top ten
Web Hacking
techniques   2010
                         Jeremiah Grossman
             Founder & Chief Technology Officer


                              © 2011 WhiteHat Security, Inc.
Jeremiah Grossman
• WhiteHat Security Founder & CTO
• Technology R&D and industry evangelist
• InfoWorld's CTO Top 25 for 2007
• Co-founder of the Web Application Security Consortium
• Co-author: Cross-Site Scripting Attacks
• Former Yahoo! information security officer

                                                   © 2010 WhiteHat Security, Inc. | Page   2
Top Ten Web Hacking Techniques (2010)
400+ enterprise customers
 •Start-ups to Fortune 500
Flagship offering “WhiteHat Sentinel Service”
 •1000’s of assessments performed annually
Recognized leader in website security
 •Quoted thousands of times by the mainstream press


About the Top Ten
“Every year the Web security community produces a stunning
amount of new hacking techniques published in various white
papers, blog posts, magazine articles, mailing list emails, etc. Within
the thousands of pages are the latest ways to attack websites, Web
browsers, Web proxies, and so on. Beyond individual vulnerability
instances with CVE numbers or system compromises, we're talking
about brand new and creative methods of Web-based attack.”

New Techniques
                     2009 (80)
       Creating a rogue CA certificate

                      2008 (70)
                GIFAR (GIF + JAR)

                       2007 (83)
 XSS Vulnerabilities in Common Shockwave Flash Files

                       2006 (65)
       Web Browser Intranet Hacking / Port Scanning

      69 new techniques
1) 'Padding Oracle' Crypto Attack
2) Evercookie
3) Hacking Auto-Complete
4) Attacking HTTPS with Cache Injection
5) Bypassing CSRF protections with ClickJacking and HTTP Parameter Pollution
6) Universal XSS in IE8
8) JavaSnoop
9) CSS History Hack In Firefox Without JavaScript for Intranet Portscanning
10) Java Applet DNS Rebinding

Bypassing CSRF with Clickjacking
and HTTP Parameter Pollution

Clickjacking is when an attacker invisibly hovers an object
(button, link, etc.) below a user's mouse. When the user
clicks on something they visually see, they're instead
really clicking on something the attacker wanted them to.
HTTP Parameter Pollution is where an attacker submits
multiple input parameters (query string, post data,
cookies, etc.) with the same name. Upon receipt
applications may react in unexpected ways and open up
avenues of server-side and client-side exploitation. By
cleverly leveraging these two former Top Ten attacks,
CSRF attacks can be carried out against a user even
when recommended token defenses are in use.
       Lavakumar Kuppan (@lavakumark)


Clickjacking (Top Ten 2009)
Think of any button – image, link, form, etc. – on any website – that can appear
between the Web browser walls. This includes wire transfer on banks, DSL router
buttons, Digg buttons, CPC advertising banners, Netflix queue.

Next consider that an attacker can invisibly hover these buttons below the user's
mouse, so that when a user clicks on something they visually see, they're actually
clicking on something the attacker wants them to.

What could the bad guy do with that ability?

Hover Invisible IFRAMEs
                                       HTML, CSS, and JavaScript
                                       may size, follow the mouse
                                       and make transparent third-
                                       party IFRAME content.

 style="opacity:.1;filter: alpha(opacity=.1); -moz-opacity 1.0;">!

HTTP Parameter Pollution (HPP) - Top Ten 2009
If an attacker submit multiple input parameters (query string, post data, cookies,
etc.) of the same name, the application may react in unexpected ways and open
up new avenues of server-side and client-side exploitation.
           GET /foo?par1=val1&par1=val2 HTTP/1.1
           User-Agent: Mozilla/5.0
           Host: Host
           Accept: */*

           POST /foo HTTP/1.1
           User-Agent: Mozilla/5.0
           Host: Host
           Accept: */*


           POST /index.aspx?par1=val1&par1=val2 HTTP/1.1
           User-Agent: Mozilla/5.0
           Host: Host
           Cookie: par1=val3; par1=val4
           Content-Length: 19

Bizarre behavior


Example Scenario
<form method="POST">
<input type="text" name="email" value=””></input>
<input type="hidden" name=”csrf-token” value="a0a0a0a0a0a"/>

if (req.parameter("email").isSet() && req.parameter("csrf-token").isValid()) {
   // process the form and update the email ID
} else {
   // display an empty form to the user (CSRF token included)

Bringing it all together
 <iframe src=”http://example/updateEmail.jsp?”>

 HTTP request via user submitted form via Clickjacking. The form was not filled out by
 the victim, meaning the email parameter in the POST body is blank. Now the
 QueryString contains the attacker entered value for the ‘email’ parameter.

