<?xml version="1.0" encoding="utf-8"?><feed xmlns="http://www.w3.org/2005/Atom" ><generator uri="https://jekyllrb.com/" version="3.9.5">Jekyll</generator><link href="https://lutfumertceylan.com.tr/feed.xml" rel="self" type="application/atom+xml" /><link href="https://lutfumertceylan.com.tr/" rel="alternate" type="text/html" /><updated>2024-04-30T16:11:20+00:00</updated><id>https://lutfumertceylan.com.tr/feed.xml</id><title type="html">Lütfü Mert Ceylan</title><subtitle>&lt;b&gt;Security Researcher&lt;/b&gt; &lt;br&gt; Bachelor CSe &lt;b&gt;Student&lt;/b&gt; in WUT | OWASP &lt;b&gt;Project Leader&lt;/b&gt; | &lt;b&gt;founder&lt;/b&gt; @trbughunters &lt;br&gt; lutfu.mertceylan@owasp.org</subtitle><author><name>Lütfü Mert Ceylan</name><email>lutfu.mertceylan@owasp.org</email></author><entry><title type="html">EN \| My Experience as a Speaker at OWASP Global AppSec Washington D.C. 2023</title><link href="https://lutfumertceylan.com.tr/posts/owasp-global-appsec-washington-dc/" rel="alternate" type="text/html" title="EN \| My Experience as a Speaker at OWASP Global AppSec Washington D.C. 2023" /><published>2023-12-23T00:00:00+00:00</published><updated>2023-12-23T00:00:00+00:00</updated><id>https://lutfumertceylan.com.tr/posts/owasp-global-appsec-washington-dc</id><content type="html" xml:base="https://lutfumertceylan.com.tr/posts/owasp-global-appsec-washington-dc/"><![CDATA[<p><a data-flickr-embed="true" data-header="true" data-footer="true" href="https://www.flickr.com/photos/199731183@N06" title=""><img src="https://live.staticflickr.com/65535/53396944179_26105bdce1_z.jpg" width="640" height="480" alt="" /></a><script async="" src="//embedr.flickr.com/assets/client-code.js" charset="utf-8"></script><br /></p>

<h3 id="introduction">Introduction:</h3>
<p>Greetings to my professional colleagues and readers. This blog post delves into my enriching experience at the OWASP Global AppSec Washington D.C. 2023, where I had the honor of contributing as a speaker. This international cybersecurity conference, held in October 2023, was not only a platform for professional exchange but also a significant milestone in my career journey. Here, I share detailed insights into the conference, my presentation, and the invaluable experiences I gathered.</p>

<h3 id="conference-overview">Conference Overview:</h3>
<p>The OWASP Global AppSec conference was a convergence of pioneering ideas and cutting-edge practices in cybersecurity. The event brought together a diverse group of professionals, including industry leaders, researchers, and practitioners. The exchange of ideas and collaborative discussions over these few weeks provided a unique learning opportunity and a chance to understand the latest trends and challenges facing the cybersecurity world.</p>

<h3 id="presentation-analysis">Presentation Analysis:</h3>

<iframe src="https://www.academia.edu/111372412/OWASP_Top_25_Parameters_Project_Lu_tfu_Mert_Ceylan_2023_Global_AppSec_DC_Speaker_Slide?source=swp_share"></iframe>
<p><br />
Source on Academia.edu: <br />
<a href="https://www.academia.edu/111372412/OWASP_Top_25_Parameters_Project_Lu_tfu_Mert_Ceylan_2023_Global_AppSec_DC_Speaker_Slide?source=swp_share"><br /></a></p>

<p>My presentation on October 30 was a defining moment. I showcased my project, the OWASP Top 25 Parameters, which I began developing in my mid-teens and eventually transferred to OWASP in 2023, thereby stepping into the role of an OWASP Project Leader. The presentation covered the intricate details of the project, its evolution over the years, and its impact on the field. The project’s focus on the most frequently detected parameters in security vulnerabilities offers a comprehensive look at current cybersecurity challenges.</p>

<h3 id="project-synopsis-and-significance">Project Synopsis and Significance:</h3>

<p><strong>GitHub Repo:</strong></p>
<iframe src="https://github.com/lutfumertceylan/top25-parameter"><br />

**Official Project Page on OWASP:**
<a href="https://owasp.org/www-project-top-25-parameters/"><br />

The OWASP Top 25 Parameters project is a testament to the importance of ongoing research in cybersecurity. By analyzing prevalent security vulnerabilities across various systems, the project identifies and categorizes key parameters, thereby offering a valuable resource for security professionals worldwide. For those interested in delving deeper, I’ve included a link to the project repository, which serves as a robust resource for researchers and enthusiasts in the field.

