Breaking Application’s Logic to DOS Attack
https://medium.com/@abhiunix/breaking-applications-logic-to-dos-attack-b38d5e1794b?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://medium.com/@abhiunix/breaking-applications-logic-to-dos-attack-b38d5e1794b?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
Breaking Application’s Logic to DOS Attack
Hey guys,
Recently I had found a bug which was fine enough to deserve this post. So, I thought of writing it up here. I can not disclose…
Recently I had found a bug which was fine enough to deserve this post. So, I thought of writing it up here. I can not disclose…
Hey guys,
Recently I had found a bug which was fine enough to deserve this post. So, I thought of writing it up here. I can not disclose…Continue reading on Medium » (https://medium.com/@abhiunix/breaking-applications-logic-to-dos-attack-b38d5e1794b?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
Recently I had found a bug which was fine enough to deserve this post. So, I thought of writing it up here. I can not disclose…Continue reading on Medium » (https://medium.com/@abhiunix/breaking-applications-logic-to-dos-attack-b38d5e1794b?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
Medium
Breaking Application’s Logic to DOS Attack
Hey guys,
Recently I had found a bug which was fine enough to deserve this post. So, I thought of writing it up here. I can not disclose…
Recently I had found a bug which was fine enough to deserve this post. So, I thought of writing it up here. I can not disclose…
Hacking Articles Tips Tricks Videos Tutorials
Photo
KitPloit - PenTest Tools!
Regexploit - Find Regular Expressions Which Are Vulnerable To ReDoS (Regular Expression Denial Of Service)
https://1.bp.blogspot.com/-UjWm8eord38/YO93rWcho5I/AAAAAAAAjQ0/Xwl7ZZuO-SUdvH7ODpTuRdsNolgYLWpowCNcBGAsYHQ/w640-h126/regexploit_1.png Find regexes which are vulnerable to Regular Expression Denial of Service (ReDoS).
More info on the Doyensec blog
Many default regular expression parsers have unbounded worst-case complexity. Regex matching may be quick when presented with a matching input string. However, certain non-matching input strings can make the regular expression matcher go into crazy backtracking loops and take ages to process. This can cause denial of service, as the CPU will be stuck trying to match the regex.
This tool is designed to:
* find regular expressions which are vulnerable to ReDoS
* give an example malicious string which will cause catastrophic backtracking Worst-case complexityThis reflects the complexity of the regular expression matcher's backtracking procedure with respect to the length of the entered string.
Cubic complexity here means that if the vulnerable part of the string is doubled in length, the execution time should be about 8 times longer (2^3). For exponential ReDoS with starred stars e.g.
For explotability, cubic complexity or higher is typically required unless truly giant strings are allowed as input. ExampleRun
As another example, install a module version vulnerable to ReDoS such as
___________________________
@hacking_Attack
@Hacking_Video
Regexploit - Find Regular Expressions Which Are Vulnerable To ReDoS (Regular Expression Denial Of Service)
https://1.bp.blogspot.com/-UjWm8eord38/YO93rWcho5I/AAAAAAAAjQ0/Xwl7ZZuO-SUdvH7ODpTuRdsNolgYLWpowCNcBGAsYHQ/w640-h126/regexploit_1.png Find regexes which are vulnerable to Regular Expression Denial of Service (ReDoS).
More info on the Doyensec blog
Many default regular expression parsers have unbounded worst-case complexity. Regex matching may be quick when presented with a matching input string. However, certain non-matching input strings can make the regular expression matcher go into crazy backtracking loops and take ages to process. This can cause denial of service, as the CPU will be stuck trying to match the regex.
This tool is designed to:
* find regular expressions which are vulnerable to ReDoS
* give an example malicious string which will cause catastrophic backtracking Worst-case complexityThis reflects the complexity of the regular expression matcher's backtracking procedure with respect to the length of the entered string.
Cubic complexity here means that if the vulnerable part of the string is doubled in length, the execution time should be about 8 times longer (2^3). For exponential ReDoS with starred stars e.g.