 POST /updateEmail.jsp?

 When the server side JSP code calls req.parameter("email"), the value that is returned
 is the one in the QueryString (HPP first occurrence) and not the POST body. Since
 this value can be controlled by the attacker, he can trick the victim in to updating his
 account with the attacker’s mail ID.

Attacking HTTPS with Cache Injection

No matter what type of encryption is used to defend a
network, sooner or later the password, key, or certificate
needs to be stored. If an attacker is able to tamper with
the storage mechanism, even the strongest encryption
mechanism can fail. The researchers demonstrated how
to attack storage mechanisms by tampering with SSL
session and break into Wifi networks using WPA. They
also showed how to exploit SSL warning inconsistencies
and caching mechanisms to trick the user into accepting a
bad certs and steal their username & password.

Elie Bursztein (@ELIE), Baptiste Gourdin
(@bapt1ste), Dan Boneh

RFC1918 Caching Security - (Top Ten 2009)
Public Wifi


 coffee shops, airplanes,
 corp guest networks      Bad Guy

     • Victim(s) located on a RFC 1918 network with a Bad Guy
     • Bad Guy may take the opportunity to read victim’s Web mail, steal creds, etc.
     • Bad Guy man-in-the-middles HTTP (Airpwn) to inject IFRAMEs to RFC-1918 IPs
     • MitM IFRAMEs to include JavaScript malware (BeEF). Or ...
     • Inject JavaScript malware into popular Web widget URLs. (Ad servers, counters, etc.)
     • Cache content in the browser for a really long time, beyond current session!

• 43% of the Alexa top 100,000 use external javascript libraries
• Injecting a malicious javascript library into the browser cache
 allows the attacker to compromise a website protected by SSL

• The malicious library stays in the cache until the user clears it.
 Moving to a “safe” location doesn’t help

• One poisoned injection leads to multiple breaches
• Multiples websites share the same external library such as
 Google Analytics

• Injecting a malicious version of one of these shared libraries
 allows the attacker to target all the websites that use it

Browser Defense -- sort of
• The only defense against cache injection is the SSL warning
 displayed by the browser when a bad certificate is supplied

• Corner cases that allows an attacker to alter the way SSL
 certificate warning are displayed

• These alterations make caching attack efficient as the user is
 more likely to click through the tampered warning

Video Demo
• The following demos show how caching injection attacks
 works against Internet Explorer 8 and Firefox 3.6

• These demos were done in real time against real sites with
 their real certificates


Hacking Auto-Complete

This research encompasses a set of techniques where a
malicious website may surreptitiously obtain their visitors
names, job title, workplace, physical address, telephone
number, email addresses, usernames, passwords, search
terms, social security numbers, credit card numbers, and
on and on by simulating JavaScript keystroke events in
Web browsers HTML form auto-complete / autofill

Jeremiah Grossman (@jeremiahg)

I want to know your name, who
you work for, where you live, your
email address, etc.
Right at the moment you a visit a website. Even if you’ve never
been there before, let alone entered information.

Safari Address Book Autofill (enabled by default)

           <input type="text"   name="name">
           <input type="text"   name="company">
           <input type="text"   name="city">
           <input type="text"   name="state">
           <input type="text"   name="country">
           <input type="text"   name="email">

Address Card Autofill works even when
you’ve NEVER entered personal data on


ethical hackingrobert gordon university
var event = document.createEvent('TextEvent');
event.initTextEvent('textInput', 1, 1, null, char);

input.value = "";               Step 1) Dynamically create
input.selectionStart = 0;       input fields with the pre-set
input.selectionEnd = 0;         attribute names.
input.dispatchEvent(event);!    Step 2) Cycle through the
!                               alphabet initiating text events
setTimeout(function() {         until a form value populates.
  if (input.value.length > 1) {
   // capture the value;        Step 3) Profit! -- Steal data
  }                             with JavaScript.
}, 500);                        *transparency is even more fun!*

                                                v4 / v5
Internet Explorer 8 = SAFE
AutoComplete: User-supplied form values are shared across
different websites by attribute “name”. For example, email
addresses entered into a field on website A populates the autofill for
the same field name on website B, C, D, etc.
                                 <input type="text" name="email">

DEMO - Down, Down, Enter
// hit down arrow an incrementing number of times.
// separate with time to allow the GUI to keep pace
for (var i = 1; i <= downs; i++) {
   time += 30; // time padding
   keyStroke(this, 40, time); // down button
!       !
time += 15; // time padding
keyStroke(this, 13, time); // enter button

