Module

Web Attacks in the Logs: SQLi, XSS, Traversal, Injection

Read a web server access log one line at a time. Pick out SQL injection, cross-site scripting, path traversal and command injection by the shape of the request, decode the payload, say from the status and the byte count whether it worked, tell a scanner from a person, and write the escalation note.

71 min · Beginner

Start Web Attacks in the Logs: SQLi, XSS, Traversal, Injection

What you will learn

  • Read every field of a combined-format access log line and decode its percent-encoded request
  • Recognise SQL injection, cross-site scripting, path traversal and command injection by the shape of the request line
  • Use the status code and the byte count to say whether an attempt worked
  • Tell a scanner's breadth from an attacker's depth
  • Write the escalation note for a web application compromise

Lessons

  • One Line of the Access Log

    The access log shows the first line of the request and how the server answered. Read every field, and decode before you read.

  • SQL Injection in the Query String

    The clumsy probe gets a 500. The ones that work get a 200, and the only difference is the size of the response.

  • XSS: The Attack That Is Not Aimed at the Server

    A 200 on an XSS probe means the page rendered with the payload in it. The victims show up hours later, from other addresses.

  • Breaking Out of the App: Traversal and Command Injection

    A 404 says the first try missed. The 200 with 2,114 bytes two lines later is /etc/passwd leaving the building.

  • Scanner or Attacker? One Night, Two Addresses

    1,384 lines from a scanner and 61 from a person. The scanner is noise to record; the sixty-one lines are the incident.

More in this zone

Web Attacks in the Logs: SQLi, XSS, Traversal, Injection | EpicDetect