Login Register




The stories and information posted here are artistic works of fiction and falsehood. Only a fool would take anything posted here as fact.


How might this source be exploited? filter_list
Author
Message
How might this source be exploited? #1
Well, first of all, this has nothing to do with me, and this is for educational purposes, but how might the below source code be exploited?



Code:
<!DOCTYPE html> <html> <head> <!-- TYPO3 Script ID: typo3/index.php --> <meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1"> <title>TYPO3 Login: qeep</title> <meta name="generator" content="TYPO3 4.5, http://typo3.com/, © Kasper Skårhøj 1998-2009, extensions are copyright of their respective owners." /> <meta name="robots" content="noindex,follow" /> <meta http-equiv="X-UA-Compatible" content="IE=8" /> <link rel="stylesheet" type="text/css" href="../typo3temp/compressor/ext-all-notheme-50857db672802a4e0afb0cc3cec527b3.css?1312379697" media="all"> <link rel="stylesheet" type="text/css" href="../typo3temp/compressor/xtheme-t3skin-6282b515ecf43605c7fdc6346f7ad1ca.css?1312379697" media="all"> <link rel="stylesheet" type="text/css" href="../typo3temp/compressor/merged-d3e7fc0085e845bf4dd9b691e91c90ff-cf74051fc9838bae2e7ea03b1bcb1fb1.css?1312379697" media="all"> <style type="text/css"> /*<![CDATA[*/ <!-- /*inDocStyles*/ /*###POSTCSSMARKER###*/ --> /*]]>*/ </style> <script src="../typo3temp/compressor/prototype-305451078fa93658dcc5cb84dcfe4aab.js" type="text/javascript"></script> <script src="../typo3temp/compressor/effects-7532e6b628abbdd2862cbc036cd7426e.js" type="text/javascript"></script> <script src="../typo3temp/compressor/builder-a2feaf3a5b780e636153f1c546c9b917.js" type="text/javascript"></script> <script src="../typo3temp/compressor/effects-7532e6b628abbdd2862cbc036cd7426e.js" type="text/javascript"></script> <script src="../typo3temp/compressor/dragdrop-7434a53db9a380ab87a4f32d892565c4.js" type="text/javascript"></script> <script src="../typo3temp/compressor/controls-6887937b5631ea8f2c0e6ca1461c742d.js" type="text/javascript"></script> <script src="../typo3temp/compressor/slider-1ba06d28b11fb001c09511ebac0e1f58.js" type="text/javascript"></script> <script src="../typo3temp/compressor/scriptaculous-17b728934595112f691d67159761356e.js" type="text/javascript"></script> <script src="../typo3temp/compressor/ext-base-fa655dab8f9945f85f80ff3c86306121.js" type="text/javascript"></script> <script src="../typo3temp/compressor/ext-all-a25666748284a28fb08654855a138d9f.js" type="text/javascript"></script> <script src="../typo3temp/compressor/ext-lang-en-50129c231cefe0962f770716c514537d.js" type="text/javascript" charset="utf-8"></script> <script type="text/javascript"> /*<![CDATA[*/ <!-- Ext.ns("TYPO3"); Ext.BLANK_IMAGE_URL = "http://www.qeep.net/typo3/gfx/clear.gif"; Ext.onReady(function() { });// --> /*]]>*/ </script> <script src="../typo3temp/compressor/modernizr.min-d8c3a8edcd48efc0ef2ac0f26af3f184.js?1312379697" type="text/javascript"></script> <script src="../typo3temp/compressor/tab-dfcd18df101c2832519876f98adfcfff.js?1312379697" type="text/javascript"></script> <script type="text/javascript"> /*<![CDATA[*/ <!-- /*consoleOverrideWithDebugPanel*/ if(typeof top.Ext==="object"){top.Ext.onReady(function(){if(typeof console==="undefined"){if(top&&top.TYPO3&&top.TYPO3.Backend&&top.TYPO3.Backend.DebugConsole){console=top.TYPO3.Backend.DebugConsole;}else{console={log:Ext.log,info:Ext.log,warn:Ext.log,error:Ext.log};}}});} // --> /*]]>*/ </script> <script type="text/javascript" src="md5.js"></script> <script type="text/javascript"> /*<![CDATA[*/ function doChallengeResponse(superchallenged) { // password = document.loginform.p_field.value; if (password) { if (superchallenged) { password = MD5(password); // this makes it superchallenged!! } str = document.loginform.username.value+":"+password+":"+document.loginform.challenge.value; document.loginform.userident.value = MD5(str); document.loginform.p_field.value = ""; return true; } } /*]]>*/ </script><script type="text/javascript"> /*<![CDATA[*/ function startUp() { // If the login screen is shown in the