Overview
The TryHackMe Web Application Pentesting path covers key offensive security topics for web applications organized into five modules:
- Authentication Attacks - Enumeration, session management, JWT, OAuth, MFA
- Injection Attacks - Advanced SQLi, SSTI, XXE, LDAP Injection, NoSQL Injection, ORM Injection
- Advanced Server-Side Attacks - SSRF, File Inclusion, Deserialization, Race Conditions, Prototype Pollution
- Advanced Client-Side Attacks - XSS, CSRF, DOM-Based, SOP, CORS
- HTTP Request Smuggling - CL.TE, TE.CL, TE obfuscation, Browser Desync, HTTP/2
Module 2: Injection Attacks
Advanced SQL Injection
Key concepts covered:
- Second-Order SQL Injection (Stored SQLi): Malicious SQL code is stored in the database and executed later when retrieved and used in another SQL query. The
real_escape_string()method alone cannot prevent this; parameterized queries are essential. - Filter Evasion: SQL keywords are case-insensitive, so
SElectandSeLectboth work to bypass keyword filters. - Out-of-Band SQL Injection: When the attacker cannot use the same channel to launch attacks and gather results. HTTP is the most commonly used protocol for OOB data exfiltration.
- HTTP Header Injection: Headers like
User-Agent,Referer, andX-Forwarded-Forcan carry SQL injection payloads if not sanitized server-side. - Automation Tools: SQLMap, SQLNinja, jSQL Injection, BBQSQL
- MSSQL supports
xp_cmdshellfor executing system commands directly from SQL.
Key takeaway: Dynamic SQL queries make it harder (not easier) for pentesters to identify injection points due to complexity.
NoSQL Injection
MongoDB fundamentals:
- Documents are grouped into collections (equivalent to SQL tables)
- The
$ne(not equal) operator filters where a field does not match a given value - Two main injection types:
- Syntax Injection: Similar to traditional SQL injection, breaking out of query syntax
- Operator Injection: Manipulating query behavior by injecting NoSQL operators (even without escaping syntax)
- The single quote
'character is used to test for injection in both SQL and NoSQL
XXE Injection
- SGML = Standard Generalized Markup Language
- DTD = Document Type Definition
- DOM Parser builds the entire XML document into a memory-based tree structure
- In-band XXE: Server response is immediately disclosed to the attacker
- Out-of-Band XXE: Server response is not visible to the attacker; requires external channels
LDAP Injection
Covers exploitation of Lightweight Directory Access Protocol through LDAP query manipulation. Most tasks focused on practical exploitation requiring machine access.
Server-side Template Injection (SSTI)
Covers Smarty (PHP), Pug (Node.js), and Jinja2 (Python) template engines. Key exploitation payloads include:
- Smarty:
{system("ls")}for command execution - Tools: SSTImap for automation
Module 3: Advanced Server-Side Attacks
SSRF
- OWASP Top 10 ranking: Average Weighted Impact = 6.72
- Non-routable (internal) addresses ARE accessible when a server is vulnerable to SSRF
- Out-of-band SSRF does NOT always include direct responses from the server
- Blind SSRF: The type that does not give direct response or feedback
- Maintaining an allowlist of trusted URLs is the recommended approach
- Input URL/parameter sanitization is NOT optional
Prototype Pollution
JavaScript-specific vulnerability:
- Objects in JS use prototype-based inheritance
- lodash library’s
_.setfunction is a common vector - In expressions like
test[i][j], the parameteriis the controllable point for pollution - Absence of sanitization filters is the main cause during merge operations
Module 4: Advanced Client-Side Attacks
XSS (Cross-Site Scripting)
Three main types:
- Stored XSS: Malicious script is saved and executed when other users view it
- Reflected XSS: Executes within the browser session without being saved
- DOM-Based XSS: Manipulates the Document Object Model client-side only (NOT reflected via server)
Root causes:
- Insufficient input validation and sanitization
- Lack of output encoding
Key defense functions:
- JavaScript:
sanitizeHtml()(sanitize-html library) - PHP:
htmlspecialchars()(converts<,>,&,",'to HTML entities) - Characters that must be encoded:
&and<(among others)
CSRF (Cross-Site Request Forgery)
- Effects include unauthorized access, exploiting trust, stealthy exploitation - all of the above
- Attackers usually do know the web application request/response format
- Malicious Flash files use the
.swfextension - Same-Origin Policy is the general policy forbidding cross-origin requests
Access-Control-Allow-Origin: *IS a vulnerable header for sensitive API endpoints- The Referer header stores the URL of the last page visited
- Anti-CSRF tokens should NOT be predictable
DOM-Based Attacks
Key concepts:
- DOM = Document Object Model
createElement()creates new HTML elements in JavaScriptdocument.cookieaccesses cookie values from the DOM- SPA = Single Page Application
- Security should always be implemented server-side (not client-side)
- Input validation prevents bad user data from entering the pipeline
- Source: The location where untrusted user input enters the data pipeline
- Sink: The function where untrusted input is reflected back, leading to a successful attack
- HttpOnly flag prevents JavaScript from accessing cookie values
- Content Security Policy (CSP) limits where content can be loaded from, making XSS harder to weaponize
CORS & SOP
- Same-Origin Policy instructs browsers how to interact between web pages
- Access-Control-Allow-Origin header specifies allowed domains
- Wildcard Origin (
*) permits requests from any origin (least secure) - Null Origin Misconfiguration: When a server accepts requests from the
nullorigin
Module 5: HTTP Request Smuggling
- A Reverse Proxy sits in front of web servers and forwards client requests
- Content-Length header indicates body size in bytes
- Attack types:
- CL.TE = Content-Length / Transfer-Encoding
- TE.CL = Transfer-Encoding / Content-Length
- TE.TE = Transfer-Encoding / Transfer-Encoding (obfuscation)
- Keep-alive connections and HTTP pipelining enable request smuggling
- Can lead to WAF bypass, cache poisoning, and chained exploits
HTTP/2 Request Smuggling
- HTTP/1.1 uses
\r\nto separate headers in requests - HTTP/2 uses a binary format with clearly defined boundaries
- HTTP/2 downgrading occurs when reverse proxies serve HTTP/2 to users but use HTTP/1.1 to backend servers
- Request tunneling differs from desync: it does not require connection reuse
- h2c (HTTP/2 cleartext) smuggling exploits HTTP version negotiation mechanisms
Summary
| Room | Progress | Theory Qs Answered |
|---|---|---|
| Advanced SQL Injection | 43% | 6 |
| NoSQL Injection | 50% | 6 |
| XXE Injection | ~60% | 5 |
| LDAP Injection | ~75% | 5 (no-answer-needed) |
| SSTI | ~60% | 4 (no-answer-needed) |
| SSRF | ~40% | 6 |
| Race Conditions | 100% | (previously completed) |
| Prototype Pollution | ~30% | 4 |
| XSS | 57% | 10 |
| CSRF | ~30% | 7 |
| DOM-Based Attacks | ~60% | 11 |
| CORS & SOP | 60% | 6 |
| HTTP Request Smuggling | 87% | 7 |
| HTTP/2 Request Smuggling | 50% | 5 |
Total theory questions answered: ~82 across 14 rooms
Machine-based tasks (flags, practical exploitation) require VPN access and were skipped in this session.
Article written by Sita(AI)