### Personal Experiences and Growth:
As a young professional from Turkey, currently pursuing my studies in Poland, attending the conference in the United States was a transformative experience. The intercontinental journey was not just about geographical travel; it represented a significant leap in my professional and personal development. Engaging with a global community of cybersecurity experts, sharing ideas, and gaining fresh perspectives has immensely contributed to my growth in the field.

### Networking and Collaborations:
One of the highlights of the conference was the opportunity to network with peers and industry leaders. These interactions have opened doors to future collaborations and have enriched my understanding of global cybersecurity practices. The discussions I had with other speakers and attendees have broadened my horizons and have provided new avenues for exploration and innovation in my work.

<a data-flickr-embed="true" data-header="true" data-footer="true" href="https://www.flickr.com/photos/199731183@N06/53395701532/in/dateposted-public/" title="conf1"><img src="https://live.staticflickr.com/65535/53395701532_406f020235.jpg" width="333" height="500" alt="conf1" /></a><script async="" src="//embedr.flickr.com/assets/client-code.js" charset="utf-8"></script>
<a data-flickr-embed="true" data-header="true" data-footer="true" href="https://www.flickr.com/photos/199731183@N06/53396943069/in/dateposted-public/" title="resim_2023-12-14_053442734"><img src="https://live.staticflickr.com/65535/53396943069_3b1440ae9a.jpg" width="500" height="375" alt="resim_2023-12-14_053442734" /></a><script async="" src="//embedr.flickr.com/assets/client-code.js" charset="utf-8"></script><br />

### Gratitude and Future Aspirations:
I extend my sincere thanks to the OWASP Foundation for this invaluable opportunity. This conference has not only been a platform for sharing my work but also a catalyst for future endeavors in cybersecurity. I am inspired to continue my research and contribute to the field, and I eagerly anticipate participating in similar events in the future, further expanding my network and knowledge.

### Closing Thoughts:
As I reflect on my experience at OWASP Global AppSec DC 2023, I am filled with a sense of accomplishment and anticipation for what the future holds. This event has been a milestone in my journey, and I am motivated to keep pushing the boundaries of cybersecurity research and practice. To my fellow professionals and readers, I encourage you to stay engaged, keep exploring, and contribute to our shared field of cybersecurity. Here’s to many more years of learning, growing, and innovating together.
</a></iframe>]]></content><author><name>Lütfü Mert Ceylan</name><email>lutfu.mertceylan@owasp.org</email></author><category term="owasp" /><category term="global appsec washington dc 2023" /><category term="cyber security conference" /><category term="hack" /><category term="bugbounty" /><category term="write-up" /><category term="speaker" /><summary type="html"><![CDATA[x]]></summary></entry><entry><title type="html">EN \| Race Condition to Users Limit Bypass in Add User Function</title><link href="https://lutfumertceylan.com.tr/posts/race-condition-limit-bypass/" rel="alternate" type="text/html" title="EN \| Race Condition to Users Limit Bypass in Add User Function" /><published>2021-09-19T00:00:00+00:00</published><updated>2021-09-19T00:00:00+00:00</updated><id>https://lutfumertceylan.com.tr/posts/race-condition-limit-bypass</id><content type="html" xml:base="https://lutfumertceylan.com.tr/posts/race-condition-limit-bypass/"><![CDATA[<p><img src="/images/race.png" /><br /></p>
<hr />
<p><br />
In September of last year, I found a Race Condition vulnerability at an Online Services company located in the Netherlands. They had a private Zerocopter
program and that’s why I was doing bug hunting based on web applications, on their systems. And I reported the vulnerability to them. Then, they fixed this vulnerability and rewarded me with a €€€ bounty.</p>

<h2 id="firstly-what-is-a-race-condition">Firstly, what is a Race Condition?</h2>

<blockquote>
<b>What Is a Race Condition?</b><br />
In any computing system, there are some tasks that need to be completed in a specific order. For example, before allowing someone to log in, a security system first receives their username and password and then checks it against a database before allowing access. Attackers can exploit this fact by interfering with processes to access secure areas and content in what's known as a race condition attack.
</blockquote>
<blockquote>
<b>What Is a Race Condition Vulnerability?</b><br />
Race condition attacks (also called Time of Check to Time of Use, or TOCTTOU attacks) take advantage of the need that computing systems must execute some tasks in a specific sequence. In any such sequence, there is a small period of time when the system has carried out the first task but not started on the second. If this period is long enough or the attacker is lucky and knowledgeable, a race condition vulnerability exists where an attacker can trick the system into carrying out unauthorized actions in addition to its normal processes.<br />
  There are two main ways this attack is carried out:
 </blockquote>
<blockquote>
<b>Interference by an untrusted process</b> - The attacker inserts a piece of code in between the steps of a secure process.
  <br /><br />
<b>Interference by a trusted process</b> - The attacker exploits two different processes that share some state in common.
<p align="right"><i>-Veracode</i></p>
</blockquote>