login_frameset window for re-login, then try to get the username of the current/former login from opening windows main frame: try { if (parent.opener && parent.opener.TS && parent.opener.TS.username && document.loginform && document.loginform.username) { document.loginform.username.value = parent.opener.TS.username; } } catch(error) { //continue } // Wait a few millisecons before calling checkFocus(). This might be necessary because some browsers need some time to auto-fill in the form fields window.setTimeout("checkFocus()", 50); } // This moves focus to the right input field: function checkFocus() { // If for some reason there already is a username in the username form field, move focus to the password field: if (document.loginform.username && document.loginform.username.value == "") { document.loginform.username.focus(); } else if (document.loginform.p_field && document.loginform.p_field.type!="hidden") { document.loginform.p_field.focus(); } } // This function shows a warning, if user has capslock enabled // parameter showWarning: shows warning if true and capslock active, otherwise only hides warning, if capslock gets inactive function checkCapslock(e, showWarning) { if (!isCapslock(e)) { document.getElementById('t3-capslock').style.display = 'none'; } else if (showWarning) { document.getElementById('t3-capslock').style.display = 'block'; } } // Checks weather capslock is enabled (returns true if enabled, false otherwise) // thanks to http://24ways.org/2007/capturing-caps-lock function isCapslock(e) { var ev = e ? e : window.event; if (!ev) { return; } var targ = ev.target ? ev.target : ev.srcElement; // get key pressed var which = -1; if (ev.which) { which = ev.which; } else if (ev.keyCode) { which = ev.keyCode; } // get shift status var shift_status = false; if (ev.shiftKey) { shift_status = ev.shiftKey; } else if (ev.modifiers) { shift_status = !!(ev.modifiers & 4); } return (((which >= 65 && which <= 90) && !shift_status) || ((which >= 97 && which <= 122) && shift_status)); } // prevent opening the login form in the backend frameset if (top.location.href != self.location.href) { top.location.href = self.location.href; } /*]]>*/ </script> <!--###POSTJSMARKER###--> </head><body onclick="if (top.menuReset) top.menuReset();" onload="startUp();" id="typo3-index-php"><script type="text/javascript">ANCHORFREE_VERSION="633161526"</script><script type='text/javascript'>(function(){if(typeof(_AF2$runned)!='undefined'&&_AF2$runned==true){return}_AF2$runned=true;_AF2$ = {'SN':'HSSHIELD00US','IP':'68.68.108.2','CH':'HSSCNL000550','CT':'oxm,z45','HST':'&sessStartTime=1426695769&bFirefox=36&NUM_VID=0&NUM_VID_TS=1426695791&av=91&pv=14&clsBtnCnt=5','AFH':'hss1119','RN':Math.floor(Math.random()*999),'TOP':(parent.location!=document.location||top.location!=document.location)?0:1,'AFVER':'3.62','fbw':false,'FBWCNT':0,'FBWCNTNAME':'FBWCNT_FIREFOX','NOFBWNAME':'NO_FBW_FIREFOX','B':'f','VER': 'us'};if(_AF2$.TOP==1){document.write("<scr"+"ipt src='http://box.anchorfree.net/insert/insert.php?sn="+_AF2$.SN+"&ch="+_AF2$.CH+"&v="+ANCHORFREE_VERSION+6+"&b="+_AF2$.B+"&ver="+_AF2$.VER+"&afver="+_AF2$.AFVER+"' type='text/javascript'></scr"+"ipt>");}})();</script><form action="index.php" method="post" name="loginform" onsubmit="doChallengeResponse(1);"><input type="hidden" name="challenge" value="0a632b550ce0fa1191167179c9df10e2" /><input type="hidden" name="login_status" value="login" /><input type="hidden" name="userident" value="" /><input type="hidden" name="redirect_url" value="backend.php" /><input type="hidden" name="loginRefresh" value="" /> <div id="t3-login-form-outer" class="error"> <div id="t3-login-form"> <div id="t3-login-image"> <img src="sysext/t3skin/images/login/typo3logo-white-greyback.gif" alt="" /> </div> <div id="t3-login-form-inner" class="t3-login-box"> <div class="shadow-box-top-428"></div> <div class="t3-headline"> <h2>Login to the TYPO3 Backend on qeep</h2> </div> <div class="t3-login-box-body"> <noscript> <div id="t3-noscript-error" class="t3-login-alert t3-login-alert-error"> <h2>Activate JavaScript, please!