(a*)*$a fudge factor is used and the complexity will be greater than 10.For explotability, cubic complexity or higher is typically required unless truly giant strings are allowed as input. ExampleRun
regexploitand enter the regular expression v\w*_\w*_\w*$at the command line. $ regexploit
v\w*_\w*_\w*$
Pattern: v\w*_\w*_\w*$
---
Worst-case complexity: 3 ⭐⭐⭐ (cubic)
Repeated character: [5f:_]
Final character to cause backtracking: [^WORD]
Example: 'v' + '_' * 3456 + '!' The part \w*_\w*_\w*contains three overlapping repeating groups (\w matches letters, digits and underscores). As showed in the line Repeated character: [5f:_], a long string of _(0x5f) will match this section in many different ways. The worst-case complexity is 3 as there are 3 infinitely repeating groups. An example to cause ReDoS is given: it consists of the required prefix v, a long string of _and then a !(non-word character) to cause backtracking. Not all ReDoSes require a particular character at the end, but in this case, a long string of _will match the regex successfully and won't backtrack. The line Final character to cause backtracking: [^WORD]shows that a non-matching character (not a word character) is required at the end to prevent matching and cause ReDoS.As another example, install a module version vulnerable to ReDoS such as
pip install ua-parser==0.9.0. To scan the installed python modules run regexploit-python-env. Importing ua_parser.user_agent_parser
Vulnerable regex in /somewhere/.env/lib/python3.9/site-packages/ua_parser/user_agent_parser.py #183
Pattern: \bSmartWatch *\( *([^;]+) *; *([^;]+) *;
Context: self.user_agent_re = re.compile(self.pattern)
---
Worst-case complexity: 3 ⭐⭐⭐
Repeated character: [20]
Example: 'SmartWatch(' + ' ' * 3456
Worst-case complexity: 3 ⭐⭐⭐
Repeated character: [20]
Example: 'SmartWatch(0;' + ' ' * 3456
Vulnerable regex in /somewhere/.env/lib/python3.9/site-packages/ua_parser/user_agent_parser.py #183
Pattern: ; *([^;/]+) Build[/ ]Huawei(MT1-U06|[A-Z]+\d+[^\);]+)[^\);]*\)
Context: self.user_agent_re = re.compile(self.pattern)
---
Worst-case complexity: 3 ⭐⭐⭐
Repeated character: [[0-9]]
Example: ';0 Build/HuaweiA' + '0' * 3456
... For each vulnerable regular expression it prints one or more malicious string to trigger ReDoS. Setting your user agent to ;0 Build/HuaweiA000000000000000...[...]___________________________
@hacking_Attack
@Hacking_Video
KitPloit - PenTest & Hacking Tools
Regexploit - Find Regular Expressions Which Are Vulnerable To ReDoS (Regular Expression Denial Of Service)
Hacking Articles Tips Tricks Videos Tutorials
KitPloit - PenTest Tools! Regexploit - Find Regular Expressions Which Are Vulnerable To ReDoS (Regular Expression Denial Of Service) https://1.bp.blogspot.com/-UjWm8eord38/YO93rWcho5I/AAAAAAAAjQ0/Xwl7ZZuO-SUdvH7ODpTuRdsNolgYLWpowCNcBGAsYHQ/w640-h126/regexploit_1.png…
and browsing a website using an old version of ua-parser may cause the server to take a long time to process your request, probably ending in status 502. InstallationPython 3.8+ is required. To extract regexes from JavaScript / TypeScript code, NodeJS 12+ is also required.
Optionally make a virtual environment
Those regexes are fed into the python ReDoS finder.