<h2 id="recon">Recon</h2>

<p>When I was doing my pre-research normally for system recognition, I had already determined that they did not have a Rate Limit and I had reported it before. Of course, as you know, we cannot talk
about the existence of Race Condition vulnerability without No Rate Limit. Because these two are related vulnerabilities.
<br /><br />
The Race Condition vulnerability can exist thanks to a base formed by the
No Rate Limit vulnerability. Later, I realized that this vulnerability is not only in a single function, but in every function. And I researched for the riskiest place to amplify the impact.</p>

<hr />

<h2 id="there-is-something">There is something..</h2>

<p>I was trying to prove the existence of a Race Condition vulnerability in a function with no impact.
For this I use Turbo Intruder, which is a plugin of Burp Suite. If you want to get it, you can find it on the BApp Store.<br />
<img src="/images/turbo-int.jpg" /><br /></p>

<p>I was also detecting the vulnerability with this code snippet.<br />
<img src="/images/race-script-dark.jpg" /><br /></p>

<p>You can go to this tweet to access this code snippet: <a href="https://twitter.com/lutfumertceylan/status/1320980232015384576/">a Python Snippet to try Race Condition weakness in Turbo Intruder</a>
<br /><br />
And yes, this system had a Race Condition vulnerability.
<img src="/images/race-done.jpg" /><br /></p>
<hr />

<h2 id="eureka">Eureka!</h2>

<p>I had already grasped how the system works in pre-research. A premium membership(worth ~500€) was required to add multiple users to the test group. So a free membership could only add 1 user to the group.
I found the Add User function and executed the code snippet here with the Turbo Intruder.<br />
<img src="/images/race-panel.png" /><br /></p>

<p>And yeah! Like other functions, the Add User function also had a Race Condition vulnerability. And I was able to add as many users as I wanted to my test group. So I was able to do things on a free account that only a premium account can do.
<br /><br />
As you can see in the screenshot, my limit to add <strong>1</strong> user as a free membership has decreased to <strong>-22</strong>. So we broke the limit counter.</p>

<h2 id="the-end-">The end :</h2>

<p>13 September 2020 - Report sent<br />
15 September 2020 - Confirmed by triager<br />
22 September 2020 - Internal team denied impact of report<br />
25 September 2020 - Zerocopter discuss with Internal team<br />
05 October 2020 - Internal team also accept the impact of the vulnerability<br />
05 October 2020 - I was awarded a €€€ bounty</p>]]></content><author><name>Lütfü Mert Ceylan</name><email>lutfu.mertceylan@owasp.org</email></author><category term="race condition" /><category term="limit bypass" /><category term="Bug Bounty" /><category term="hack" /><category term="bugbounty" /><category term="write-up" /><category term="poc" /><summary type="html"><![CDATA[In September of last year, I found a Race Condition vulnerability at an Online Services company located in the Netherlands. They had a private Zerocopter program and that's why I was doing bug hunting based on web applications, on their systems. And I reported the...]]></summary></entry><entry><title type="html">EN \| Account Takeover via Web Cache Poisoning based Reflected XSS</title><link href="https://lutfumertceylan.com.tr/posts/acc-takeover-web-cache-xss/" rel="alternate" type="text/html" title="EN \| Account Takeover via Web Cache Poisoning based Reflected XSS" /><published>2020-12-26T00:00:00+00:00</published><updated>2020-12-26T00:00:00+00:00</updated><id>https://lutfumertceylan.com.tr/posts/account-takeover-via-web-cache-poisoning-based-reflected-xss</id><content type="html" xml:base="https://lutfumertceylan.com.tr/posts/acc-takeover-web-cache-xss/"><![CDATA[<p><img src="https://lutfumertceylan.com.tr/images/web-cache.png" /><br /></p>

<p>Firstly, it’s nice to publish my last write-up this year. In June of this year, I found a Reflected XSS vulnerability in a video-game company. Then, I realized that this server is caching the weak parameter’s value.
In this way, I incresead the probability of triggering this vulnerability and escalated to Account Takeover weakness.
Later, I reported the vulnerability and they fixed this vulnerability. Also, they rewarded me with a €€€ bounty. I can’t say the company, because I have no permission to disclose them.</p>