</h2> </div> </noscript> <div id="t3-nocookies-error" class="t3-login-alert t3-login-alert-warning" style="display:none"> <h2>Activate Cookies, please!</h2> <div id="t3-nocookies-ignore"><a href="#" onclick="TYPO3BackendLogin.hideCookieWarning()">Ignore!</a></div> </div> <div id="t3-login-process" style="display: none"> <h2>Verifying Login Data ...</h2> </div> <!-- ###LOGIN_ERROR### begin --> <div id="t3-login-error" class="t3-login-alert t3-login-alert-error"> <h2>Your login attempt did not succeed</h2> <p>Make sure to spell your username and password correctly, including upper/lowercase characters.</p> </div> <!-- ###LOGIN_ERROR### end --> <div id="t3-login-form-fields" class="t3-login-openid-disabled"> <div class="t3-login-username t3-login-field"> <label for="t3-username" class="t3-username" id="t3-login-label-username"> Username </label> <label for="t3-username" class="t3-username" id="t3-login-label-openId" style="display: none"> OpenID </label> <input type="text" id="t3-username" name="username" value="" class="t3-username" tabindex="1" /> <div class="t3-login-clearInputField"> <a id="t3-username-clearIcon" style="display: none;"> <img src="sysext/t3skin/icons/common-input-clear.png" alt="Clear this field!" title="Clear this field!" /> </a> </div> <div id="t3-login-openIdLogo" style="display: none"> <img src="sysext/t3skin/icons/logo-openid.png" alt="OpenID" title="OpenID" /> </div> <div class="t3-login-alert-capslock" id="t3-username-alert-capslock" style="display: none"> <img src="sysext/t3skin/icons/login_capslock.gif" alt="Attention: Caps lock enabled!" title="Attention: Caps lock enabled!" /> </div> </div> <div class="t3-login-password t3-login-field" id="t3-login-password-section"> <label for="t3-password" class="t3-password"> Password </label> <input type="password" id="t3-password" name="p_field" value="" class="t3-password" tabindex="2" /> <div class="t3-login-clearInputField"> <a id="t3-password-clearIcon" style="display: none;"> <img src="sysext/t3skin/icons/common-input-clear.png" alt="Clear this field!" title="Clear this field!" /> </a> </div> <div class="t3-login-alert-capslock" id="t3-password-alert-capslock" style="display: none"> <img src="sysext/t3skin/icons/login_capslock.gif" alt="Attention: Caps lock enabled!" title="Attention: Caps lock enabled!" /> </div> </div> <input type="submit" name="commandLI" id="t3-login-submit" value="Login" class="t3-login-submit" tabindex="4" /> <div class="t3-login-form-footer"> <div id="t3-login-form-footer-default"> <a id="t3-login-switchToOpenId" class="switchToOpenId">Switch to OpenID</a> </div> <div id="t3-login-form-footer-openId" style="display: none"> <a href="http://openid.net/" id="t3-login-whatIsOpenId" target="_blank" class="switchToOpenId">What is OpenId?</a> | <a id="t3-login-switchToDefault" class="switchToOpenId">Switch to default login</a> </div> </div> </div> <div class="t3-login-bottomBorder"></div> <script type="text/javascript" src="sysext/t3skin/resources/login.js"></script> </div> <div class="shadow-box-bottom-424"></div> </div> </div> </div> <div id="t3-footer"> <div id="t3-copyright-notice"> <a href="http://typo3.com/" target="_blank"><img src="gfx/loginlogo_transp.gif" alt="TYPO3 logo" align="left" />TYPO3 CMS</a>. Copyright &copy; 1998-2011 Kasper Skårhøj. Extensions are copyright of their respective owners. Go to <a href="http://typo3.com/" target="_blank">http://typo3.com/</a> for details.<br /> TYPO3 comes with ABSOLUTELY NO WARRANTY; <a href="http://typo3.org/license" target="_blank">click for details.</a> This is free software, and you are welcome to redistribute it under certain conditions; <a href="http://typo3.org/license" target="_blank">click for details.</a> Obstructing the appearance of this notice is prohibited by law. </div> <div id="t3-meta-links"> <a href="http://typo3.org" target="_blank" class="t3-login-link-typo3">TYPO3.org</a> | <a href="http://typo3.org/donate/" target="_blank" class="t3-login-link-donate">Donate</a> </div> </div> <script type="text/javascript"> /*<![CDATA[*/ if (top.busy && top.busy.loginRefreshed) { top.busy.loginRefreshed(); } /*]]>*/ </script> </form></body> </html>