* CVE-2020-8492: cpython's urllib.request (WWW-Authenticate header parsing)
* CVE-2021-21236: CairoSVG (SVG parsing)
* CVE-2021-21240: httplib2 (WWW-Authenticate header parsing)
* CVE-2021-25292: python-pillow (PDF parsing)
* CVE-2021-26813: python-markdown2 (Markdown parsing)
* CVE-2021-27290: npm/ssri (SRI parsing)
* CVE-2021-27291: pygments lexers for ADL, CADL, Ceylon, Evoque, Factor, Logos, Matlab, Octave, ODIN, Scilab & Varnish VCL (Syntax highlighting)
* CVE-2021-27292: ua-parser-js (User-Agent header parsing)
* CVE-2021-27293: RestSharp (JSON deserialisation in a .NET C# package)
* bpo-38804: cpython's http.cookiejar (Set-Cookie header parsing)
* SimpleCrawler (archived) (HTML parsing)
* CVE-2021-28092: is-svg (SVG parsing)
* nuget.org, NuGetGallery and NuGet.Client (Parsing NuGet package IDs)
* markdown (python) (Markdown parsing)
* ansi-html (nodejs) (ANSI parsing)
* Plus unpublished bugs in a handful of pypi, npm, ruby and nuget packages CreditsThis tool has been created by Ben Caller of Doyensec LLC during research time. https://camo.githubusercontent.com/604dfb1a1bfac98d0048f363e0e6d65bd88b4fdbd57f5b001a8f76ea580c1097/68747470733a2f2f646f79656e7365632e636f6d2f696d616765732f6c6f676f2e737667 Download Regexploit
___________________________
@hacking_Attack
@Hacking_Video
Optionally make a virtual environment
python3 -m venv .env
source .env/bin/activateNow actually install with pip pip install regexploit UsageRegexploit with a list of regexesEnter regular expressions via stdin (one per line) into regexploit. regexploitor via a file cat myregexes.txt | regexploitExtract regexes automaticallyThere is built-in support for parsing regexes out of Python, JavaScript, TypeScript, C#, YAML and JSON. Python codeParses Python code (without executing it) via the AST to find regexes. The regexes are then analysed for ReDoS. regexploit-py my-project/
regexploit-py "my-project/**/*.py" --globJavascript / TypescriptThis will use the bundled NodeJS package in regexploit/bin/javascriptwhich parses your JavaScript as an AST with eslint and prints out all regexes.Those regexes are fed into the python ReDoS finder.
regexploit-js my-module/my-file.js another/file.js some/folder/
regexploit-js "my-project/node_modules/**/*.js" --globN.B. there are differences between javascript and python regex parsing so there may be some errors. I'm not sure I want to write a JS regex AST! Python importsSearch for regexes in all the python modules currently installed in your path / env. This means you can pip installwhatever modules you are interested in and they will be analysed. Cpython code is included. regexploit-python-envN.B. this doesn't parse the python code to an AST and will only find regexes compiled automatically on module import. Modules are actually imported, so code in the modules will be executed. This is helpful for finding regexes which are built up from smaller strings on load e.g. CVE-2021-25292 in Pillow JSON / YAMLYaml support requires pyyaml, which can be installed with pip install regexploit[yaml]. regexploit-json *.json
regexploit-yaml *.yamlC# (.NET)regexploit-csharp something.csBugs reported* CVE-2020-5243: uap-core affecting uap-python, uap-ruby, etc. (User-Agent header parsing)* CVE-2020-8492: cpython's urllib.request (WWW-Authenticate header parsing)
* CVE-2021-21236: CairoSVG (SVG parsing)
* CVE-2021-21240: httplib2 (WWW-Authenticate header parsing)
* CVE-2021-25292: python-pillow (PDF parsing)
* CVE-2021-26813: python-markdown2 (Markdown parsing)
* CVE-2021-27290: npm/ssri (SRI parsing)
* CVE-2021-27291: pygments lexers for ADL, CADL, Ceylon, Evoque, Factor, Logos, Matlab, Octave, ODIN, Scilab & Varnish VCL (Syntax highlighting)
* CVE-2021-27292: ua-parser-js (User-Agent header parsing)
* CVE-2021-27293: RestSharp (JSON deserialisation in a .NET C# package)
* bpo-38804: cpython's http.cookiejar (Set-Cookie header parsing)
* SimpleCrawler (archived) (HTML parsing)
* CVE-2021-28092: is-svg (SVG parsing)
* nuget.org, NuGetGallery and NuGet.Client (Parsing NuGet package IDs)
* markdown (python) (Markdown parsing)
* ansi-html (nodejs) (ANSI parsing)
* Plus unpublished bugs in a handful of pypi, npm, ruby and nuget packages CreditsThis tool has been created by Ben Caller of Doyensec LLC during research time. https://camo.githubusercontent.com/604dfb1a1bfac98d0048f363e0e6d65bd88b4fdbd57f5b001a8f76ea580c1097/68747470733a2f2f646f79656e7365632e636f6d2f696d616765732f6c6f676f2e737667 Download Regexploit
___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
How to know if android phone is hacked 2021
Nowadays everyone has it own Android or SmartPhone. From a report, it is stated that there is a sudden rise in the mobile users from last…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
How to know if android phone is hacked 2021