// initiate keystroke on a given object
function keyStroke(obj, code, t) {
  //create new event and fire
  var e = document.createEventObject();
  e.keyCode = code;
  setTimeout(function() {obj.fireEvent("onkeydown", e); }, t);
} // end keyStroke

                        Security Basis, and an Internet Explorer data stealer
                        Andrea Giammarchi, Ajaxian Staff


Search terms
Credit card numbers and CCVs
Contact information
Answers to secret questions
Email addresses

AutoComplete is NOT enabled by default, but Internet
Explorer asks if the user if they would like to enable
the feature after filling out a non-password form.

Have the email address, but need the password

Saving Passwords
 Many Web Browsers have “password managers,” which provide
 a convenient way to save passwords on a “per website” basis.
 <form method="post" action="/">
 E-Mail: <input type="text" name="email"><br />
 Password: <input type="password" name="pass"><br />
 <input type="submit" value="Login">


If a website with a saved password is vulnerable to XSS, the
payload can dynamically create login forms, which executes the
browser’s password auto-complete feature. Since the payload is
on the same domain the username / password can be stolen.
function stealCreds() {
 var string = "E-Mail: " + document.getElementById("u").value;
 string += "nPassword: " + document.getElementById("p").value;
 return string;
document.write('<form method="post" action="/">E-Mail: <input
id="u" type="text" name="email" value=""><br>Password: <input
id="p" type="password" name="password" value=""></form>');

setTimeout('alert(stealCreds())', 2000);

               * *                 DEMO
What to do...
Disable Auto-Complete in the Web browser

Remove persistent data
(History, Form Data, Cookies, LocalStorage, etc.)

NoScript (Firefox Extension), 1Password, etc.

<form autocomplete="off">
<input type="text" autocomplete="off" />


Evercookie is a javascript API available that produces
extremely persistent cookies in a browser. Its goal is to
identify a client even after they've removed standard
cookies, Flash cookies (Local Shared Objects or LSOs),
and others. Evercookie accomplishes this by storing the
cookie data in several types of storage mechanisms that
are available on the local browser. Additionally, if evercookie
has found the user has removed any of the types of cookies
in question, it recreates them using each mechanism

Samy Kamkar (@samykamkar)


1) Standard HTTP Cookies               6) Internet Explorer userData storage

2) Flash Cookies (LSOs)                7) Storing cookies in Web cache

3) Silverlight Isolated Storage        8) Storing cookies in HTTP ETags

4) Storing cookies in RGB values of auto- 9) HTML5 Session Storage
 generated, force-cached PNGs using
 HTML5 Canvas tag to read pixels          10) HTML5 Local Storage
 (cookies) back out
                                          11) HTML5 Global Storage
5) Storing cookies in Web History
                                          12) HTML5 Database Storage via SQLite
6) caching

• Persistent cookies via Javascript API
• Recreates after deletion
• Combines different storage mechanisms
• Easy to use!

var ec = new evercookie();

ec.set(“uniqueid”, “31337”); // set uniqueid = 31337

// get our evercookie data back
ec.get(“uniqueid”, function(val) { alert (“ID is “ + val) } );

PNGs Cache
Cookie stored in RGB values of auto-generated, force-cached PNGs
using HTML5 Canvas Tag to read pixels back out

Pixel 0x0 = 0x4f5741 OWA
Pixel 0x1 = 0x535000 SP0

Killing Evercookies (Video)
    1) Open a new tab, then close all other windows and tabs.
    2) Delete Silverlight Isolated Storage
    • Go to
    • Right click the Silverlight application (any app will do)
    • Silverlight Preferences > Application Storage > Delete all...
    • Click "Yes"
    • * Optionally disable "Enable application storage"
    3) Delete Flash Local Shared Objects (LSO)
    • Go got the Flash "Website Storage Settings panel"
    • Click "Delete all sites"
    • Click "Confirm"
    4) Clear Browsing Data
    • - Wrench > Tools > Clear Browsing Data...
    • - Select all options
    • - Clear data from this period: Everything
    • - Click "Clear Browsing data"


Other Protections
• Nevercookie - The evercookie killer
Firefox plugin to extend Firefox’s Private Browsing

• Use a virtual machine. (On your neighbor’s WiFi Network)

Other Worries...
• System/browser timing
• GPU timing via plugins/accelerators (w/Flash)
• MAC address accessible via Java or ActiveX!

