diff --git a/src/pentesting-web/login-bypass/README.md b/src/pentesting-web/login-bypass/README.md index 67a8801e061..1941e9bb3eb 100644 --- a/src/pentesting-web/login-bypass/README.md +++ b/src/pentesting-web/login-bypass/README.md @@ -88,6 +88,35 @@ If the page has "**Remember Me**" functionality check how is it implemented and Pages usually redirect users after login. Check whether the destination can be altered to cause an [**Open Redirect**](../open-redirect.md), especially when authorization codes or other secrets could be sent through the redirect flow. +#### ASP.NET execution after redirect (EAR) + +Do not assume that a `30x` response means the protected ASP.NET page stopped processing. In **execution after redirect** (CWE-698), the application recognizes an unauthenticated request and sets a redirect, but protected rendering or actions still run in the original response.[[5]](#references)[[8]](#references) + +The high-risk ASP.NET pattern is `Response.Redirect(url, false)` followed by `HttpApplication.CompleteRequest()`. The `false` `endResponse` argument explicitly avoids terminating the current page, while `CompleteRequest()` advances the ASP.NET HTTP pipeline toward `EndRequest`; it does **not** abort the current call stack or guarantee that later page-lifecycle callbacks and rendering cannot run. A `return` after the helper only exits that method.[[5]](#references)[[6]](#references)[[7]](#references) + +```csharp +if (!IsAuthenticated()) +{ + Response.Redirect("/login.aspx", false); + Context.ApplicationInstance.CompleteRequest(); + return; +} +``` + +Test the raw response with redirect following disabled. Compare status, `Location`, body length, and body markers against a normal redirect; inspect whether protected HTML, hidden ASP.NET form fields, secrets, or action results appear after an `Object moved` page. If authorized for active validation, replay the exposed form/action directly rather than merely rendering untrusted response HTML.[[5]](#references) + +```bash +curl -kisS --max-redirs 0 https://target.example/protected.aspx \ + -o /tmp/response.txt +grep -Ei 'HTTP/|Location:|Content-Length:|__VIEWSTATE|Object moved' /tmp/response.txt +``` + +For source or decompiled-code review, search for `Redirect(..., false)`, wrappers combining `Redirect` with `CompleteRequest`, and authentication checks inside `Page_Load`, `Page_Init`, or event handlers. Trace the **whole page lifecycle** and independently authorize every state-changing handler; a redirect is navigation, not an authorization boundary.[[5]](#references)[[6]](#references)[[7]](#references) + +A useful exploitation chain is **EAR → configuration access → unsafe upload destination**. A path check that only creates and deletes a test file proves writability, not that the destination is an approved share or non-executable directory. If configuration accepts an IIS webroot, also test secondary ingestion paths: an ordinary upload may randomize names and remove extensions while automatic archive extraction restores attacker-controlled entry names such as `shell.aspx`. See [Zip/Tar File Automatically decompressed Upload](../file-upload/README.md#ziptar-file-automatically-decompressed-upload), [Archive Extraction Path Traversal](../../generic-hacking/archive-extraction-path-traversal.md), and [IIS writable-webroot execution](../../network-services-pentesting/pentesting-web/iis-internet-information-services.md#writable-webroot--aspx-command-shell).[[5]](#references) + +For a non-destructive Progress ShareFile check, watchTowr's detector requests `/ConfigService/Admin.aspx` without following the redirect and flags the vulnerable behavior when it receives `302` plus a response body larger than 10,000 characters; it deliberately does not exercise the upload/RCE stage.[[9]](#references) + ### Client-side authentication & authorization bypass in SPAs Some applications only protect routes/actions in the **frontend** (route guards, hidden buttons, `localStorage` / `sessionStorage`, feature flags, or JSON fields such as `role`, `groups`, `is_active`, `PluginId`, `TimeoutStatus`). If the **backend APIs don't re-check authentication and authorization**, you can often unlock the whole UI or perform the action directly.[[2]](#references) @@ -122,5 +151,10 @@ Common patterns: - [2] [Client-side Authentication Bypass](https://kuldeep.io/posts/client-side-authentication-bypass/) - [3] [OWASP Authentication Cheat Sheet](https://cheatsheetseries.owasp.org/cheatsheets/Authentication_Cheat_Sheet.html) - [4] [MDN - HTML `autocomplete` attribute](https://developer.mozilla.org/en-US/docs/Web/HTML/Attributes/autocomplete) +- [5] [watchTowr Labs - Progress ShareFile pre-authentication RCE chain](https://labs.watchtowr.com/youre-not-supposed-to-sharefile-with-everyone-progress-sharefile-pre-auth-rce-chain-cve-2026-2699-cve-2026-2701/) +- [6] [Microsoft Learn - `HttpResponse.Redirect` method](https://learn.microsoft.com/en-us/dotnet/api/system.web.httpresponse.redirect?view=netframework-4.8.1) +- [7] [Microsoft Learn - `HttpApplication.CompleteRequest` method](https://learn.microsoft.com/en-us/dotnet/api/system.web.httpapplication.completerequest?view=netframework-4.8.1) +- [8] [MITRE CWE-698 - Execution After Redirect](https://cwe.mitre.org/data/definitions/698.html) +- [9] [watchTowr ShareFile CVE-2026-2699 Detection Artifact Generator](https://github.com/watchtowrlabs/watchTowr-vs-Progress-ShareFile-CVE-2026-2699) {{#include ../../banners/hacktricks-training.md}}