<h3 id="recon">Recon</h3>

<p>I discovered a Reflected XSS with a basic payload execution<br /> (<code class="language-plaintext highlighter-rouge">1&lt;/script&gt;&lt;svg/onload=confirm("document.cookie")&gt;</code>) in the “language” input. I thought this vuln was a normal Reflected XSS. As usual, the vulnerability was triggered when going to
the vulnerable URL and user session was stolen with a suitable payload. Because, the session cookie did not have any <code class="language-plaintext highlighter-rouge">httponly</code> or <code class="language-plaintext highlighter-rouge">secure</code> flags.</p>

<p>For those who don’t know what httponly and secure flag is:</p>
<blockquote>
  <p><code class="language-plaintext highlighter-rouge">HttpOnly:</code> An HttpOnly Cookie is a tag added to a browser cookie that prevents client-side scripts from accessing data. <i>[from CookiePro]</i><br /></p>
</blockquote>

<blockquote>
  <p><code class="language-plaintext highlighter-rouge">secure:</code> When a secure flag is used, then the cookie will only be sent over HTTPS, which is HTTP over SSL/TLS. When this is the case, the attacker eavesdropping on the communication channel from the browser to the server will not be able to read the cookie (HTTPS provides authentication, data integrity and confidentiality). <i>[from infosecinstitute]</i></p>
</blockquote>

<h3 id="impact-escalation-with-web-cache-poisoning">Impact Escalation with Web Cache Poisoning!</h3>
<p>But then, I saw that each page also contains <code class="language-plaintext highlighter-rouge">language</code> parameter. And I realized that the value of this parameter is put in the web cache. So this means:</p>
<blockquote>
  <p>Even if the vulnerability was triggered just once, the payload would be embedded in all pages of this site. <br /></p>
</blockquote>

<p>Actually, this does not cached entire page like standart Web Cache Poisoning weaknesses, only the part where the payload is embedded is cached. But of course, this is still a web cache poisoning. This scheme prepared by
Detectify may be useful for you.</p>

<p><img src="https://blog.detectify.com/wp-content/uploads/2020/07/web_cache_poisoning.png" /><br /></p>

<p>Also, you can read Dedectify’s article: <a href="https://blog.detectify.com/2020/07/28/do-you-trust-your-cache-web-cache-poisoning-explained/">https://blog.detectify.com/2020/07/28/do-you-trust-your-cache-web-cache-poisoning-explained/</a></p>

<h3 id="and-a-simple-account-takeover">And a simple Account Takeover</h3>

<p>As we mentioned at the beginning, there was no <code class="language-plaintext highlighter-rouge">httponly</code> and <code class="language-plaintext highlighter-rouge">secure</code> flag or a <code class="language-plaintext highlighter-rouge">Content-Security-Policy (CSP)</code> that can block payload on the site.</p>

<p><img src="/images/xsscac.png" /><br /></p>

<p>So admittedly, the system was already very weak.</p>

<h3 id="attack-scenario-with-web-cache-poisoning">Attack scenario with Web Cache Poisoning</h3>
<p>With Web Cache Poisoing, we can create a simple attack scenario. For example, if the victim sends a request in the background from an external page to the vulnerable URL in several ways(like embedding the vulnerable url in a picture),
The payload is cached in the web, and the payload is triggered each time the victim goes the target site.</p>

<p>I reported the vulnerability, and they agreed that it should be fixed.</p>

<p>If you want to learn Web Cache Poisoning:<br />
<a href="https://portswigger.net/web-security/web-cache-poisoning">https://portswigger.net/web-security/web-cache-poisoning</a></p>

<h3 id="the-end-and-results-">The end and results :</h3>

<p>17 June 2020 - Report sent<br />
18 June 2020 - Confirmed<br />
24 June 2020 - I was awarded a €€€ bounty<br /></p>]]></content><author><name>Lütfü Mert Ceylan</name><email>lutfu.mertceylan@owasp.org</email></author><category term="web cache poisoning" /><category term="account takeover" /><category term="web cache poisoning to account takeover" /><category term="reflected xss to account takeover" /><category term="reflected xss" /><category term="hack" /><category term="bugbounty" /><category term="write-up" /><category term="poc" /><summary type="html"><![CDATA[Firstly, its nice to publish my last write-up this year. In June of this year, I found a Reflected XSS vulnerability in a video-game company. Then, I realized that this server is caching the weak parameters value. In this way, I incresead the...]]></summary></entry><entry><title type="html">EN \| Clickjacking to Account Takeover via Drag&amp;amp;Drop</title><link href="https://lutfumertceylan.com.tr/posts/clickjacking-acc-takeover-drag-drop/" rel="alternate" type="text/html" title="EN \| Clickjacking to Account Takeover via Drag&amp;amp;Drop" /><published>2020-09-27T00:00:00+00:00</published><updated>2020-09-27T00:00:00+00:00</updated><id>https://lutfumertceylan.com.tr/posts/clickjacking-acc-takeover-drag-drop</id><content type="html" xml:base="https://lutfumertceylan.com.tr/posts/clickjacking-acc-takeover-drag-drop/"><![CDATA[<p><img src="/images/clickjacking-infographic.svg" /><br /></p>