Nowadays everyone has it own Android or SmartPhone. From a report, it is stated that there is a sudden rise in the mobile users from last…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
How to know if android phone is hacked 2021
Nowadays everyone has it own Android or SmartPhone. From a report, it is stated that there is a sudden rise in the mobile users from last…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Victim:1 | Vulnhub Walkthrough
https://cdn-images-1.medium.com/max/928/1*s-zBHGADLAeh1tdjEeTi3w.png
A lot of services to enumerate on this box so let’s get started
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Victim:1 | Vulnhub Walkthrough
https://cdn-images-1.medium.com/max/928/1*s-zBHGADLAeh1tdjEeTi3w.png
A lot of services to enumerate on this box so let’s get started
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Victim:1 | Vulnhub Walkthrough
A lot of services to enumerate on this box so let’s get started
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Free Firasdris_BotV0.9 -Auto Upload Shells, crack WP, CP, SMTP | 2021
Link Download: Link: https://exe.io/qCnsTg5
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Free Firasdris_BotV0.9 -Auto Upload Shells, crack WP, CP, SMTP | 2021
Link Download: Link: https://exe.io/qCnsTg5
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
🔥 Free 🔥Firasdris_BotV0.9 -Auto Upload Shells, crack WP, CP, SMTP | 2021
Link Download: Link: https://exe.io/qCnsTg5
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Breaking Application’s Logic to DOS Attack
https://cdn-images-1.medium.com/max/600/1*HapwwkP6A0HFpcWveqtRrg.png
Hey guys,
Recently I had found a bug which was fine enough to deserve this post. So, I thought of writing it up here. I can not disclose…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Breaking Application’s Logic to DOS Attack
https://cdn-images-1.medium.com/max/600/1*HapwwkP6A0HFpcWveqtRrg.png
Hey guys,
Recently I had found a bug which was fine enough to deserve this post. So, I thought of writing it up here. I can not disclose…
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Breaking Application’s Logic to DOS Attack
Hey guys,
Recently I had found a bug which was fine enough to deserve this post. So, I thought of writing it up here. I can not disclose…
Recently I had found a bug which was fine enough to deserve this post. So, I thought of writing it up here. I can not disclose…
Breaking Application’s Logic to DOS Attack
Hey guys, Recently I had found a bug which was fine enough to deserve this post. So, I thought of writing it up here. I can not disclose…Continue reading on Medium »
Read more...
Hey guys, Recently I had found a bug which was fine enough to deserve this post. So, I thought of writing it up here. I can not disclose…Continue reading on Medium »
Read more...
Regexploit - Find Regular Expressions Which Are Vulnerable To ReDoS (Regular Expression Denial Of Service)
http://www.kitploit.com/2021/07/regexploit-find-regular-expressions.html
___________________________
@hacking_Attack
@Hacking_Video
http://www.kitploit.com/2021/07/regexploit-find-regular-expressions.html
___________________________
@hacking_Attack
@Hacking_Video
KitPloit - PenTest & Hacking Tools
Regexploit - Find Regular Expressions Which Are Vulnerable To ReDoS (Regular Expression Denial Of Service)
Find regexes which are vulnerable (https://www.kitploit.com/search/label/Vulnerable) to Regular Expression (https://www.kitploit.com/search/label/Regular%20Expression) Denial of Service (https://www.kitploit.com/search/label/Denial%20of%20Service) (ReDoS). More info on the Doyensec blog (https://blog.doyensec.com/2021/03/11/regexploit.html) Many default regular expression parsers have unbounded worst-case complexity. Regex matching may be quick when presented with a matching input string. However, certain non-matching input strings can make the regular expression matcher go into crazy backtracking loops and take ages to process. This can cause denial of service, as the CPU will be stuck trying to match the regex. This tool is designed to: find regular expressions (https://www.kitploit.com/search/label/Regular%20Expressions) which are vulnerable to ReDoS give an example malicious string which will cause catastrophic backtracking
Worst-case complexity
This reflects the complexity of the regular expression matcher's backtracking procedure with respect to the length of the entered string. Cubic complexity here means that if the vulnerable part of the string is doubled in length, the execution time should be about 8 times longer (2^3). For exponential ReDoS with starred stars e.g. (a*)*$ a fudge factor is used and the complexity will be greater than 10. For explotability, cubic complexity or higher is typically required unless truly giant strings are allowed as input.
