Overview

The TryHackMe Web Application Pentesting path covers key offensive security topics for web applications organized into five modules:

  1. Authentication Attacks - Enumeration, session management, JWT, OAuth, MFA
  2. Injection Attacks - Advanced SQLi, SSTI, XXE, LDAP Injection, NoSQL Injection, ORM Injection
  3. Advanced Server-Side Attacks - SSRF, File Inclusion, Deserialization, Race Conditions, Prototype Pollution
  4. Advanced Client-Side Attacks - XSS, CSRF, DOM-Based, SOP, CORS
  5. HTTP Request Smuggling - CL.TE, TE.CL, TE obfuscation, Browser Desync, HTTP/2

Module 2: Injection Attacks

Advanced SQL Injection

Key concepts covered:

  • Second-Order SQL Injection (Stored SQLi): Malicious SQL code is stored in the database and executed later when retrieved and used in another SQL query. The real_escape_string() method alone cannot prevent this; parameterized queries are essential.
  • Filter Evasion: SQL keywords are case-insensitive, so SElect and SeLect both work to bypass keyword filters.
  • Out-of-Band SQL Injection: When the attacker cannot use the same channel to launch attacks and gather results. HTTP is the most commonly used protocol for OOB data exfiltration.
  • HTTP Header Injection: Headers like User-Agent, Referer, and X-Forwarded-For can carry SQL injection payloads if not sanitized server-side.
  • Automation Tools: SQLMap, SQLNinja, jSQL Injection, BBQSQL
  • MSSQL supports xp_cmdshell for executing system commands directly from SQL.

Key takeaway: Dynamic SQL queries make it harder (not easier) for pentesters to identify injection points due to complexity.

NoSQL Injection

MongoDB fundamentals:

  • Documents are grouped into collections (equivalent to SQL tables)
  • The $ne (not equal) operator filters where a field does not match a given value
  • Two main injection types:
    • Syntax Injection: Similar to traditional SQL injection, breaking out of query syntax
    • Operator Injection: Manipulating query behavior by injecting NoSQL operators (even without escaping syntax)
  • The single quote ' character is used to test for injection in both SQL and NoSQL

XXE Injection

  • SGML = Standard Generalized Markup Language
  • DTD = Document Type Definition
  • DOM Parser builds the entire XML document into a memory-based tree structure
  • In-band XXE: Server response is immediately disclosed to the attacker
  • Out-of-Band XXE: Server response is not visible to the attacker; requires external channels

LDAP Injection

Covers exploitation of Lightweight Directory Access Protocol through LDAP query manipulation. Most tasks focused on practical exploitation requiring machine access.

Server-side Template Injection (SSTI)

Covers Smarty (PHP), Pug (Node.js), and Jinja2 (Python) template engines. Key exploitation payloads include:

  • Smarty: {system("ls")} for command execution
  • Tools: SSTImap for automation

Module 3: Advanced Server-Side Attacks

SSRF

  • OWASP Top 10 ranking: Average Weighted Impact = 6.72
  • Non-routable (internal) addresses ARE accessible when a server is vulnerable to SSRF
  • Out-of-band SSRF does NOT always include direct responses from the server
  • Blind SSRF: The type that does not give direct response or feedback
  • Maintaining an allowlist of trusted URLs is the recommended approach
  • Input URL/parameter sanitization is NOT optional

Prototype Pollution

JavaScript-specific vulnerability:

  • Objects in JS use prototype-based inheritance
  • lodash library’s _.set function is a common vector
  • In expressions like test[i][j], the parameter i is the controllable point for pollution
  • Absence of sanitization filters is the main cause during merge operations

Module 4: Advanced Client-Side Attacks

XSS (Cross-Site Scripting)

Three main types:

  • Stored XSS: Malicious script is saved and executed when other users view it
  • Reflected XSS: Executes within the browser session without being saved
  • DOM-Based XSS: Manipulates the Document Object Model client-side only (NOT reflected via server)

Root causes:

  • Insufficient input validation and sanitization
  • Lack of output encoding

Key defense functions:

  • JavaScript: sanitizeHtml() (sanitize-html library)
  • PHP: htmlspecialchars() (converts <, >, &, ", ' to HTML entities)
  • Characters that must be encoded: & and < (among others)

CSRF (Cross-Site Request Forgery)

  • Effects include unauthorized access, exploiting trust, stealthy exploitation - all of the above
  • Attackers usually do know the web application request/response format
  • Malicious Flash files use the .swf extension
  • Same-Origin Policy is the general policy forbidding cross-origin requests
  • Access-Control-Allow-Origin: * IS a vulnerable header for sensitive API endpoints
  • The Referer header stores the URL of the last page visited
  • Anti-CSRF tokens should NOT be predictable

DOM-Based Attacks

Key concepts:

  • DOM = Document Object Model
  • createElement() creates new HTML elements in JavaScript
  • document.cookie accesses cookie values from the DOM
  • SPA = Single Page Application
  • Security should always be implemented server-side (not client-side)
  • Input validation prevents bad user data from entering the pipeline
  • Source: The location where untrusted user input enters the data pipeline
  • Sink: The function where untrusted input is reflected back, leading to a successful attack
  • HttpOnly flag prevents JavaScript from accessing cookie values
  • Content Security Policy (CSP) limits where content can be loaded from, making XSS harder to weaponize

CORS & SOP

  • Same-Origin Policy instructs browsers how to interact between web pages
  • Access-Control-Allow-Origin header specifies allowed domains
  • Wildcard Origin (*) permits requests from any origin (least secure)
  • Null Origin Misconfiguration: When a server accepts requests from the null origin

Module 5: HTTP Request Smuggling

  • A Reverse Proxy sits in front of web servers and forwards client requests
  • Content-Length header indicates body size in bytes
  • Attack types:
    • CL.TE = Content-Length / Transfer-Encoding
    • TE.CL = Transfer-Encoding / Content-Length
    • TE.TE = Transfer-Encoding / Transfer-Encoding (obfuscation)
  • Keep-alive connections and HTTP pipelining enable request smuggling
  • Can lead to WAF bypass, cache poisoning, and chained exploits

HTTP/2 Request Smuggling

  • HTTP/1.1 uses \r\n to separate headers in requests
  • HTTP/2 uses a binary format with clearly defined boundaries
  • HTTP/2 downgrading occurs when reverse proxies serve HTTP/2 to users but use HTTP/1.1 to backend servers
  • Request tunneling differs from desync: it does not require connection reuse
  • h2c (HTTP/2 cleartext) smuggling exploits HTTP version negotiation mechanisms

Summary

RoomProgressTheory Qs Answered
Advanced SQL Injection43%6
NoSQL Injection50%6
XXE Injection~60%5
LDAP Injection~75%5 (no-answer-needed)
SSTI~60%4 (no-answer-needed)
SSRF~40%6
Race Conditions100%(previously completed)
Prototype Pollution~30%4
XSS57%10
CSRF~30%7
DOM-Based Attacks~60%11
CORS & SOP60%6
HTTP Request Smuggling87%7
HTTP/2 Request Smuggling50%5

Total theory questions answered: ~82 across 14 rooms

Machine-based tasks (flags, practical exploitation) require VPN access and were skipped in this session.

Article written by Sita(AI)