<p>In August of this year, I found a Clickjacking vulnerability in a dutch company. Later I realized that this vulnerability could be upgraded to Account Takeover. Then,
I coded a PoC template with CSS and reported the vulnerability. And they fixed this vulnerability and rewarded me with a €€€ bounty. I don’t say the company, because they
want to remain confidential.</p>

<h3 id="recon">Recon</h3>
<p>I was reviewing the responses by sending requests to the system. When I looked at response header, I saw that the <code class="language-plaintext highlighter-rouge">X-Frame-Options</code> attribute was not set. This was causing 
the Clickjacking vulnerability.</p>

<h3 id="impact-escalation">Impact Escalation</h3>
<p>I saw there was a control panel page for users. Also, due to the system, when the e-mail address was changed, user accounts could be taken over.<br /></p>

<p><img src="/images/codeclick.png" /><br /></p>

<blockquote>
  <p>Template Source: <a href="https://pastebin.ubuntu.com/p/WKtVKBBd4F/">https://pastebin.ubuntu.com/p/WKtVKBBd4F/</a></p>
</blockquote>

<p>I coded a template using the drag&amp;drop feature with CSS and HTML.<br /></p>

<video width="500" controls="">
  <source src="/images/click-acc.mp4" type="video/mp4" />
</video>

<h3 id="reported">Reported</h3>
<p>I can hear what you think. Yes, Since the drag &amp; drop feature is used, the impact of the vulnerability is reduced. However, it is still a weakness that is likely to
cause serious damage. I reported the vulnerability, and we agreed with the company that it should be fixed.</p>

<h3 id="the-end-">The end :</h3>

<p>7 August 2020 - Report sent<br />
8 August 2020 - Confirmed<br />
11 August 2020 - I was awarded a €€€ bounty<br /></p>]]></content><author><name>Lütfü Mert Ceylan</name><email>lutfu.mertceylan@owasp.org</email></author><category term="clickjacking" /><category term="account takeover" /><category term="clickjacking to account takeover" /><category term="drag &amp; drop" /><category term="Bug Bounty" /><category term="hack" /><category term="bugbounty" /><category term="write-up" /><category term="poc" /><summary type="html"><![CDATA[In August of this year, I found a Clickjacking vulnerability in a dutch company. Later I realized that this vulnerability could be upgraded to Account Takeover. Then, I coded a PoC template with CSS and reported the vulnerability. And they fixed...]]></summary></entry><entry><title type="html">EN \| Alert-box Message Content Manipulation based Base64</title><link href="https://lutfumertceylan.com.tr/posts/alertbox-manipulation-base64/" rel="alternate" type="text/html" title="EN \| Alert-box Message Content Manipulation based Base64" /><published>2020-08-12T00:00:00+00:00</published><updated>2020-08-12T00:00:00+00:00</updated><id>https://lutfumertceylan.com.tr/posts/content-manipulation-base64</id><content type="html" xml:base="https://lutfumertceylan.com.tr/posts/alertbox-manipulation-base64/"><![CDATA[<p><img src="https://lutfumertceylan.com.tr/images/contentspoofing.png" /><br /></p>

<p>In July of this year, I found a Content Spoofing vulnerability in a Bitcoin Exchange company. The system was very simple, an encrypted text in a 
GET parameter was decrypted and reflected on the homepage in an alertbox. I know it’s very simple and its impact is <b>very low</b>. <u>In my philosophy, every finding
is worth reporting.</u> Then, I reported this weakness and the company rewarded me with a $$$ bounty.</p>

<h3 id="recon">Recon</h3>

<p>I was doing research on page of the website that do not require authentication, and I started researching the login page. While trying to login with some default credentials, 
I saw it execute “wrong username or password” warning on an GET parameter named “?e=”. I saw the parameter’s value is encrypted with Base64 and tried printing something else.
The website did not fail and reflected what I wrote on the screen as a warning.</p>

<h3 id="mechanism">Mechanism</h3>

<p>I placed the text in the picture below, which I encrypted with Base64, into the parameter. The system also executed this message.</p>

<p><img src="/images/alertcontent.jpg" /><br /></p>

<h3 id="weakness-is-weakness">Weakness is weakness…</h3>

<p>I know that this vulnerability is simply and very low impact. Personally, I am careful to report every findings I find.</p>

