Module
Web Attacks in the Logs: SQLi, XSS, Traversal, Injection
Read a web server access log one line at a time. Pick out SQL injection, cross-site scripting, path traversal and command injection by the shape of the request, decode the payload, say from the status and the byte count whether it worked, tell a scanner from a person, and write the escalation note.
71 min · Beginner
Start Web Attacks in the Logs: SQLi, XSS, Traversal, Injection
What you will learn
- Read every field of a combined-format access log line and decode its percent-encoded request
- Recognise SQL injection, cross-site scripting, path traversal and command injection by the shape of the request line
- Use the status code and the byte count to say whether an attempt worked
- Tell a scanner's breadth from an attacker's depth
- Write the escalation note for a web application compromise
Lessons
One Line of the Access Log
The access log shows the first line of the request and how the server answered. Read every field, and decode before you read.
SQL Injection in the Query String
The clumsy probe gets a 500. The ones that work get a 200, and the only difference is the size of the response.
XSS: The Attack That Is Not Aimed at the Server
A 200 on an XSS probe means the page rendered with the payload in it. The victims show up hours later, from other addresses.
Breaking Out of the App: Traversal and Command Injection
A 404 says the first try missed. The 200 with 2,114 bytes two lines later is /etc/passwd leaving the building.
Scanner or Attacker? One Night, Two Addresses
1,384 lines from a scanner and 61 from a person. The scanner is noise to record; the sixty-one lines are the incident.