daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

index.md (6133B)


      1 ---
      2 title: "Client Side Path Traversal"
      3 topic: "Client Side Path Traversal"
      4 topicSlug: "client-side-path-traversal"
      5 sourcePath: "Client Side Path Traversal/README.md"
      6 sourceUrl: "https://github.com/swisskyrepo/PayloadsAllTheThings/blob/3ac27901c711/Client%20Side%20Path%20Traversal/README.md"
      7 sha: "3ac27901c711"
      8 isReadme: true
      9 ---
     10 
     11 # Client Side Path Traversal
     12 
     13 > Client-Side Path Traversal (CSPT), sometimes also referred to as "On-site Request Forgery," is a vulnerability that can be exploited as a tool for CSRF or XSS attacks.  
     14 > It takes advantage of the client side's ability to make requests using fetch to a URL, where multiple "../" characters can be injected. After normalization, these characters redirect the request to a different URL, potentially leading to security breaches.  
     15 > Since every request is initiated from within the frontend of the application, the browser automatically includes cookies and other authentication mechanisms, making them available for exploitation in these attacks.
     16 
     17 ## Summary
     18 
     19 * [Tools](#tools)
     20 * [Methodology](#methodology)
     21     * [CSPT to XSS](#cspt-to-xss)
     22     * [CSPT to CSRF](#cspt-to-xss)
     23 * [Labs](#labs)
     24 * [References](#references)
     25 
     26 ## Tools
     27 
     28 * [doyensec/CSPTBurpExtension](https://github.com/doyensec/CSPTBurpExtension) - CSPT is an open-source Burp Suite extension to find and exploit Client-Side Path Traversal.
     29 
     30 ## Methodology
     31 
     32 ### CSPT to XSS
     33 
     34 ![cspt-query-param](https://matanber.com/images/blog/cspt-query-param.png)
     35 
     36 A post-serving page calls the fetch function, sending a request to a URL with attacker-controlled input which is not properly encoded in its path, allowing the attacker to inject `../` sequences to the path and make the request get sent to an arbitrary endpoint. This behavior is referred to as a CSPT vulnerability.
     37 
     38 **Example**:
     39 
     40 * The page `https://example.com/static/cms/news.html` takes a `newsitemid` as parameter
     41 * Then fetch the content of `https://example.com/newitems/<newsitemid>`
     42 * A text injection was also discovered in `https://example.com/pricing/default.js` via the `cb` parameter
     43 * Final payload is `https://example.com/static/cms/news.html?newsitemid=../pricing/default.js?cb=alert(document.domain)//`
     44 
     45 ### CSPT to CSRF
     46 
     47 A CSPT is redirecting legitimate HTTP requests, allowing the front end to add necessary tokens for API calls, such as authentication or CSRF tokens. This capability can potentially be exploited to circumvent existing CSRF protection measures.
     48 
     49 |                                             | CSRF               | CSPT2CSRF          |
     50 | ------------------------------------------- | -----------------  | ------------------ |
     51 | POST CSRF ?                                 | :white_check_mark: | :white_check_mark: |
     52 | Can control the body ?                      | :white_check_mark: | :x:                |
     53 | Can work with anti-CSRF token ?             | :x:                | :white_check_mark: |
     54 | Can work with Samesite=Lax ?                | :x:                | :white_check_mark: |
     55 | GET / PATCH / PUT / DELETE CSRF ?           | :x:                | :white_check_mark: |
     56 | 1-click CSRF ?                              | :x:                | :white_check_mark: |
     57 | Does impact depend on source and on sinks ? | :x:                | :white_check_mark: |
     58 
     59 Real-World Scenarios:
     60 
     61 * 1-click CSPT2CSRF in Rocket.Chat
     62 * CVE-2023-45316: CSPT2CSRF with a POST sink in Mattermost : `/<team>/channels/channelname?telem_action=under_control&forceRHSOpen&telem_run_id=../../../../../../api/v4/caches/invalidate`
     63 * CVE-2023-6458: CSPT2CSRF with a GET sink in Mattermost
     64 * [Client Side Path Manipulation - erasec.be](https://www.erasec.be/blog/client-side-path-manipulation/): CSPT2CSRF `https://example.com/signup/invite?email=foo%40bar.com&inviteCode=123456789/../../../cards/123e4567-e89b-42d3-a456-556642440000/cancel?a=`
     65 * [CVE-2023-5123 : CSPT2CSRF in Grafana’s JSON API Plugin](https://medium.com/@maxime.escourbiac/grafana-cve-2023-5123-write-up-74e1be7ef652)
     66 
     67 ## Labs
     68 
     69 * [doyensec/CSPTPlayground](https://github.com/doyensec/CSPTPlayground) - CSPTPlayground is an open-source playground to find and exploit Client-Side Path Traversal (CSPT).
     70 * [Root Me - CSPT - The Ruler](https://www.root-me.org/en/Challenges/Web-Client/CSPT-The-Ruler)
     71 
     72 ## References
     73 
     74 * [Exploiting Client-Side Path Traversal to Perform Cross-Site Request Forgery - Introducing CSPT2CSRF - Maxence Schmitt - July 2, 2024](https://web.archive.org/web/20260222183040/https://blog.doyensec.com/2024/07/02/cspt2csrf.html)
     75 * [Exploiting Client-Side Path Traversal - CSRF is dead, long live CSRF - Whitepaper - Maxence Schmitt - July 2, 2024](https://web.archive.org/web/20240702212818/https://www.doyensec.com/resources/Doyensec_CSPT2CSRF_Whitepaper.pdf)
     76 * [Exploiting Client-Side Path Traversal - CSRF is Dead, Long Live CSRF - OWASP Global AppSec 2024 - Maxence Schmitt - June 24, 2024](https://web.archive.org/web/20250521192653/https://www.doyensec.com/resources/Doyensec_CSPT2CSRF_OWASP_Appsec_Lisbon.pdf)
     77 * [Leaking Jupyter instance auth token chaining CVE-2023-39968, CVE-2024-22421 and a chromium bug - Davwwwx - August 30, 2023](https://web.archive.org/web/20240703155707/https://blog.xss.am/2023/08/cve-2023-39968-jupyter-token-leak/)
     78 * [On-site request forgery - Dafydd Stuttard - May 3, 2007](https://web.archive.org/web/20260212042947/https://portswigger.net/blog/on-site-request-forgery)
     79 * [Bypassing WAFs to Exploit CSPT Using Encoding Levels - Matan Berson - May 10, 2024](https://web.archive.org/web/20240512110749/https://matanber.com/blog/cspt-levels)
     80 * [Automating Client-Side Path Traversals Discovery - Vitor Falcao - October 3, 2024](https://web.archive.org/web/20241004042613/https://vitorfalcao.com/posts/automating-cspt-discovery/)
     81 * [CSPT the Eval Villain Way! - Dennis Goodlett - December 3, 2024](https://web.archive.org/web/20241203171704/https://blog.doyensec.com/2024/12/03/cspt-with-eval-villain.html)
     82 * [Bypassing File Upload Restrictions To Exploit Client-Side Path Traversal - Maxence Schmitt - January 9, 2025](https://web.archive.org/web/20250109093347/https://blog.doyensec.com/2025/01/09/cspt-file-upload.html)