daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

index.md (4960B)


      1 ---
      2 title: "HTTP Parameter Pollution"
      3 topic: "HTTP Parameter Pollution"
      4 topicSlug: "http-parameter-pollution"
      5 sourcePath: "HTTP Parameter Pollution/README.md"
      6 sourceUrl: "https://github.com/swisskyrepo/PayloadsAllTheThings/blob/3ac27901c711/HTTP%20Parameter%20Pollution/README.md"
      7 sha: "3ac27901c711"
      8 isReadme: true
      9 ---
     10 
     11 # HTTP Parameter Pollution
     12 
     13 > HTTP Parameter Pollution (HPP) is a Web attack evasion technique that allows an attacker to craft a HTTP request in order to manipulate web logics or retrieve hidden information. This evasion technique is based on splitting an attack vector between multiple instances of a parameter with the same name (?param1=value&param1=value). As there is no formal way of parsing HTTP parameters, individual web technologies have their own unique way of parsing and reading URL parameters with the same name. Some taking the first occurrence, some taking the last occurrence, and some reading it as an array. This behavior is abused by the attacker in order to bypass pattern-based security mechanisms.
     14 
     15 ## Summary
     16 
     17 * [Tools](#tools)
     18 * [Methodology](#methodology)
     19     * [Parameter Pollution Table](#parameter-pollution-table)
     20     * [Parameter Pollution Payloads](#parameter-pollution-payloads)
     21 * [References](#references)
     22 
     23 ## Tools
     24 
     25 * **Burp Suite**: Manually modify requests to test duplicate parameters.
     26 * **OWASP ZAP**: Intercept and manipulate HTTP parameters.
     27 
     28 ## Methodology
     29 
     30 HTTP Parameter Pollution (HPP) is a web security vulnerability where an attacker injects multiple instances of the same HTTP parameter into a request. The server's behavior when processing duplicate parameters can vary, potentially leading to unexpected or exploitable behavior.
     31 
     32 HPP can target two levels:
     33 
     34 * Client-Side HPP: Exploits JavaScript code running on the client (browser).
     35 * Server-Side HPP: Exploits how the server processes multiple parameters with the same name.
     36 
     37 **Examples**:
     38 
     39 ```ps1
     40 /app?debug=false&debug=true
     41 /transfer?amount=1&amount=5000
     42 ```
     43 
     44 ### Parameter Pollution Table
     45 
     46 When ?par1=a&par1=b
     47 
     48 | Technology                                      | Parsing Result           | outcome (par1=) |
     49 | ----------------------------------------------- | ------------------------ | --------------- |
     50 | ASP.NET/IIS                                     | All occurrences          | a,b             |
     51 | ASP/IIS                                         | All occurrences          | a,b             |
     52 | Golang net/http - `r.URL.Query().Get("param")`  | First occurrence         | a               |
     53 | Golang net/http - `r.URL.Query()["param"]`      | All occurrences in array | ['a','b']       |
     54 | IBM HTTP Server                                 | First occurrence         | a               |
     55 | IBM Lotus Domino                                | First occurrence         | a               |
     56 | JSP,Servlet/Tomcat                              | First occurrence         | a               |
     57 | mod_wsgi (Python)/Apache                        | First occurrence         | a               |
     58 | Nodejs                                          | All occurrences          | a,b             |
     59 | Perl CGI/Apache                                 | First occurrence         | a               |
     60 | Perl CGI/Apache                                 | First occurrence         | a               |
     61 | PHP/Apache                                      | Last occurrence          | b               |
     62 | PHP/Zues                                        | Last occurrence          | b               |
     63 | Python Django                                   | Last occurrence          | b               |
     64 | Python Flask                                    | First occurrence         | a               |
     65 | Python/Zope                                     | All occurrences in array | ['a','b']       |
     66 | Ruby on Rails                                   | Last occurrence          | b               |
     67 
     68 ### Parameter Pollution Payloads
     69 
     70 * Duplicate Parameters:
     71 
     72     ```ps1
     73     param=value1&param=value2
     74     ```
     75 
     76 * Array Injection:
     77 
     78     ```ps1
     79     param[]=value1
     80     param[]=value1&param[]=value2
     81     param[]=value1&param=value2
     82     param=value1&param[]=value2
     83     ```
     84 
     85 * Encoded Injection:
     86 
     87     ```ps1
     88     param=value1%26other=value2
     89     ```
     90 
     91 * Nested Injection:
     92 
     93     ```ps1
     94     param[key1]=value1&param[key2]=value2
     95     ```
     96 
     97 * JSON Injection:
     98 
     99     ```ps1
    100     {
    101         "test": "user",
    102         "test": "admin"
    103     }
    104     ```
    105 
    106 ## References
    107 
    108 * [How to Detect HTTP Parameter Pollution Attacks - Acunetix - January 9, 2024](https://web.archive.org/web/20260112091623/https://www.acunetix.com/blog/whitepaper-http-parameter-pollution/)
    109 * [HTTP Parameter Pollution - Itamar Verta - December 20, 2023](https://web.archive.org/web/20190721110154/https://www.imperva.com/learn/application-security/http-parameter-pollution/)
    110 * [HTTP Parameter Pollution in 11 minutes - PwnFunction - January 28, 2019](https://web.archive.org/web/20190212095035/https://www.youtube.com/watch?v=QVZBl8yxVX0)