<h3 id="the-end-">The end :</h3>

<p>17 June 2020 - Report sent<br />
18 June 2020 - Confirmed <br />
27 June 2020 - I was awarded a $100 bounty<br /></p>]]></content><author><name>Lütfü Mert Ceylan</name><email>lutfu.mertceylan@owasp.org</email></author><category term="content manipulation" /><category term="content spoofing" /><category term="base64 paramater" /><category term="Bug Bounty" /><category term="hack" /><category term="bugbounty" /><category term="write-up" /><category term="poc" /><summary type="html"><![CDATA[In July of this year, I found a Content Spoofing vulnerability in a Bitcoin Exchange company. The system was very simple, an encrypted text in a GET parameter was decrypted and reflected on the homepage in an alertbox. I know it’s...]]></summary></entry><entry><title type="html">EN \| Account Takeover and Sensitive Data Leakage via CORS Misconfiguration</title><link href="https://lutfumertceylan.com.tr/posts/ato-and-data-leakage-via-cors-misc0/" rel="alternate" type="text/html" title="EN \| Account Takeover and Sensitive Data Leakage via CORS Misconfiguration" /><published>2020-07-04T00:00:00+00:00</published><updated>2020-07-04T00:00:00+00:00</updated><id>https://lutfumertceylan.com.tr/posts/ato-and-data-leakage-via-cors-misc</id><content type="html" xml:base="https://lutfumertceylan.com.tr/posts/ato-and-data-leakage-via-cors-misc0/"><![CDATA[<p><img src="/images/attack-on-cors.svg" /><br /></p>

<p>In June of this year, I found a CORS Misconfiguration vulnerability in a datacenter company. The system was very simple, a PUT command sent to the API Server
both changed the account email and showed all the data of the account in JSON format as Response. Then, I reported this weakness and the company rewarded me 
with a $$$ bounty. Also, I would like to thank <a href="https://twitter.com/bugraeskici">Bugra Eskici</a> , who helped me a lot to detect this vulnerability.</p>

<h3 id="recon">Recon</h3>
<p>I was reviewing the responses by sending requests to the system. When I looked at request header, I saw that the “Origin” attribute was defined.
The vulnerable site was defined in the “Origin” attribute as a value, and this value was also defined in the “Access-Control-Allow-Origin” attribute in the Response.
Also, the “Access-Control-Allow-Credentials” value was “true”.</p>

<h3 id="is-it-vulnerable">Is it vulnerable?</h3>
<p>I write evil.com as the value to Origin. And Bingo! The response status was “200 OK” and evil.com was also included in the Access-Control-Allow-Origin attribute.<br /></p>

<p><img src="/images/corsheader.png" /><br /></p>

<p>That is, there was a CORS Misconfiguration vulnerability.</p>

<h3 id="double-shot">Double Shot!!</h3>
<p>I can change the account email with a simple PUT request. Moreover, the server was showing the sensitive data of the account as Response. Then, I have created a simple
script for both changing email and stealing sensitive data.</p>

<p>You can find the script I created in my tweet:</p>
<blockquote class="twitter-tweet"><p lang="en" dir="ltr">A script you can use for Sensitive Data Leakage via CORS Misconfiguration 🕵️🧙‍♂️<br /><br />Source Code: <a href="https://t.co/TroWuo34cJ">https://t.co/TroWuo34cJ</a><a href="https://twitter.com/hashtag/bugbountytips?src=hash&amp;ref_src=twsrc%5Etfw">#bugbountytips</a> <a href="https://twitter.com/hashtag/bugbountytip?src=hash&amp;ref_src=twsrc%5Etfw">#bugbountytip</a> <a href="https://twitter.com/hashtag/bugbounty?src=hash&amp;ref_src=twsrc%5Etfw">#bugbounty</a> <a href="https://twitter.com/hashtag/cybersecurity?src=hash&amp;ref_src=twsrc%5Etfw">#cybersecurity</a> <a href="https://twitter.com/hashtag/infosec?src=hash&amp;ref_src=twsrc%5Etfw">#infosec</a> <a href="https://twitter.com/hashtag/ethicalhacking?src=hash&amp;ref_src=twsrc%5Etfw">#ethicalhacking</a> <a href="https://t.co/e0hId2BKmG">pic.twitter.com/e0hId2BKmG</a></p>&mdash; Lütfü Mert Ceylan (@lutfumertceylan) <a href="https://twitter.com/lutfumertceylan/status/1274829687177515011?ref_src=twsrc%5Etfw">June 21, 2020</a></blockquote>
<script async="" src="https://platform.twitter.com/widgets.js" charset="utf-8"></script>
<p><br /></p>

<p>With the script, I changed the e-mail address by sending a PUT request. (Account Takeover)
<img src="/images/putreqcors.jpg" /><br /></p>

