{"id":324,"date":"2012-10-31T13:14:52","date_gmt":"2012-10-31T20:14:52","guid":{"rendered":"http:\/\/seanmurphree.com\/blog\/?p=324"},"modified":"2012-10-31T13:15:00","modified_gmt":"2012-10-31T20:15:00","slug":"natas-level-7-user-input-and-unsafe-includes","status":"publish","type":"post","link":"https:\/\/seanmurphree.com\/blog\/?p=324","title":{"rendered":"Natas Level 7 &#8211; User Input and Unsafe Includes"},"content":{"rendered":"<p>In this post we&#8217;re going to be looking at Level 7 of the Natas wargame from Over The Wire.<\/p>\n<h2>What&#8217;s Going On?<\/h2>\n<p>Upon logging in, we are presented with a page with two links. \u00a0Let&#8217;s view the page&#8217;s source first. \u00a0Upon doing this, we get a comment hint that the password for the next level is located in the file at\u00a0\/etc\/natas_webpass\/natas8. \u00a0We also see that the two links are links to the current page with a value assigned to the &#8220;page&#8221; variable. \u00a0The value is passed via the URL and GET style arguments, making it easy to edit. \u00a0If we go back and click on either link we can see some text on each page.<\/p>\n<p>This site navigation option of taking a page name as a variable has many positive sides from a web-programmer&#8217;s point of view. \u00a0However, let&#8217;s look at how it is implemented in this page. \u00a0The simplest thing to conclude would be a simple include($_GET[&#8216;page&#8217;]); call. \u00a0This would, in the example of home and about, simply get files called home or about. \u00a0Let&#8217;s check this idea by requesting those URLs ourselves and checking they exist and match what we saw earlier on those pages. \u00a0We should find\u00a0<a href=\"http:\/\/natas7.natas.labs.overthewire.org\/home\">http:\/\/natas7.natas.labs.overthewire.org\/home<\/a>\u00a0and\u00a0<a href=\"http:\/\/natas7.natas.labs.overthewire.org\/about\">http:\/\/natas7.natas.labs.overthewire.org\/about<\/a>\u00a0both exist, and have our expected values. \u00a0Thus, let&#8217;s make the assumption we figured out how the include works. \u00a0How can we use this to get the password to the next level?<\/p>\n<h2>Exploit<\/h2>\n<p>Since the include file is specified via the page variable, let&#8217;s think about what we can supply as the page variable to get the password to the next level. \u00a0As we saw in the comment hint, the password is stored in the file\u00a0\/etc\/natas_webpass\/natas8. \u00a0So, let&#8217;s try supplying that as the value of the page variable! \u00a0Requesting the page,\u00a0<a href=\"http:\/\/natas7.natas.labs.overthewire.org\/index.php?page=\/etc\/natas_webpass\/natas8\">http:\/\/natas7.natas.labs.overthewire.org\/index.php?page=\/etc\/natas_webpass\/natas8<\/a>, we get a response with the password for level 8.<\/p>\n<h2>So What?<\/h2>\n<p>So what!? \u00a0So don&#8217;t blindly let users access files or provide absolute and full file locations! \u00a0Use some input sanitation! Start from the current directory (string concat &#8220;.\/&#8221;.$sanitizedUserInput). \u00a0Append file types! \u00a0There are various options at making this safer, but having un-sanitized user provided data act as absolute file paths on the server, is not a good idea.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>In this post we&#8217;re going to be looking at Level 7 of the Natas wargame from Over The Wire. What&#8217;s Going On? Upon logging in, we are presented with a page with two links. \u00a0Let&#8217;s view the page&#8217;s source first. &hellip; <a href=\"https:\/\/seanmurphree.com\/blog\/?p=324\">Continue reading <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":[],"categories":[36,35,4],"tags":[],"_links":{"self":[{"href":"https:\/\/seanmurphree.com\/blog\/index.php?rest_route=\/wp\/v2\/posts\/324"}],"collection":[{"href":"https:\/\/seanmurphree.com\/blog\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/seanmurphree.com\/blog\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/seanmurphree.com\/blog\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/seanmurphree.com\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=324"}],"version-history":[{"count":3,"href":"https:\/\/seanmurphree.com\/blog\/index.php?rest_route=\/wp\/v2\/posts\/324\/revisions"}],"predecessor-version":[{"id":327,"href":"https:\/\/seanmurphree.com\/blog\/index.php?rest_route=\/wp\/v2\/posts\/324\/revisions\/327"}],"wp:attachment":[{"href":"https:\/\/seanmurphree.com\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=324"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/seanmurphree.com\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=324"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/seanmurphree.com\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=324"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}