![]() |
|
Tutorial [Concept] cURL_exec not sanitized when used as a user-input - Printable Version +- Sinisterly (https://sinister.li) +-- Forum: Hacking (https://sinister.li/Forum-Hacking) +--- Forum: Website & Server Hacking (https://sinister.li/Forum-Website-Server-Hacking) +--- Thread: Tutorial [Concept] cURL_exec not sanitized when used as a user-input (/Thread-Tutorial-Concept-cURL-exec-not-sanitized-when-used-as-a-user-input) |
[Concept] cURL_exec not sanitized when used as a user-input - Z0le - 05-13-2014 This tutorial is just to understand the concept when cURL_exec() is based on /controlled by user input . What is cURL ? cURL is a shortcut of "Client for URLs" , URL is spelled in uppercase just to make it so obvious that cURL deals with URLs . cURL devides into two : 1- libcurl - a Client side transfer library supporting (HTTPS Certificates ,DICT, FILE, FTP, FTPS, GOPHER, HTTP, HTTPS, IMAP, IMAPS, LDAP, LDAPS, POP3, POP3S, RTMP, RTSP, SCP, SFTP, SMTP, SMTPS, TELNET and TFTP. . . . etc) 2- cURL - Which is a command lining tool for getting and sending (Files ,POST Data fields . . . etc) using URL synatx . What is cURL_exec() ? cURL_exec is a PHP function that it's usage is to execute a setted up cURL session( cURL initialization[curl_init();] , Option setting[CURL_SETOPT();] . . .) in a php script. It actually does it's job when it's called so there's no actuall big deal with cURL_exec() . What makes it a bit dangerous to make cURL_exec based on user input without user input sanitizing? Let's assume that there's a script that uses cURL_exec() based on a user input session without sanitizing By other meaning the URL that is going to be used by cURL when initializing is based on some user input without sanitizing the input , This can lead to some various vulnerabilities in your PHP script (Which is something that you don't really want to get infected with). What various attacks could a user use against a URL used in curl based on user input ? Example : PHP Code: <form method="post" action="">
<font color="red">URL : </font> <input type="text" name="url">
<button style="background-color:red;" name="Enter" type="submit" value="HTML">Log in!</button></center>
<?php
$link = $_POST['url'];
if (isset($link)){
$ch = curl_init($link); /// cURL initialization with a user input URL
curl_setopt($ch, CURLOPT_RETURNTRANSFER, true); // writes the response to a variable
$result = curl_exec($ch); // Executes the cURL session
echo $result;
}
?>This form of script can be exploited if the attacker/user Uses the file:// protocol to read arbitary files from the server ex : file:///FILE-TO-READ , Which leads to local file disclosures. In an older versions of libcurl such as 5.11(!) , libcurl was compiled to support SCP , So that it can be tricked to get a file using semicolons , Which can lead to a Remote command execution . Code: EX : "scp://username:password@something/a'``;dir >/tmp/test``;'"#bye RE: [Concept] cURL_exec not sanitized when used as a user-input - Crypt - 05-14-2014 www.hackforums.net/showthread.php?tid=4060569 Just quit trying, you're bad and always will be. Take your LQ copy and pasted tuts elsewhere. RE: [Concept] cURL_exec not sanitized when used as a user-input - Adorapuff - 05-14-2014 (05-14-2014, 12:00 AM)Crypt Wrote: www.hackforums.net/showthread.php?tid=4060569 Give OP benefit of the doubt. Maybe he is. RE: [Concept] cURL_exec not sanitized when used as a user-input - Z0le - 05-14-2014 (05-14-2014, 12:00 AM)Crypt Wrote: www.hackforums.net/showthread.php?tid=4060569 Lmfao BeggFoMercy , Is another name of my nicknames , You just adjusted a huge failure . RE: [Concept] cURL_exec not sanitized when used as a user-input - Crypt - 05-14-2014 (05-14-2014, 12:13 AM)Z0le Wrote: Lmfao BeggFoMercy , Is another name of my nicknames , You just adjusted a huge failure . Quit capitalizing all of the letters after a comma you illiterate little boy. This time, I didn't say it wasn't you. I told you to take your LQ copy and pasted tuts elsewhere. You obviously did copy and paste this, unless you actually took the time to re-write it. RE: [Concept] cURL_exec not sanitized when used as a user-input - Z0le - 05-14-2014 Wait , re-writing a tutorial means that the writer knows every thing that is in the tutorial , That's a very good piece of evidence on your stupidity , Copy & pasted this ? Why not just send a URL of the source that I copy pasted my tutorial from . |