'Padding Oracle' Crypto Attack

In 2002 a powerful side-channel attack, ‘padding
oracle’ (NOT THE DATABASE!), was described targeting
AES CBC-mode encryption with PKCS#5 padding. If
there is an oracle which on receipt of a ciphertext,
decrypts it and replies whether the padding is correct,
shows how to use that oracle to decrypt data without
knowing the encryption key. The new techniques allow
attackers to use a ‘padding oracle’ to decrypt and encrypt
messages of any length without knowing the secret key
and exploit popular web development frameworks
including ASP.NET.
Juliano Rizzo (@julianor)
Thai Duong (@thaidn)

Brian Holyfield


Padding Oracle Attack Basics
An application uses a query string parameter to pass an encrypted username,
company id, and role id of a user. The parameter is encrypted using CBC mode,
and each value uses a unique initialization vector (IV) pre-pended to the ciphertext.
When the application is sent an encrypted value, it responds in one of three ways:

1)Valid ciphertext, properly padded and valid data (200 OK)
2)Invalid ciphertext, improper padding (500 Internal Server Error)
3)Valid ciphertext, properly padded and invalid data (200 OK - custom error)

User’s name (BRIAN), company id (12), and role id (2). The value, in plaintext, can
be represented as BRIAN;12;2;




First block of ciphertext pre-pended with an IV of all NULL values.

Request: http://site/app.jsp?UID=0000000000000000F851D6CC68FC9537
Response: 500 - Internal Server Error


Cross-Site Request Forgery (CSRF) is a major web vulnerability that forces users to perform unintended actions on websites. It remains underreported due to the difficulty of detection. CSRF can be used to hijack user accounts, modify browser settings, and force purchases without user awareness or consent. While solutions like tokens exist, many websites remain vulnerable to CSRF attacks.

Last byte of the initialization vector incremented by one.

Request: http://app/home.jsp?UID=0000000000000001F851D6CC68FC9537
Response: 500 - Internal Server Error

Incrementing the last byte in the IV up to FF will produce a valid padding sequence for a
single byte of padding (0×01). Only one value will produce the correct padding byte and
have different response than the other 255.

Request: http://site/app?UID=000000000000003CF851D6CC68FC9537
Response: 200 OK

                             If [Intermediary Byte] ^ 0x3C == 0×01,
                             then [Intermediary Byte] == 0x3C ^ 0×01,
                             so [Intermediary Byte] == 0x3D

To crack the 7th byte, the 7th and 8th byte must equal 0×02 for valid padding. Since we
already know that the last intermediary value byte is 0x3D, we can update the 8th IV byte
to 0x3F (which will produce 0×02) and then focus on brute forcing the 7th byte (starting
with 0×00 and working our way up through 0xFF).

Work backwards through the entire block until every byte of the intermediary value is
cracked and uncovering the decrypted value one byte at a time. The final byte is cracked
using an IV that produces an entire block of just padding (0×08).

                  "The first stage of the attack takes a few thousand requests, but
                 once it succeeds and the attacker gets the secret keys, it's totally
                    stealthy.The cryptographic knowledge required is very basic."
                                                                     - Julian Rizzo

"It turns out that the vulnerability in ASP.NET is the most critical amongst
          other frameworks. In short, it totally destroys ASP.NET security,"
                                                                -Thai Duong

Impact & Prevention
Vulnerable Frameworks
ASP.Net, CAPTCHAs, JavaServer Faces, OWASP ESAPI,
Ruby On Rails, etc.

•Encrypt-then-MAC (sign) and validate-then-decrypt

What have we learned?
• Encryption attacks took the top spot for the 2nd year in a row.
• Web Browser privacy? Web browser security? Not so much.
• “Top Ten” attacks from previous years are being improved.
• Several attack techniques from previous years are now
 actively being used maliciously in the wild.

Thank You...
• Sponsors: OWASP, Black Hat, WhiteHat
• Panel of Experts: Ed Skoudis, Giorgio
  Maone, Caleb Sima, Chris Wysopal, Jeff
  Willams, Charlie Miller, Dan Kaminsky,
  Steven Christey (Mitre), and Arian Evans
• All the security researchers for their
• Everyone in the Web Application Security
  community who assisted


Top Ten Web Hacking Techniques (2010)