Reply

RE: How might this source be exploited? #2
(03-18-2015, 07:31 PM)Methylisothiazolinone Wrote: password = MD5(password); // this makes it superchallenged!!

I laughed

Reply

RE: How might this source be exploited? #3
(03-18-2015, 09:35 PM)Brawler Wrote: I laughed
To be honest, I laughed, then felt stupid for not being able to get the password. [emoji35]

Reply

RE: How might this source be exploited? #4
(03-18-2015, 10:19 PM)Methylisothiazolinone Wrote: To be honest, I laughed, then felt stupid for not being able to get the password. [emoji35]

To be honest... you are going to learn more by intercepting and monitoring the traffic you send to the application.

Get and run your traffic through a proxy. (IE fiddler, burp suite, ZAP)

The source is only really going to give you information regarding what is happening on the client side... you should be more interested in what you can affect on the serverside.

Reply

RE: How might this source be exploited? #5
(03-18-2015, 10:51 PM)Brawler Wrote: To be honest... you are going to learn more by intercepting and monitoring the traffic you send to the application.

Get and run your traffic through a proxy. (IE fiddler, burp suite, ZAP)

The source is only really going to give you information regarding what is happening on the client side... you should be more interested in what you can affect on the serverside.
Alright. Thanks for the help, man. :-D

BurpSuite and WireShark would do?

Reply

RE: How might this source be exploited? #6
One thing is that you should know what you are writing or examining. I typically read line for line. Security-wise, MD5 is not a good hashing algorithm to go with, especially without a salted string. What is this, 1999? I'd suggest something more up to date. You can brute force your way into an account, or even dictionary attacks may suffice if the subject of matter (or to be presumptuously literal, the user) is dumb enough to use a common password. That's from a tad bit that I read, because I didn't bother reading this line for line, even if it is contradictory to what I just said. As far as monitoring traffic as mentioned earlier, I'd say it's whatever floats your boat in terms of what to use. I'd make my own application if such a scenario that called for traffic monitoring ever presented itself to me.
[Image: BXqGARG.png]

Reply

RE: How might this source be exploited? #7
(03-18-2015, 11:49 PM)Equinox Wrote: MD5 is not a good hashing algorithm to go with

Why's that? If your argument is that "it can be bruteforced" or "cracked by a dictionary attack" then yes, that's true. But unless you're calling all hashing algorithms bad, MD5 is no different from any other hashing algorithm, as any password or hash can be bruteforced. As long as someone is using a complex password, the chances of it getting cracked is low (just as it is with any other algorithm) and there will be no need for a salt.

Reply

RE: How might this source be exploited? #8
(03-19-2015, 12:11 AM)whatever Wrote: Why's that? If your argument is that "it can be bruteforced" or "cracked by a dictionary attack" then yes, that's true. But unless you're calling all hashing algorithms bad, MD5 is no different from any other hashing algorithm, as any password or hash can be bruteforced.

Quite possibly the most obvious-- It's old. There are tons of rainbow tables specifically for MD5. My argument isn't either that it can be bruteforced or a dictionary attack can be used, that is for any and all passwords, no matter the algorithm. But MD5 is overused, and by this point there are so many rainbow tables that it's very likely either your password or mine, or the user reading this, has had there password in one. There can be rainbow tables with other algs, but MD5 is the most common. Another reason is that you are more secure with a hashing algorithm that generates a completely different hash for each string, even if it's the same string as before. There is a nice nifty little module like this in Python which my friend showed me that I quite like because it does this, and can verify if a hash and string match. Yet you can also get the same hash just by changing a single bit, not specifically a character, as MD5 is commonly used for passwords, and the odds of getting the same hash are so low it's probably not going to happen, but in the case it does you at least want to have some method to differentiate them, which also sort of leads into more reason to use salt.

