PHP Developers Network

A community of PHP developers offering assistance, advice, discussion, and friendship.
 
Loading
It is currently Thu Oct 17, 2019 6:35 am

All times are UTC - 5 hours




Post new topic Reply to topic  [ 3 posts ] 
Author Message
 Post subject: Breakdown of attack URL
PostPosted: Thu Nov 03, 2011 10:41 am 
Offline
Forum Newbie

Joined: Thu Mar 18, 2010 3:10 pm
Posts: 3
I want a better understanding of what I'm looking at when an attack is reported to me. I'm hoping you guys can help me out by breaking down a URL for me and sending me to the correct sources to get more information. Example URL:

Syntax: [ Download ] [ Hide ]
/MFR1.HTM?view=Panasonic_reviews%22%20onmousedown=%22ct(this,%20'http%3A%2F%2Fwww.imaging-resource.com%2FMFR1.HTM%3Fview%3DPanasonic_reviews','21','3','%2F%2F%2F%3Fpage%3Dpanasonic','',%20'00f08b68183ac8e8fc131147ad2015c66e310dec38043fbb8cc3',%200)/?page=../../../../../../../../../../../../..//proc/self/environ%0000 HTTP Response 200


My understanding was that a server responds with 200 when the request succeeded. I'm guessing the above URL didn't break anything as far as the server was concerned so it sent a 200 repsonse. And if I load this in the browser, it continued to load the page as expected. So what was this URL trying to do exactly? Thanks!


Top
 Profile  
 
PostPosted: Thu Nov 03, 2011 5:41 pm 
Offline
DevNet Resident
User avatar

Joined: Sun Sep 03, 2006 5:19 am
Posts: 1579
Location: Sofia, Bulgaria
The last part looks like an attempt to elevate a LFI into code execution as /proc/self/environ, can control attacker-controlled strings.
The javascript looks like an attempt at XSS. Why try both at the same time is a puzzle. Maybe it's a misbehaving automated attack script?


Top
 Profile  
 
PostPosted: Fri Nov 04, 2011 2:34 am 
Offline
Forum Regular
User avatar

Joined: Wed Mar 05, 2008 11:23 pm
Posts: 732
Location: Sunriver, OR
Decoded
Syntax: [ Download ] [ Hide ]
/MFR1.HTM?view=Panasonic_reviews" onmousedown="ct(this, 'http://www.imaging-resource.com/MFR1.HTM?view=Panasonic_reviews','21','3','///?page=panasonic','', '00f08b68183ac8e8fc131147ad2015c66e310dec38043fbb8cc3', 0)/?page=../../../../../../../../../../../../..//proc/self/environ00 HTTP Response 200


Looks like a session id, or cookie data?


Top
 Profile  
 
Display posts from previous:  Sort by  
Post new topic Reply to topic  [ 3 posts ] 

All times are UTC - 5 hours


Who is online

Users browsing this forum: No registered users and 5 guests


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Jump to:  
Powered by phpBB® Forum Software © phpBB Group