  • 1. top ten Web Hacking techniques 2010 Jeremiah Grossman Founder & Chief Technology Officer Webcast 03.17.2011 © 2011 WhiteHat Security, Inc.
  • 2. Jeremiah Grossman • WhiteHat Security Founder & CTO • Technology R&D and industry evangelist • InfoWorld's CTO Top 25 for 2007 • Co-founder of the Web Application Security Consortium • Co-author: Cross-Site Scripting Attacks • Former Yahoo! information security officer © 2010 WhiteHat Security, Inc. | Page 2
  • 4. 400+ enterprise customers •Start-ups to Fortune 500 Flagship offering “WhiteHat Sentinel Service” •1000’s of assessments performed annually Recognized leader in website security •Quoted thousands of times by the mainstream press 4
  • 5. About the Top Ten “Every year the Web security community produces a stunning amount of new hacking techniques published in various white papers, blog posts, magazine articles, mailing list emails, etc. Within the thousands of pages are the latest ways to attack websites, Web browsers, Web proxies, and so on. Beyond individual vulnerability instances with CVE numbers or system compromises, we're talking about brand new and creative methods of Web-based attack.” 5
  • 6. New Techniques 2009 (80) Creating a rogue CA certificate 2008 (70) GIFAR (GIF + JAR) 2007 (83) XSS Vulnerabilities in Common Shockwave Flash Files 2006 (65) Web Browser Intranet Hacking / Port Scanning 6
  • 7. 2010 69 new techniques 1) 'Padding Oracle' Crypto Attack 2) Evercookie 3) Hacking Auto-Complete 4) Attacking HTTPS with Cache Injection 5) Bypassing CSRF protections with ClickJacking and HTTP Parameter Pollution 6) Universal XSS in IE8 7) HTTP POST DoS 8) JavaSnoop 9) CSS History Hack In Firefox Without JavaScript for Intranet Portscanning 10) Java Applet DNS Rebinding 7
  • 8. Bypassing CSRF with Clickjacking and HTTP Parameter Pollution 5 Clickjacking is when an attacker invisibly hovers an object (button, link, etc.) below a user's mouse. When the user clicks on something they visually see, they're instead really clicking on something the attacker wanted them to. HTTP Parameter Pollution is where an attacker submits multiple input parameters (query string, post data, cookies, etc.) with the same name. Upon receipt applications may react in unexpected ways and open up avenues of server-side and client-side exploitation. By cleverly leveraging these two former Top Ten attacks, CSRF attacks can be carried out against a user even when recommended token defenses are in use. Lavakumar Kuppan (@lavakumark) 8
  • 9. Clickjacking (Top Ten 2009) Think of any button – image, link, form, etc. – on any website – that can appear between the Web browser walls. This includes wire transfer on banks, DSL router buttons, Digg buttons, CPC advertising banners, Netflix queue. Next consider that an attacker can invisibly hover these buttons below the user's mouse, so that when a user clicks on something they visually see, they're actually clicking on something the attacker wants them to. What could the bad guy do with that ability? 9
  • 10. Hover Invisible IFRAMEs HTML, CSS, and JavaScript may size, follow the mouse and make transparent third- party IFRAME content. <iframe src="http://victim/page.html" scrolling="no" frameborder="0" style="opacity:.1;filter: alpha(opacity=.1); -moz-opacity 1.0;">! </iframe> 10
  • 11. HTTP Parameter Pollution (HPP) - Top Ten 2009 If an attacker submit multiple input parameters (query string, post data, cookies, etc.) of the same name, the application may react in unexpected ways and open up new avenues of server-side and client-side exploitation. GET /foo?par1=val1&par1=val2 HTTP/1.1 User-Agent: Mozilla/5.0 Host: Host Accept: */* POST /foo HTTP/1.1 User-Agent: Mozilla/5.0 Host: Host Accept: */* par1=val1&par1=val2 POST /index.aspx?par1=val1&par1=val2 HTTP/1.1 User-Agent: Mozilla/5.0 Host: Host Cookie: par1=val3; par1=val4 Content-Length: 19 par1=val5&par1=val6 11
  • 13. 13
  • 14. 14
  • 15. 15
  • 16. Simple parameter injection void private executeBackendRequest(HTTPRequest request) { String amount=request.getParameter("amount"); String beneficiary=request.getParameter("recipient"); HttpRequest("","POST", "action=transfer&amount="+amount+"&recipient="+beneficiary); } Malicious URL: Translates to: action=transfer&amount=1000&recipient=Jeremiah&action=withdraw It is possible the attack could work if proper authorization controls are not in place and the application uses the last occurrence of the action parameter (IBM Lotus Domino, PHP / Apache, etc.) 16
