{"id":307,"date":"2012-10-31T11:17:36","date_gmt":"2012-10-31T18:17:36","guid":{"rendered":"http:\/\/seanmurphree.com\/blog\/?p=307"},"modified":"2012-10-31T11:51:46","modified_gmt":"2012-10-31T18:51:46","slug":"natas-level-4-http-request-forging","status":"publish","type":"post","link":"https:\/\/seanmurphree.com\/blog\/?p=307","title":{"rendered":"Natas Level 4 &#8211; HTTP Request Forging"},"content":{"rendered":"<p>Let&#8217;s look at Natas Level 4 in this post. \u00a0To get started, point your browser over to the level 4 website,\u00a0<a href=\"http:\/\/natas4.natas.labs.overthewire.org\/\">http:\/\/natas4.natas.labs.overthewire.org\/<\/a>, and log in with the password from the previous level.<\/p>\n<h2>What&#8217;s Going On?<\/h2>\n<p>Upon logging in we get a message that access is disallowed and that it will only be granted to people coming from\u00a0http:\/\/natas5.natas.labs.overthewire.org\/. \u00a0Well that&#8217;s interesting, how are we supposed to come from level 5? \u00a0Well, for this we&#8217;re going to look into how HTTP requests work.<\/p>\n<p>First, it should be clear enough to say that HTTP requests are generated by a client and sent to an HTTP server. \u00a0This server processes the request and sends a response back to the client. \u00a0In browsing the web, this happens through our web-browser and we are usually unaware of it. \u00a0That is, until we get messages back from the server saying things like HTTP Error 404, File Not Found.<\/p>\n<p>So, how does a website know things like where a person is coming from when they are requesting a page? \u00a0Well, since HTTP is a stateless protocol, it&#8217;s supplied in the clients HTTP request. \u00a0This attribute of the HTTP request is called the &#8220;referer&#8221;, and is usually set by your browser when you follow a link. \u00a0Thus, since it&#8217;s supplied by the user, it is something the user can fake! \u00a0Let&#8217;s attempt to do that for this level.<\/p>\n<h2>Exploit<\/h2>\n<p>In this level we&#8217;re going to switch from using the browser now, to using the command line! \u00a0We&#8217;re going to make simple use of the cURL program. \u00a0This is standard on many Linux distributions and is also available for Windows. \u00a0cURL lets us request a curl via the command line, as well as supply changes to the HTTP request based on command line arguments. \u00a0Today we&#8217;ll be making use of the &#8211;user and &#8211;referer arguments. \u00a0The user argument lets us specify the username and password to log in to the natas level4 web page. \u00a0The referer argument lets us specify our own URL to act as the referer of our HTTP request. \u00a0Putting it all together we should get:<\/p>\n<blockquote><p>curl &#8211;user natas4:PasswordForNatas4GoesHere &#8211;referer http:\/\/natas5.natas.labs.overthewire.org\/ http:\/\/natas4.natas.labs.overthewire.org\/<\/p><\/blockquote>\n<p>In response we should see a print out of the HTML from the request, and if done correctly this code includes the password for natas level 5!<\/p>\n<h2>So What?<\/h2>\n<p>This level is a reminder about the statelessness of HTTP and as such the unverified nature of HTTP request attributes. \u00a0HTTP requests are under the full control of the user\/crafter, and as such should be best treated as being from a malicious request creator, not an average user.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Let&#8217;s look at Natas Level 4 in this post. \u00a0To get started, point your browser over to the level 4 website,\u00a0http:\/\/natas4.natas.labs.overthewire.org\/, and log in with the password from the previous level. What&#8217;s Going On? Upon logging in we get a &hellip; <a href=\"https:\/\/seanmurphree.com\/blog\/?p=307\">Continue reading <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":[],"categories":[36,35,4],"tags":[],"_links":{"self":[{"href":"https:\/\/seanmurphree.com\/blog\/index.php?rest_route=\/wp\/v2\/posts\/307"}],"collection":[{"href":"https:\/\/seanmurphree.com\/blog\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/seanmurphree.com\/blog\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/seanmurphree.com\/blog\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/seanmurphree.com\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=307"}],"version-history":[{"count":2,"href":"https:\/\/seanmurphree.com\/blog\/index.php?rest_route=\/wp\/v2\/posts\/307\/revisions"}],"predecessor-version":[{"id":314,"href":"https:\/\/seanmurphree.com\/blog\/index.php?rest_route=\/wp\/v2\/posts\/307\/revisions\/314"}],"wp:attachment":[{"href":"https:\/\/seanmurphree.com\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=307"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/seanmurphree.com\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=307"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/seanmurphree.com\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=307"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}