click controls. The vulnerable callback endpoint itself, however, is often a minimal document with no valuable UI.
     20 
     21 SOME bridges that gap: the constrained script runs in a same-origin auxiliary window and uses its `window.opener` reference to reach a more interesting document in the opener.<sup>[[1]](#references)</sup>
     22 
     23 Basically, the attack flow is the following:
     24 
     25 - Find a **callback that you can abuse** (potentially limited to \[\w\\.\_]).
     26   - If it is not limited and arbitrary JavaScript is possible, treat it as ordinary XSS.
     27 - Make the **victim open a page** controlled by the **attacker**
     28 - The **page will open itself** in a **different window** (the new window will have the object **`opener`** referencing the initial one)
     29 - The **initial page** will load the **page** where the **interesting DOM** is located.
     30 - The **second page** will load the **vulnerable page abusing the callback** and using the **`opener`** object to **access and execute some action in the initial page** (which now contains the interesting DOM).
     31 
     32 > [!CAUTION]
     33 > A window reference can survive navigation of the referenced browsing context, although same-origin policy checks are evaluated against the documents' current origins. Modern isolation features such as `Cross-Origin-Opener-Policy` and `rel=noopener` can sever the relationship.
     34 >
     35 > To dereference the opener's DOM, the auxiliary page and the opener's current document must be **same-origin**. The chain therefore needs same-origin script execution, such as the vulnerable callback endpoint itself.
     36 
     37 ### Exploitation
     38 
     39 - Use the SOME Generator to build a PoC for this attack class.<sup>[[3]](#references)</sup>
     40 - Use the targeting tool to derive a clickable element's DOM method path.<sup>[[4]](#references)</sup>
     41 
     42 ### Example
     43 
     44 - The SOME Playground provides a deliberately vulnerable example.<sup>[[5]](#references)</sup>
     45   - In this example the server generates JavaScript from the callback parameter: `<script>opener.{callback_content}</script>`. That is why the callback itself does not need to repeat `opener`.
     46 - Also check this CTF writeup: [https://ctftime.org/writeup/36068](https://ctftime.org/writeup/36068)<sup>[[2]](#references)</sup>
     47 
     48 ## References
     49 
     50 - [1] [HITB 2017 AMS, "Everybody Wants Some – Advance Same Origin Method Execution"](https://conference.hitb.org/hitbsecconf2017ams/sessions/everybody-wants-some-advance-same-origin-method-execution/)
     51 - [2] [SOME - Same Origin Method Execution CTF writeup (CTFtime)](https://ctftime.org/writeup/36068)
     52 - [3] [SOME Playground — PoC Generator](https://www.someattack.com/Playground/SOMEGenerator)
     53 - [4] [SOME Playground — Targeting Tool](https://www.someattack.com/Playground/targeting_tool)
     54 - [5] [SOME Playground — Vulnerable example](https://www.someattack.com/Playground/)