  • 17. Example Scenario http://example/updateEmail.jsp Client-Side <form method="POST"> <input type="text" name="email" value=””></input> <input type="hidden" name=”csrf-token” value="a0a0a0a0a0a"/> </form> Server-Side if (req.parameter("email").isSet() && req.parameter("csrf-token").isValid()) { // process the form and update the email ID } else { // display an empty form to the user (CSRF token included) } 17
  • 18. Bringing it all together <iframe src=”http://example/updateEmail.jsp?”> HTTP request via user submitted form via Clickjacking. The form was not filled out by the victim, meaning the email parameter in the POST body is blank. Now the QueryString contains the attacker entered value for the ‘email’ parameter. POST /updateEmail.jsp? HTTP/1.1 Host: email=&csrf-token=a0a0a0a0a0 When the server side JSP code calls req.parameter("email"), the value that is returned is the one in the QueryString (HPP first occurrence) and not the POST body. Since this value can be controlled by the attacker, he can trick the victim in to updating his account with the attacker’s mail ID. 18
  • 19. Attacking HTTPS with Cache Injection 4 No matter what type of encryption is used to defend a network, sooner or later the password, key, or certificate needs to be stored. If an attacker is able to tamper with the storage mechanism, even the strongest encryption mechanism can fail. The researchers demonstrated how to attack storage mechanisms by tampering with SSL session and break into Wifi networks using WPA. They also showed how to exploit SSL warning inconsistencies and caching mechanisms to trick the user into accepting a bad certs and steal their username & password. Elie Bursztein (@ELIE), Baptiste Gourdin (@bapt1ste), Dan Boneh 19
  • 20. RFC1918 Caching Security - (Top Ten 2009) Public Wifi HTTP Internet Airpwn Victims coffee shops, airplanes, corp guest networks Bad Guy • Victim(s) located on a RFC 1918 network with a Bad Guy • Bad Guy may take the opportunity to read victim’s Web mail, steal creds, etc. • Bad Guy man-in-the-middles HTTP (Airpwn) to inject IFRAMEs to RFC-1918 IPs • MitM IFRAMEs to include JavaScript malware (BeEF). Or ... • Inject JavaScript malware into popular Web widget URLs. (Ad servers, counters, etc.) • Cache content in the browser for a really long time, beyond current session!
  • 21. Situation • 43% of the Alexa top 100,000 use external javascript libraries • Injecting a malicious javascript library into the browser cache allows the attacker to compromise a website protected by SSL • The malicious library stays in the cache until the user clears it. Moving to a “safe” location doesn’t help 21
  • 22. Impact • One poisoned injection leads to multiple breaches • Multiples websites share the same external library such as Google Analytics • Injecting a malicious version of one of these shared libraries allows the attacker to target all the websites that use it 22
  • 23. Browser Defense -- sort of • The only defense against cache injection is the SSL warning displayed by the browser when a bad certificate is supplied • Corner cases that allows an attacker to alter the way SSL certificate warning are displayed • These alterations make caching attack efficient as the user is more likely to click through the tampered warning 23
  • 24. Video Demo • The following demos show how caching injection attacks works against Internet Explorer 8 and Firefox 3.6 • These demos were done in real time against real sites with their real certificates 24
  • 25. Hacking Auto-Complete 3 This research encompasses a set of techniques where a malicious website may surreptitiously obtain their visitors names, job title, workplace, physical address, telephone number, email addresses, usernames, passwords, search terms, social security numbers, credit card numbers, and on and on by simulating JavaScript keystroke events in Web browsers HTML form auto-complete / autofill functionality. Jeremiah Grossman (@jeremiahg) 25
  • 26. I want to know your name, who you work for, where you live, your email address, etc. Right at the moment you a visit a website. Even if you’ve never been there before, let alone entered information. 26
  • 27. Safari Address Book Autofill (enabled by default) <form> <input type="text" name="name"> <input type="text" name="company"> <input type="text" name="city"> <input type="text" name="state"> <input type="text" name="country"> <input type="text" name="email"> </form> 27
  • 28. Address Card Autofill works even when you’ve NEVER entered personal data on ANY WEBSITE. 28
  • 29. Demo var event = document.createEvent('TextEvent'); event.initTextEvent('textInput', 1, 1, null, char); input.value = ""; Step 1) Dynamically create input.selectionStart = 0; input fields with the pre-set input.selectionEnd = 0; attribute names. input.focus(); input.dispatchEvent(event);! Step 2) Cycle through the ! alphabet initiating text events setTimeout(function() { until a form value populates. if (input.value.length > 1) { // capture the value; Step 3) Profit! -- Steal data } with JavaScript. }, 500); *transparency is even more fun!* Safari v4 / v5 29