Example
Run regexploit and enter the regular expression v\w*_\w*_\w*$ at the command line. $ regexploit
v\w*_\w*_\w*$
Pattern: v\w*_\w*_\w*$
---
Worst-case complexity: 3 ⭐⭐⭐ (cubic)
Repeated character: [5f:_]
Final character to cause backtracking: [^WORD]
Example: 'v' + '_' * 3456 + '!'
The part \w*_\w*_\w* contains three overlapping repeating groups (\w matches letters, digits and underscores). As showed in the line Repeated character: [5f:_], a long string of _ (0x5f) will match this section in many different ways. The worst-case complexity is 3 as there are 3 infinitely repeating groups. An example to cause ReDoS is given: it consists of the required prefix v, a long string of _ and then a ! (non-word character) to cause backtracking. Not all ReDoSes require a particular character at the end, but in this case, a long string of _ will match the regex successfully and won't backtrack. The line Final character to cause backtracking: [^WORD] shows that a non-matching character (not a word character) is required at the end to prevent matching and cause ReDoS. As another example, install a module version vulnerable to ReDoS such as pip install ua-parser==0.9.0. To scan the installed python modules run regexploit-python-env. Importing ua_parser.user_agent_parser
Vulnerable regex in /somewhere/.env/lib/python3.9/site-packages/ua_parser/user_agent_parser.py #183
Pattern: \bSmartWatch *\( *([^;]+) *; *([^;]+) *;
Context: self.user_agent_re = re.compile(self.pattern)
---
Worst-case complexity: 3 ⭐⭐⭐
Repeated character: [20]
Example: 'SmartWatch(' + ' ' * 3456
Worst-case complexity: 3 ⭐⭐⭐
Repeated character: [20]
Example: 'SmartWatch(0;' + ' ' * 3456
Vulnerable regex in /somewhere/.env/lib/python3.9/site-packages/ua_parser/user_agent_parser.py #183
Pattern: ; *([^;/]+) Build[/ ]Huawei(MT1-U06|[A-Z]+\d+[^\);]+)[^\);]*\)
Context: self.user_agent_re = re.compile(self.pattern)
---
Worst-case complexity: 3 ⭐⭐⭐
Repeated character: [[0-9]]
Example: ';0 Build/HuaweiA' + '0' * 3456
...
For each vulnerable regular expression it prints one or more malicious string to trigger ReDoS. Setting your user agent to ;0 Build/HuaweiA000000000000000... and browsing a website using an old version of ua-parser may cause the server to take a long time to process your request, probably ending in status 502.
Installation
___________________________
@hacking_Attack
@Hacking_Video
Worst-case complexity
This reflects the complexity of the regular expression matcher's backtracking procedure with respect to the length of the entered string. Cubic complexity here means that if the vulnerable part of the string is doubled in length, the execution time should be about 8 times longer (2^3). For exponential ReDoS with starred stars e.g. (a*)*$ a fudge factor is used and the complexity will be greater than 10. For explotability, cubic complexity or higher is typically required unless truly giant strings are allowed as input.
Example
Run regexploit and enter the regular expression v\w*_\w*_\w*$ at the command line. $ regexploit
v\w*_\w*_\w*$
Pattern: v\w*_\w*_\w*$
---
Worst-case complexity: 3 ⭐⭐⭐ (cubic)
Repeated character: [5f:_]
Final character to cause backtracking: [^WORD]
Example: 'v' + '_' * 3456 + '!'