<p>Then, I sent the Response containing sensitive data to a request-bin service with this script.
<img src="/images/respcors.jpg" /><br /></p>

<p>And, sensitive data sent the attacker’s site.
<img src="/images/sensdatacors.jpg" /><br /></p>

<p>So I was able to both change the e-mail address of the victim account and steal sensitive data. Both vulnerabilities were caused by CORS Misconfiguration.
As I have explained, it is possible to exploit these vulnerabilities with a simple script.</p>

<h3 id="the-end-">The end :</h3>

<p>10 June 2020 - Report sent<br />
10 June 2020 - Confirmed <br />
11 June 2020 - I was awarded a $$$ bounty<br /></p>]]></content><author><name>Lütfü Mert Ceylan</name><email>lutfu.mertceylan@owasp.org</email></author><category term="cors misconfiguration" /><category term="account takeover" /><category term="sensitive data leak" /><category term="Bug Bounty" /><category term="hack" /><category term="bugbounty" /><category term="write-up" /><category term="poc" /><summary type="html"><![CDATA[In June of this year, I found a CORS Misconfiguration vulnerability in a datacenter company. The system was very simple, a PUT command sent to the API Server both changed the account email and showed all the data of the account in JSON format as Response. Then, I reported...]]></summary></entry><entry><title type="html">EN \| Account Takeover and Sensitive Data Leakage via CORS Misconfiguration</title><link href="https://lutfumertceylan.com.tr/posts/ato-and-data-leakage-via-cors-misc/" rel="alternate" type="text/html" title="EN \| Account Takeover and Sensitive Data Leakage via CORS Misconfiguration" /><published>2020-07-04T00:00:00+00:00</published><updated>2020-07-04T00:00:00+00:00</updated><id>https://lutfumertceylan.com.tr/posts/ato-and-data-leakage-via-cors-misc0</id><content type="html" xml:base="https://lutfumertceylan.com.tr/posts/ato-and-data-leakage-via-cors-misc/"><![CDATA[<p><img src="https://portswigger.net/web-security/images/attack-on-cors.svg" /><br /></p>

<p>In June of this year, I found a CORS Misconfiguration vulnerability in a datacenter company. The system was very simple, a PUT command sent to the API Server
both changed the account email and showed all the data of the account in JSON format as Response. Then, I reported this weakness and the company rewarded me 
with a $$$ bounty. Also, I would like to thank <a href="https://twitter.com/bugraeskici">Bugra Eskici</a> , who helped me a lot to detect this vulnerability.</p>

<h3 id="recon">Recon</h3>
<p>I was reviewing the responses by sending requests to the system. When I looked at request header, I saw that the “Origin” attribute was defined.
The vulnerable site was defined in the “Origin” attribute as a value, and this value was also defined in the “Access-Control-Allow-Origin” attribute in the Response.
Also, the “Access-Control-Allow-Credentials” value was “true”.</p>

<h3 id="is-it-vulnerable">Is it vulnerable?</h3>
<p>I write evil.com as the value to Origin. And Bingo! The response status was “200 OK” and evil.com was also included in the Access-Control-Allow-Origin attribute.<br /></p>

<p><img src="/images/corsheader.png" /><br /></p>

<p>That is, there was a CORS Misconfiguration vulnerability.</p>

<h3 id="double-shot">Double Shot!!</h3>
<p>I can change the account email with a simple PUT request. Moreover, the server was showing the sensitive data of the account as Response. Then, I have created a simple
script for both changing email and stealing sensitive data.</p>

<p>You can find the script I created in my tweet:</p>
<blockquote class="twitter-tweet"><p lang="en" dir="ltr">A script you can use for Sensitive Data Leakage via CORS Misconfiguration 🕵️🧙‍♂️<br /><br />Source Code: <a href="https://t.co/TroWuo34cJ">https://t.co/TroWuo34cJ</a><a href="https://twitter.com/hashtag/bugbountytips?src=hash&amp;ref_src=twsrc%5Etfw">#bugbountytips</a> <a href="https://twitter.com/hashtag/bugbountytip?src=hash&amp;ref_src=twsrc%5Etfw">#bugbountytip</a> <a href="https://twitter.com/hashtag/bugbounty?src=hash&amp;ref_src=twsrc%5Etfw">#bugbounty</a> <a href="https://twitter.com/hashtag/cybersecurity?src=hash&amp;ref_src=twsrc%5Etfw">#cybersecurity</a> <a href="https://twitter.com/hashtag/infosec?src=hash&amp;ref_src=twsrc%5Etfw">#infosec</a> <a href="https://twitter.com/hashtag/ethicalhacking?src=hash&amp;ref_src=twsrc%5Etfw">#ethicalhacking</a> <a href="https://t.co/e0hId2BKmG">pic.twitter.com/e0hId2BKmG</a></p>&mdash; Lütfü Mert Ceylan (@lutfumertceylan) <a href="https://twitter.com/lutfumertceylan/status/1274829687177515011?ref_src=twsrc%5Etfw">June 21, 2020</a></blockquote>
<script async="" src="https://platform.twitter.com/widgets.js" charset="utf-8"></script>
<p><br /></p>