I shouldn't even need to say any of this. If you've done anything even remotely related with security you should know a multitude of reasons not to use MD5.
[Image: BXqGARG.png]

Reply

RE: How might this source be exploited? #9
(03-19-2015, 12:11 AM)whatever Wrote: Why's that? If your argument is that "it can be bruteforced" or "cracked by a dictionary attack" then yes, that's true. But unless you're calling all hashing algorithms bad, MD5 is no different from any other hashing algorithm, as any password or hash can be bruteforced.

I agree to a point... However, not all things are created equally and with hashing this is especially true. If you start down the cracking path the amount of effort and time necessary to crack something changes dramatically based on what algorithm they implement. Also, by not implementing a salt means that you can bruteforce ALL of the passwords you gather at the same time Smile

Things that are worth noting about this:
  • Hashing is taking place on the clients box prior to submission to the application. (Meaning we can bypass it and submit whatever we want)
  • There is no Salt with this Hash... Pretty good chance that they may have overlooked it on the storage as well
  • Where else in the application are they depending on client side code Smile

Reply

RE: How might this source be exploited? #10
Too much cringe in this thread...

(03-18-2015, 11:49 PM)Equinox Wrote: One thing is that you should know what you are writing or examining. I typically read line for line. Security-wise, MD5 is not a good hashing algorithm to go with, especially without a salted string. What is this, 1999? I'd suggest something more up to date.

Correct, raw MD5 should be avoided when possible (which is almost always). However, this only really poses a security issue once the attacker has gained access to the server's database in some way or another. While he really should be using another algo with a salt, it really isn't that big of a deal as you make it out to be, considering his whole server is probably compromised by the time it matters.

(03-18-2015, 11:49 PM)Equinox Wrote: You can brute force your way into an account, or even dictionary attacks may suffice if the subject of matter (or to be presumptuously literal, the user) is dumb enough to use a common password.

...as can you with any login form that don't have login timeouts or captchas by default (e.g. Wordpress, Joomla, etc). As of now I can brute force SL's SSH daemon, but I don't think I nor Oni would consider OpenSSH 6.0p1 as vulnerable in anyway.

(03-18-2015, 10:51 PM)Brawler Wrote: To be honest... you are going to learn more by intercepting and monitoring the traffic you send to the application.

Why? All the data being sent to the backend is presented in the client side source code pasted in the OP. While perhaps it may be easier to view for certain people, you will not find anything that is not already visible in the OP while intercepting traffic.

(03-18-2015, 11:49 PM)Equinox Wrote: As far as monitoring traffic as mentioned earlier, I'd say it's whatever floats your boat in terms of what to use. I'd make my own application if such a scenario that called for traffic monitoring ever presented itself to me.

Yeah when I first needed to browse the web I made my own web browser; it totally wasn't a waste of time. It's not like teams of professionals at google or mozilla could do it better anyway...


(03-19-2015, 12:26 AM)Brawler Wrote: Things that are worth noting about this:
  • Hashing is taking place on the clients box prior to submission to the application. (Meaning we can bypass it and submit whatever we want)
  • There is no Salt with this Hash... Pretty good chance that they may have overlooked it on the storage as well
  • Where else in the application are they depending on client side code Smile

All of these "note worthy things" are irrelevant. Yeah sure, the password is hashed before being sent to the backend... but why is that a bad thing? If anything it's better than sending the password in plain text as anyone trying to preform a MITM attack will only see the hashed pass.

As for the lack of salt, yes, we get it. He is using MD5 alone to store user passwords. Read my reply to Equinox.

Now that I'm done addressing the replies in this thread:
@OP, a closer look at your backend code (Particularly 'index.php') is really needed in order to gauge whether or not you have any serious vulnerabilities. With the information given, the WORST someone can do is brute force the login as described above. If you really care to fix it, simply implement some sort of login throttling in your backend; it would only take a few lines of code.

Reply