The part \w*_\w*_\w* contains three overlapping repeating groups (\w matches letters, digits and underscores). As showed in the line Repeated character: [5f:_], a long string of _ (0x5f) will match this section in many different ways. The worst-case complexity is 3 as there are 3 infinitely repeating groups. An example to cause ReDoS is given: it consists of the required prefix v, a long string of _ and then a ! (non-word character) to cause backtracking. Not all ReDoSes require a particular character at the end, but in this case, a long string of _ will match the regex successfully and won't backtrack. The line Final character to cause backtracking: [^WORD] shows that a non-matching character (not a word character) is required at the end to prevent matching and cause ReDoS. As another example, install a module version vulnerable to ReDoS such as pip install ua-parser==0.9.0. To scan the installed python modules run regexploit-python-env. Importing ua_parser.user_agent_parser
Vulnerable regex in /somewhere/.env/lib/python3.9/site-packages/ua_parser/user_agent_parser.py #183
Pattern: \bSmartWatch *\( *([^;]+) *; *([^;]+) *;
Context: self.user_agent_re = re.compile(self.pattern)
---
Worst-case complexity: 3 ⭐⭐⭐
Repeated character: [20]
Example: 'SmartWatch(' + ' ' * 3456
Worst-case complexity: 3 ⭐⭐⭐
Repeated character: [20]
Example: 'SmartWatch(0;' + ' ' * 3456
Vulnerable regex in /somewhere/.env/lib/python3.9/site-packages/ua_parser/user_agent_parser.py #183
Pattern: ; *([^;/]+) Build[/ ]Huawei(MT1-U06|[A-Z]+\d+[^\);]+)[^\);]*\)
Context: self.user_agent_re = re.compile(self.pattern)
---
Worst-case complexity: 3 ⭐⭐⭐
Repeated character: [[0-9]]
Example: ';0 Build/HuaweiA' + '0' * 3456
...
For each vulnerable regular expression it prints one or more malicious string to trigger ReDoS. Setting your user agent to ;0 Build/HuaweiA000000000000000... and browsing a website using an old version of ua-parser may cause the server to take a long time to process your request, probably ending in status 502.
Installation
___________________________
@hacking_Attack
@Hacking_Video
KitPloit - PenTest & Hacking Tools
Leading source of security tools, hacking tools, cybersecurity and network security. Learn about new tools and updates in one place.
regexploit-py "my-project/**/*.py" --glob
Javascript / Typescript
This will use the bundled NodeJS package in regexploit/bin/javascript which parses your JavaScript as an AST with eslint (https://github.com/typescript-eslint/typescript-eslint/tree/master/packages/parser) and prints out all regexes. Those regexes are fed into the python ReDoS finder. regexploit-js my-module/my-file.js another/file.js some/folder/
regexploit-js "my-project/node_modules/**/*.js" --glob N.B. there are differences between javascript and python regex parsing so there may be some errors. I'm not sure I want (https://hackernoon.com/the-madness-of-parsing-real-world-javascript-regexps-d9ee336df983) to write a JS regex AST!
Python imports
Search for regexes in all the python modules currently installed in your path / env. This means you can pip install whatever modules you are interested in and they will be analysed. Cpython code is included. regexploit-python-env N.B. this doesn't parse the python code to an AST and will only find regexes compiled automatically on module import. Modules are actually imported, so code in the modules will be executed. This is helpful for finding regexes which are built up from smaller strings on load e.g. CVE-2021-25292 in Pillow (https://github.com/python-pillow/Pillow/commit/3bce145966374dd39ce58a6fc0083f8d1890719c)