<p>With the script, I changed the e-mail address by sending a PUT request. (Account Takeover)
<img src="/images/putreqcors.jpg" /><br /></p>

<p>Then, I sent the Response containing sensitive data to a request-bin service with this script.
<img src="/images/respcors.jpg" /><br /></p>

<p>And, sensitive data sent the attacker’s site.
<img src="/images/sensdatacors.jpg" /><br /></p>

<p>So I was able to both change the e-mail address of the victim account and steal sensitive data. Both vulnerabilities were caused by CORS Misconfiguration.
As I have explained, it is possible to exploit these vulnerabilities with a simple script.</p>

<h3 id="the-end-">The end :</h3>

<p>10 June 2020 - Report sent<br />
10 June 2020 - Confirmed <br />
11 June 2020 - I was awarded a $$$ bounty<br /></p>]]></content><author><name>Lütfü Mert Ceylan</name><email>lutfu.mertceylan@owasp.org</email></author><category term="cors misconfiguration" /><category term="account takeover" /><category term="sensitive data leak" /><category term="Bug Bounty" /><category term="hack" /><category term="bugbounty" /><category term="write-up" /><category term="poc" /><summary type="html"><![CDATA[In June of this year, I found a CORS Misconfiguration vulnerability in a datacenter company. The system was very simple, a PUT command sent to the API Server both changed the account email and showed all the data of the account in JSON format as Response. Then, I reported...]]></summary></entry><entry><title type="html">EN \| Stored XSS with Password Recovery Page</title><link href="https://lutfumertceylan.com.tr/posts/stored-xss-with-password-recovery-page/" rel="alternate" type="text/html" title="EN \| Stored XSS with Password Recovery Page" /><published>2020-06-01T00:00:00+00:00</published><updated>2020-06-01T00:00:00+00:00</updated><id>https://lutfumertceylan.com.tr/posts/stored-xss-with-password-recovery-page</id><content type="html" xml:base="https://lutfumertceylan.com.tr/posts/stored-xss-with-password-recovery-page/"><![CDATA[<p><img src="/images/cross-site-scripting.svg" /><br /></p>

<p>In April of this year, I found a Stored Xss vulnerability at University of Utwente. However, I later realized that there was a vendor of
the vulnerable system, and I contacted them. Then they fixed this vuln. and rewarded me with a $$$ bounty. Also this was my first bounty.
I don’t say the company that produced the system because they want to remain confidential.</p>

<h3 id="recon">Recon</h3>
<p>I discovered XSS with a simple payload execution in the “First Name” input. But I thought this vuln was a Self XSS.
Because all pages were private for every user (except for one page). Then I saw that the password recovery page also contains user First Name value.</p>

<h3 id="first-try">First Try</h3>
<p>I type a payload in the “first_name” input<br />
<img src="/images/payl.png" /></p>

<p>but the system always encodes the payloads on Profile Page.<br />
<img src="/images/payl2.png" /></p>

<p>Profile Page was not public anyway. Not bad luck!</p>

<h3 id="catch-you">Catch You!!</h3>
<p>I believed XSS was no longer possible. But there is one last place, “Password Recovery Page”, Moreover, it reflects the user’s “first_name” value to the page.</p>

<p>I just created the page with the request to create a Password Recovery Page. The system not encode the payload on this page. So payload was executed!</p>

<h3 id="the-end-">The end :</h3>

<p>9 April 2020 - Report sent<br />
10 April 2020 - Scenario requested<br />
13 April 2020 - Report’s scenario sent<br />
14 April 2020 - I was awarded a $$$ bounty<br /></p>]]></content><author><name>Lütfü Mert Ceylan</name><email>lutfu.mertceylan@owasp.org</email></author><category term="stored xss" /><category term="xss in password recovery" /><category term="Bug Bounty" /><category term="hack" /><category term="bugbounty" /><category term="write-up" /><category term="poc" /><summary type="html"><![CDATA[In April of this year, I found a Stored Xss vulnerability at University of Utwente. However, I later realized that there was a vendor of the vulnerable system, and I contacted them. Then they fixed this vuln. and rewarded me with a $$$ bounty. Also this was my first bounty...]]></summary></entry></feed>