  • 30. Internet Explorer 8 = SAFE 30
  • 31. AutoComplete: User-supplied form values are shared across different websites by attribute “name”. For example, email addresses entered into a field on website A populates the autofill for the same field name on website B, C, D, etc. <input type="text" name="email"> 31
  • 32. DEMO - Down, Down, Enter // hit down arrow an incrementing number of times. // separate with time to allow the GUI to keep pace for (var i = 1; i <= downs; i++) { time += 30; // time padding keyStroke(this, 40, time); // down button } ! ! time += 15; // time padding keyStroke(this, 13, time); // enter button // initiate keystroke on a given object function keyStroke(obj, code, t) { //create new event and fire var e = document.createEventObject(); e.keyCode = code; setTimeout(function() {obj.fireEvent("onkeydown", e); }, t); } // end keyStroke Security Basis, and an Internet Explorer data stealer Andrea Giammarchi, Ajaxian Staff 32
  • 33. Search terms Credit card numbers and CCVs Aliases Contact information Answers to secret questions Usernames Email addresses ... 33
  • 34. AutoComplete is NOT enabled by default, but Internet Explorer asks if the user if they would like to enable the feature after filling out a non-password form. 34
  • 35. Have the email address, but need the password 35
  • 36. Saving Passwords Many Web Browsers have “password managers,” which provide a convenient way to save passwords on a “per website” basis. <form method="post" action="/"> E-Mail: <input type="text" name="email"><br /> Password: <input type="password" name="pass"><br /> <input type="submit" value="Login"> </form> 36
  • 37. If a website with a saved password is vulnerable to XSS, the payload can dynamically create login forms, which executes the browser’s password auto-complete feature. Since the payload is on the same domain the username / password can be stolen. function stealCreds() { var string = "E-Mail: " + document.getElementById("u").value; string += "nPassword: " + document.getElementById("p").value; return string; } document.write('<form method="post" action="/">E-Mail: <input id="u" type="text" name="email" value=""><br>Password: <input id="p" type="password" name="password" value=""></form>'); setTimeout('alert(stealCreds())', 2000); * * DEMO 37
  • 38. What to do... Disable Auto-Complete in the Web browser Remove persistent data (History, Form Data, Cookies, LocalStorage, etc.) NoScript (Firefox Extension), 1Password, etc. <form autocomplete="off"> <input type="text" autocomplete="off" /> 38
  • 39. Evercookie 2 Evercookie is a javascript API available that produces extremely persistent cookies in a browser. Its goal is to identify a client even after they've removed standard cookies, Flash cookies (Local Shared Objects or LSOs), and others. Evercookie accomplishes this by storing the cookie data in several types of storage mechanisms that are available on the local browser. Additionally, if evercookie has found the user has removed any of the types of cookies in question, it recreates them using each mechanism available. Samy Kamkar (@samykamkar) 39
  • 40. 40
  • 41. Evercookies 1) Standard HTTP Cookies 6) Internet Explorer userData storage 2) Flash Cookies (LSOs) 7) Storing cookies in Web cache 3) Silverlight Isolated Storage 8) Storing cookies in HTTP ETags 4) Storing cookies in RGB values of auto- 9) HTML5 Session Storage generated, force-cached PNGs using HTML5 Canvas tag to read pixels 10) HTML5 Local Storage (cookies) back out 11) HTML5 Global Storage 5) Storing cookies in Web History 12) HTML5 Database Storage via SQLite 6) caching 41
  • 42. The API • Persistent cookies via Javascript API • Recreates after deletion • Combines different storage mechanisms • Easy to use! var ec = new evercookie(); ec.set(“uniqueid”, “31337”); // set uniqueid = 31337 // get our evercookie data back ec.get(“uniqueid”, function(val) { alert (“ID is “ + val) } ); 42
  • 43. PNGs Cache Cookie stored in RGB values of auto-generated, force-cached PNGs using HTML5 Canvas Tag to read pixels back out Pixel 0x0 = 0x4f5741 OWA Pixel 0x1 = 0x535000 SP0 43