JSON / YAML
Yaml support requires pyyaml, which can be installed with pip install regexploit[yaml]. regexploit-json *.json
regexploit-yaml *.yaml
C# (.NET)
regexploit-csharp something.cs
Bugs reported CVE-2020-5243: uap-core (https://github.com/ua-parser/uap-core/security/advisories/GHSA-cmcx-xhr8-3w9p) affecting uap-python, uap-ruby (https://github.com/ua-parser/uap-ruby/security/advisories/GHSA-pcqq-5962-hvcw), etc. (User-Agent header parsing) CVE-2020-8492: cpython's urllib.request (https://github.com/python/cpython/commit/0b297d4ff1c0e4480ad33acae793fbaf4bf015b4) (WWW-Authenticate header parsing) CVE-2021-21236: CairoSVG (https://github.com/advisories/GHSA-hq37-853p-g5cf) (SVG parsing) CVE-2021-21240: httplib2 (https://github.com/httplib2/httplib2/security/advisories/GHSA-93xj-8mrv-444m) (WWW-Authenticate header parsing) CVE-2021-25292: python-pillow (https://github.com/python-pillow/Pillow/commit/3bce145966374dd39ce58a6fc0083f8d1890719c) (PDF parsing) CVE-2021-26813: python-markdown2 (https://github.com/trentm/python-markdown2/pull/387) (Markdown parsing) CVE-2021-27290: npm/ssri (https://doyensec.com/resources/Doyensec_Advisory_ssri_redos.pdf) (SRI parsing) CVE-2021-27291: pygments (https://github.com/pygments/pygments/commit/2e7e8c4a7b318f4032493773732754e418279a14) lexers for ADL, CADL, Ceylon, Evoque, Factor, Logos, Matlab, Octave, ODIN, Scilab & Varnish VCL (Syntax highlighting) CVE-2021-27292: ua-parser-js (https://github.com/faisalman/ua-parser-js/commit/809439e20e273ce0d25c1d04e111dcf6011eb566) (User-Agent header parsing) CVE-2021-27293: RestSharp (https://github.com/restsharp/RestSharp/issues/1556) (JSON deserialisation in a .NET C# package) bpo-38804: cpython's http.cookiejar (https://github.com/python/cpython/pull/17157) (Set-Cookie header parsing) SimpleCrawler (archived) (https://doyensec.com/resources/Doyensec_Advisory_simplecrawler_redos.pdf) (HTML parsing) CVE-2021-28092: is-svg (https://github.com/sindresorhus/is-svg/commit/01f8a087fab8a69c3ac9085fbb16035907ab6a5b) (SVG parsing) nuget.org, NuGetGallery (https://github.com/NuGet/NuGetGallery/commit/25d2d3b32b2d9f0b1ca6e0a105b0210c2c4820f4) and NuGet.Client (https://github.com/NuGet/NuGet.Client/commit/a0671e946ce71dc59def5cc8a67c6457d66f33bf) (Parsing NuGet package IDs) markdown (python) (https://github.com/Python-Markdown/markdown/pull/1130) (Markdown parsing) ansi-html (nodejs) (https://github.com/Tjatse/ansi-html/issues/19) (ANSI parsing) Plus unpublished bugs in a handful of pypi, npm, ruby and nuget packages
Credits
___________________________
@hacking_Attack
@Hacking_Video
Javascript / Typescript
This will use the bundled NodeJS package in regexploit/bin/javascript which parses your JavaScript as an AST with eslint (https://github.com/typescript-eslint/typescript-eslint/tree/master/packages/parser) and prints out all regexes. Those regexes are fed into the python ReDoS finder. regexploit-js my-module/my-file.js another/file.js some/folder/
regexploit-js "my-project/node_modules/**/*.js" --glob N.B. there are differences between javascript and python regex parsing so there may be some errors. I'm not sure I want (https://hackernoon.com/the-madness-of-parsing-real-world-javascript-regexps-d9ee336df983) to write a JS regex AST!
