Sinisterly
Need help with this (XXE and\or SQLi) - Printable Version

+- Sinisterly (https://sinister.li)
+-- Forum: Hacking (https://sinister.li/Forum-Hacking)
+--- Forum: Website & Server Hacking (https://sinister.li/Forum-Website-Server-Hacking)
+--- Thread: Need help with this (XXE and\or SQLi) (/Thread-Need-help-with-this-XXE-and-or-SQLi)

Pages: 1 2


Need help with this (XXE and\or SQLi) - Misha- - 03-02-2015

Basically, me and a friend of mine were messing with a huuuge mobile provider yesterday, and we reached a dead end.
We found several things:
- Most types of XSS (not very useful yet)
- An SQLi which we can't use, because either addslashes or magic_quotes are working
- A potential XXE

Here are some details now.
The potential XXE:
Spoiler:
The site has a cart system (summercart I think), where you can add stuff to your cart or wishlist and then buy it when you want.
The cart itself uses XML in a cookie to store the items.
[Image: 90ba5da831.png]
I tried changing it, but on every request, it updates back to that.


The failed SQLi:
Spoiler:
You can add addresses on the site.
It doesn't filter html, so there are several persistent XSS' on there, but that's not the main thing.
It stores everything in a database. Here's the POST request.
Code:
CountryID=34&StateID='&OriginalCustomerState=&CustomerAddressLine1=асд&CustomerAddressCity=дсадtukaaaa&CityID=&CustomerAddressLine2=&CustomerAddressZip=33&action=dmExecCreate&CustomerAddressIsDefaultCard=

And the error it produces:
Code:
Error appeared. Record creation failed: Cannot add or update a child row: a foreign key constraint fails (`mtel_eshop`.`CustomerAddresses`, CONSTRAINT `FK_CustomerAddresses_StateID` FOREIGN KEY (`StateID`) REFERENCES `States` (`StateID`) ON UPDATE CASCADE) (INSERT INTO CustomerAddresses(CustomerAddressID,CustomerID,CustomerAddressLine1,CustomerAddressLine2,CustomerAddressCity,CityID,CustomerAddressZip,CountryID,StateID,CustomerAddressIsDefaultBilling,CustomerAddressIsDefaultShipping,CustomerAddressIsDefaultContact,CustomerAddressIsDefaultCard) VALUES("","146062","0A4","","4A04tukaaaa",NULL,"33","34","\'",FALSE,FALSE,FALSE,FALSE))


Anyone that wants to help me, please, post here or PM me ^^


RE: Need help with this (XXE and\or SQLi) - whatever - 03-02-2015

SQLi is still possible with either of those enabled, what makes you think it can't be done?

XXE is also pretty worthless unless you're under the rare case that there are plaintext passwords stored somewhere. You can stop being a poser now.


RE: Need help with this (XXE and\or SQLi) - Misha- - 03-02-2015

(03-02-2015, 02:01 PM)whatever Wrote: SQLi is still possible with either of those enabled, what makes you think it can't be done?

XXE is also pretty worthless unless you're under the rare case that there are plaintext passwords stored somewhere. You can stop being a poser now.

Are you fucking high?
For the SQLi, the place where i'm injecting is encapsulated with ", which I can't break out of, because of addslashes()/magic_quotes.
You would've seen that if you even looked at the query.

As for the XXE, again, are you fucking high?
Please google what XXE is and come back.


RE: Need help with this (XXE and\or SQLi) - . . - 03-02-2015

This shit is above me, hope someone can help you though.


RE: Need help with this (XXE and\or SQLi) - whatever - 03-02-2015

(03-02-2015, 02:48 PM)Misha- Wrote: Are you fucking high?
For the SQLi, the place where i'm injecting is encapsulated with ", which I can't break out of, because of addslashes()/magic_quotes.
You would've seen that if you even looked at the query.

As for the XXE, again, are you fucking high?
Please google what XXE is and come back.

Your stupidity is special. I was considering telling you if your response had been different. A google search will give you an answer. You just have to make an invalid character into a valid one, there's your hint.


RE: Need help with this (XXE and\or SQLi) - Dyme - 03-03-2015

(03-02-2015, 10:57 PM)whatever Wrote: Your stupidity is special... You just have to make an invalid character into a valid one, there's your hint.

Oh yeah man that's all you have to do and then you can bypass addslashes() and magic_quotes_gpc on all MySQL servers... who have explicitly changed their charset to big5, sjis, gbk, or cp932! I reckon that has at least a 0.5% chance of working! We can also pretend like it's not 2015 and that mysqli_real_escape_string() is not what's really filtering OP's input.

No, 'whatever', I have a feeling you're the special one here.

@OP: As for the "XXE vulnerability", what is leading you to believe you have one? Have you been able to successfully inject any external entities?


RE: Need help with this (XXE and\or SQLi) - whatever - 03-03-2015

(03-03-2015, 03:25 AM)Dyme Wrote: Oh yeah man that's all you have to do and then you can bypass addslashes() and magic_quotes_gpc on all MySQL servers... who have explicitly changed their charset to big5, sjis, gbk, or cp932! I reckon that has at least a 0.5% chance of working! We can also pretend like it's not 2015 and that mysqli_real_escape_string() is not what's really filtering OP's input.

No, 'whatever', I have a feeling you're the special one here.

@OP: As for the "XXE vulnerability", what is leading you to believe you have one? Have you been able to successfully inject any external entities?

If it's encased in " and filtered with addslashes() you would be able to break out via %bf%22, no?

I'd assume it's not using magic_quotes_gpc because that function just breaks shit and was turned off in all PHP 3.x.x versions and is depracated as of 5.3

My response was also based on the OP where mysql_real_escape_string was never mentioned, so I didn't think about it.

EDIT: Sorry, it just hit me that not all charsets support the same shit. Derp.


RE: Need help with this (XXE and\or SQLi) - BreShiE - 03-03-2015

(03-03-2015, 03:48 AM)whatever Wrote: If it's encased in " and filtered with addslashes() you would be able to break out via %bf%22, no?

I'd assume it's not using magic_quotes_gpc because that function just breaks shit and was turned off in all PHP 3.x.x versions and is depracated as of 5.3

My response was also based on the OP where mysql_real_escape_string was never mentioned, so I didn't think about it.

EDIT: Sorry, it just hit me that not all charsets support the same shit. Derp.

Maximum over kek ^


RE: Need help with this (XXE and\or SQLi) - roger_smith - 03-03-2015

(03-03-2015, 03:48 AM)whatever Wrote: If it's encased in " and filtered with addslashes() you would be able to break out via %bf%22, no?

I'd assume it's not using magic_quotes_gpc because that function just breaks shit and was turned off in all PHP 3.x.x versions and is depracated as of 5.3

My response was also based on the OP where mysql_real_escape_string was never mentioned, so I didn't think about it.

EDIT: Sorry, it just hit me that not all charsets support the same shit. Derp.

It sounds like you learned an important lesson in humility today. Congrats


RE: Need help with this (XXE and\or SQLi) - whatever - 03-03-2015

(03-03-2015, 04:37 AM)roger_smith Wrote: It sounds like you learned an important lesson in humility today. Congrats

Sigh, kill me now.