Simulate CSRF Attack
Asked Answered
S

1

5

I want to simulate CSRF Attack to check my website vulnerability. I tried it on my asp.net webapplication but failed to simulate. So please help me to simulate the CSRF attack. I have simulated by having a test.aspx.

  <form name="form1" id="form1" runat="server" method="post" action="mysite.com">
 <script type="text/javascript">
        document.cookie[".ASPXAUTH"] = "someaspxauth";
        document.cookie["ASP.NET_SessionId"] = "somesessionid";
        document.form1.submit();
    </script>
</form>

What else am i missing? Thanks in advance.

Shaughn answered 6/7, 2011 at 23:12 Comment(2)
This is great article about CSRF and in general OWSASP troyhunt.com/2010/11/…Gruel
I wrote an article on how to do this in ASP.NET Core: davidklempfner.medium.com/…Maidenhood
R
7

To simulate CSRF, you won't include the cookie or session information in the malicious code. The whole point of CSRF is that the code that executes doesn't know your session or cookie info. It just assumes that the browser will include that in its request to the application.

So to test, assume you have a page Transfer.aspx which accepts a POST method and parameters of txtFrom, txtTo, and txtAmount, with a button btnSubmit, and you want to try to transfer from account 1 to account 2. Your malicious code could be something like:

<form action="http://www.mysite.com/Transfer.aspx" method="post">
    <input type="hidden" name="txtFrom" value="1" />
    <input type="hidden" name="txtTo" value="2" />
    <input type="hidden" name="txtAmount" value="500" />
    <input type="hidden" name="__VIEWSTATE" value="[PUT VIEWSTATE VALUE HERE]" />
    <input type="hidden" name="__EVENTVALIDATION" value="[PUT EVENTVALIDATION VALUE HERE]" />
    <input type="submit" name="btnSubmit" value="Go" />
</form>

You'd have to know in advance what the viewstate and eventvalidation values would be, so you'd need to copy that from your page when you're logged in properly. This assumes that your viewstate is constant, regardless of user or session.

Now you have a malicious page. If you are logged in on one tab, open this in another tab, and submit it, if you are vulnerable, then your transfer will occur. The reason is that the cookies belonging to mysite.com are sent, which means that your session, which is alive on another tab, will be used.

To fix this, you need a unique per-session value to be included in your post. This is most easily accomplished by using the ViewStateUserKey, and setting it to your ASP.NET session ID or a hash of it. This will make your __VIEWSTATE value unique with every session, which means you will no longer be vulnerable because nobody can predict what your __VIEWSTATE value will be.

Rhettrhetta answered 6/7, 2011 at 23:32 Comment(0)

© 2022 - 2024 — McMap. All rights reserved.