Python imports
Search for regexes in all the python modules currently installed in your path / env. This means you can pip install whatever modules you are interested in and they will be analysed. Cpython code is included. regexploit-python-env N.B. this doesn't parse the python code to an AST and will only find regexes compiled automatically on module import. Modules are actually imported, so code in the modules will be executed. This is helpful for finding regexes which are built up from smaller strings on load e.g. CVE-2021-25292 in Pillow (https://github.com/python-pillow/Pillow/commit/3bce145966374dd39ce58a6fc0083f8d1890719c)
JSON / YAML
Yaml support requires pyyaml, which can be installed with pip install regexploit[yaml]. regexploit-json *.json
regexploit-yaml *.yaml
C# (.NET)
regexploit-csharp something.cs
Bugs reported CVE-2020-5243: uap-core (https://github.com/ua-parser/uap-core/security/advisories/GHSA-cmcx-xhr8-3w9p) affecting uap-python, uap-ruby (https://github.com/ua-parser/uap-ruby/security/advisories/GHSA-pcqq-5962-hvcw), etc. (User-Agent header parsing) CVE-2020-8492: cpython's urllib.request (https://github.com/python/cpython/commit/0b297d4ff1c0e4480ad33acae793fbaf4bf015b4) (WWW-Authenticate header parsing) CVE-2021-21236: CairoSVG (https://github.com/advisories/GHSA-hq37-853p-g5cf) (SVG parsing) CVE-2021-21240: httplib2 (https://github.com/httplib2/httplib2/security/advisories/GHSA-93xj-8mrv-444m) (WWW-Authenticate header parsing) CVE-2021-25292: python-pillow (https://github.com/python-pillow/Pillow/commit/3bce145966374dd39ce58a6fc0083f8d1890719c) (PDF parsing) CVE-2021-26813: python-markdown2 (https://github.com/trentm/python-markdown2/pull/387) (Markdown parsing) CVE-2021-27290: npm/ssri (https://doyensec.com/resources/Doyensec_Advisory_ssri_redos.pdf) (SRI parsing) CVE-2021-27291: pygments (https://github.com/pygments/pygments/commit/2e7e8c4a7b318f4032493773732754e418279a14) lexers for ADL, CADL, Ceylon, Evoque, Factor, Logos, Matlab, Octave, ODIN, Scilab & Varnish VCL (Syntax highlighting) CVE-2021-27292: ua-parser-js (https://github.com/faisalman/ua-parser-js/commit/809439e20e273ce0d25c1d04e111dcf6011eb566) (User-Agent header parsing) CVE-2021-27293: RestSharp (https://github.com/restsharp/RestSharp/issues/1556) (JSON deserialisation in a .NET C# package) bpo-38804: cpython's http.cookiejar (https://github.com/python/cpython/pull/17157) (Set-Cookie header parsing) SimpleCrawler (archived) (https://doyensec.com/resources/Doyensec_Advisory_simplecrawler_redos.pdf) (HTML parsing) CVE-2021-28092: is-svg (https://github.com/sindresorhus/is-svg/commit/01f8a087fab8a69c3ac9085fbb16035907ab6a5b) (SVG parsing) nuget.org, NuGetGallery (https://github.com/NuGet/NuGetGallery/commit/25d2d3b32b2d9f0b1ca6e0a105b0210c2c4820f4) and NuGet.Client (https://github.com/NuGet/NuGet.Client/commit/a0671e946ce71dc59def5cc8a67c6457d66f33bf) (Parsing NuGet package IDs) markdown (python) (https://github.com/Python-Markdown/markdown/pull/1130) (Markdown parsing) ansi-html (nodejs) (https://github.com/Tjatse/ansi-html/issues/19) (ANSI parsing) Plus unpublished bugs in a handful of pypi, npm, ruby and nuget packages
Credits
___________________________
@hacking_Attack
@Hacking_Video
GitHub
typescript-eslint/packages/parser at main · typescript-eslint/typescript-eslint
:sparkles: Monorepo for all the tooling which enables ESLint to support TypeScript - typescript-eslint/packages/parser at main · typescript-eslint/typescript-eslint
This tool has been created by Ben Caller of Doyensec LLC (https://www.doyensec.com/) during research time.
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Doyensec
Doyensec - Web and Mobile Application Security Experts
Doyensec provides expert-level Web and Mobile Application Security Services.
Download Regexploit (https://github.com/doyensec/regexploit)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
GitHub
GitHub - doyensec/regexploit: Find regular expressions which are vulnerable to ReDoS (Regular Expression Denial of Service)
Find regular expressions which are vulnerable to ReDoS (Regular Expression Denial of Service) - doyensec/regexploit
Hacking the dlink DIR-615 for fun and no profit Part 2: CVE-2020–10215
https://noob3xploiter.medium.com/hacking-the-dlink-dir-615-for-fun-and-no-profit-part-2-cve-2020-10215-586204d42bba?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://noob3xploiter.medium.com/hacking-the-dlink-dir-615-for-fun-and-no-profit-part-2-cve-2020-10215-586204d42bba?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
Hacking the dlink DIR-615 for fun and no profit Part 2: CVE-2020–10215
Hi. This is my second writeup on my hacking the dlink dir-615 series as i try to get my first cve. I found more vulns and will also make a…