  • 44. Killing Evercookies (Video) 1) Open a new tab, then close all other windows and tabs. 2) Delete Silverlight Isolated Storage • Go to • Right click the Silverlight application (any app will do) • Silverlight Preferences > Application Storage > Delete all... • Click "Yes" • * Optionally disable "Enable application storage" 3) Delete Flash Local Shared Objects (LSO) • Go got the Flash "Website Storage Settings panel" • Click "Delete all sites" • Click "Confirm" 4) Clear Browsing Data • - Wrench > Tools > Clear Browsing Data... • - Select all options • - Clear data from this period: Everything • - Click "Clear Browsing data" 44
  • 45. Other Protections • Nevercookie - The evercookie killer Firefox plugin to extend Firefox’s Private Browsing • Use a virtual machine. (On your neighbor’s WiFi Network) 45
  • 46. Other Worries... • System/browser timing • GPU timing via plugins/accelerators (w/Flash) • MAC address accessible via Java or ActiveX! 46
  • 47. 'Padding Oracle' Crypto Attack 1 In 2002 a powerful side-channel attack, ‘padding oracle’ (NOT THE DATABASE!), was described targeting AES CBC-mode encryption with PKCS#5 padding. If there is an oracle which on receipt of a ciphertext, decrypts it and replies whether the padding is correct, shows how to use that oracle to decrypt data without knowing the encryption key. The new techniques allow attackers to use a ‘padding oracle’ to decrypt and encrypt messages of any length without knowing the secret key and exploit popular web development frameworks including ASP.NET. Juliano Rizzo (@julianor) Thai Duong (@thaidn) 47
  • 49. Padding Oracle Attack Basics An application uses a query string parameter to pass an encrypted username, company id, and role id of a user. The parameter is encrypted using CBC mode, and each value uses a unique initialization vector (IV) pre-pended to the ciphertext. When the application is sent an encrypted value, it responds in one of three ways: 1)Valid ciphertext, properly padded and valid data (200 OK) 2)Invalid ciphertext, improper padding (500 Internal Server Error) 3)Valid ciphertext, properly padded and invalid data (200 OK - custom error) User’s name (BRIAN), company id (12), and role id (2). The value, in plaintext, can be represented as BRIAN;12;2; http://site/app.jsp?UID=7B216A634951170FF851D6CC68FC9537858795A28ED4AAC6 49
  • 50. 50
  • 52. First block of ciphertext pre-pended with an IV of all NULL values. Request: http://site/app.jsp?UID=0000000000000000F851D6CC68FC9537 Response: 500 - Internal Server Error 52
  • 53. Last byte of the initialization vector incremented by one. Request: http://app/home.jsp?UID=0000000000000001F851D6CC68FC9537 Response: 500 - Internal Server Error 53
  • 54. Incrementing the last byte in the IV up to FF will produce a valid padding sequence for a single byte of padding (0×01). Only one value will produce the correct padding byte and have different response than the other 255. Request: http://site/app?UID=000000000000003CF851D6CC68FC9537 Response: 200 OK If [Intermediary Byte] ^ 0x3C == 0×01, then [Intermediary Byte] == 0x3C ^ 0×01, so [Intermediary Byte] == 0x3D 54
  • 55. To crack the 7th byte, the 7th and 8th byte must equal 0×02 for valid padding. Since we already know that the last intermediary value byte is 0x3D, we can update the 8th IV byte to 0x3F (which will produce 0×02) and then focus on brute forcing the 7th byte (starting with 0×00 and working our way up through 0xFF). 55
  • 56. Work backwards through the entire block until every byte of the intermediary value is cracked and uncovering the decrypted value one byte at a time. The final byte is cracked using an IV that produces an entire block of just padding (0×08). "The first stage of the attack takes a few thousand requests, but once it succeeds and the attacker gets the secret keys, it's totally stealthy.The cryptographic knowledge required is very basic." - Julian Rizzo 56
  • 57. <VIDEO> "It turns out that the vulnerability in ASP.NET is the most critical amongst other frameworks. In short, it totally destroys ASP.NET security," -Thai Duong 57
  • 58. Impact & Prevention Vulnerable Frameworks ASP.Net, CAPTCHAs, JavaServer Faces, OWASP ESAPI, Ruby On Rails, etc. Prevention •Encrypt-then-MAC (sign) and validate-then-decrypt •Patch! 58
  • 59. What have we learned? • Encryption attacks took the top spot for the 2nd year in a row. • Web Browser privacy? Web browser security? Not so much. • “Top Ten” attacks from previous years are being improved. • Several attack techniques from previous years are now actively being used maliciously in the wild. 59
  • 60. Thank You... • Sponsors: OWASP, Black Hat, WhiteHat Security • Panel of Experts: Ed Skoudis, Giorgio Maone, Caleb Sima, Chris Wysopal, Jeff Willams, Charlie Miller, Dan Kaminsky, Steven Christey (Mitre), and Arian Evans • All the security researchers for their contributions • Everyone in the Web Application Security community who assisted Blog: Twitter: Email: 60