Difference between revisions of "Testing for Naughty SOAP Attachments (OWASP-WS-006)"

Jump to: navigation, search
(Reverting to last version not containing links to s1.shard.jp)
Line 1: Line 1:
[http://s1.shard.jp/galeach/new77.html kitty asian movies
] [http://s1.shard.jp/losaul/wholesale-australian.html car auctions australia sydney
] [http://s1.shard.jp/bireba/nortons-antivirus.html nortons antivirus updates] [http://s1.shard.jp/galeach/new151.html asian photoshop] [http://s1.shard.jp/olharder/stan-olsen-auto.html automatic mechanical orient watch
] [http://s1.shard.jp/bireba/airscanner-mobile.html norton antivirus software for free download
] [http://s1.shard.jp/galeach/new118.html at the dolphin bay dvd yesasia] [http://s1.shard.jp/galeach/new188.html the accidental asian
] [http://s1.shard.jp/olharder/autoroll-654.html links] [http://s1.shard.jp/frhorton/5hrrb99yl.html the apartheid of south africa
] [http://s1.shard.jp/losaul/australian-walkabout.html water coolers australia
] [http://s1.shard.jp/olharder/autoroll-654.html site] [http://s1.shard.jp/bireba/sofos-antivirus.html grisoft avg antivirus free download
] [http://s1.shard.jp/frhorton/vuku1m6uz.html african volcanoe
] [http://s1.shard.jp/olharder/siemens-automotive.html head automatica the razor tabs
] [http://s1.shard.jp/galeach/new99.html asiana restaurant chicago
] [http://s1.shard.jp/bireba/notron-antivirus.html mcafee home free antivirus
] [http://s1.shard.jp/galeach/new129.html eurasia map northern political
] [http://s1.shard.jp/losaul/idp-australia.html australian dental association nsw
] [http://s1.shard.jp/olharder/autoroll-654.html index] [http://s1.shard.jp/losaul/australian-sheepskin.html unlocking nokia phones australia
] [http://s1.shard.jp/losaul/consolidated-travel.html consolidated travel australia] [http://s1.shard.jp/bireba/mobile-antivirus.html winantivirus pro 2005 download
] [http://s1.shard.jp/olharder/autores-romanticos.html motorsport auto datsun
] [http://s1.shard.jp/galeach/new44.html rare asian disease
] [http://s1.shard.jp/galeach/new111.html travel asia and beyond
] [http://s1.shard.jp/olharder/kurt-cobain-autograph.html auto finder luxury
] [http://s1.shard.jp/losaul/i-still-call-australia.html making soft plastic lures australia
] [http://s1.shard.jp/olharder/automobile-sites.html automation services company
] [http://s1.shard.jp/olharder/automobile-dealer.html auction auto garden state
] [http://s1.shard.jp/olharder/auto-club-country.html grand theft auto 3 hints for pc
] [http://s1.shard.jp/losaul/australia-posters.html australia posters] [http://s1.shard.jp/frhorton/wlyxxgvnc.html history of african woman
] [http://s1.shard.jp/frhorton/4dqjbtjm2.html south africa for kids
] [http://s1.shard.jp/losaul/visa-para-australia.html australian honours secretariat
] [http://s1.shard.jp/frhorton/a1q69qdt7.html african afro american hair style
] [http://s1.shard.jp/galeach/new91.html asia.net.pk
] [http://s1.shard.jp/bireba/cheap-norton-antivirus.html macafee antivirus free download
] [http://s1.shard.jp/olharder/auto-panel-plus.html michael jordans autobiography
] [http://s1.shard.jp/olharder/autoroll-654.html top] [http://s1.shard.jp/bireba/etrust-ez-antivirus.html stinger antivirus download free
] [http://s1.shard.jp/frhorton/9df15nbui.html biggest country in africa
] [http://s1.shard.jp/frhorton/8fsjs64q2.html paffendorf welcome to africa
] [http://s1.shard.jp/frhorton/q5ck3w5jf.html african animal boy] [http://s1.shard.jp/galeach/new6.html anastasia florida
] [http://s1.shard.jp/olharder/auto-start.html 2binsurance automobile
] [http://s1.shard.jp/bireba/antivirus-software.html pandaantivirus software
] [http://s1.shard.jp/galeach/new130.html asian regionalt svenska world] 
{{Template:OWASP Testing Guide v3}}
{{Template:OWASP Testing Guide v3}}

Revision as of 10:00, 27 May 2009

http://www.textcnaerviel.com OWASP Testing Guide v3 Table of Contents

This article is part of the OWASP Testing Guide v3. The entire OWASP Testing Guide v3 can be downloaded here.

OWASP at the moment is working at the OWASP Testing Guide v4: you can browse the Guide here

Brief Summary

This section describes attack vectors for Web Services that accept attachments. The danger exists in the processing of the attachment on the server and redistribution of the file to clients.

Description of the Issue

Binary files, including executables and document types that can contain malware, can be posted using a web service in several ways. These files can be sent as a parameter of a web service method; they can be sent as an attachment using SOAP with Attachments, and they can be sent using DIME (Direct Internet Message Encapsulation) and WS-Attachments.

An attacker can craft an XML document (SOAP message) to send to a web service that contains malware as an attachment. Testing to ensure the Web Service host inspects SOAP attachments should be included in the web application testing plan.

Black Box testing and example

Testing for file as parameter vulnerabilities:

1. Find WSDL that accepts attachments:

For example:

... <s:element name="UploadFile">
  <s:element minOccurs="0" maxOccurs="1" name="filename" type="s:string" /> 
  <s:element minOccurs="0" maxOccurs="1" name="type" type="s:string" /> 
  <s:element minOccurs="0" maxOccurs="1" name="chunk" type="s:base64Binary" /> 
  <s:element minOccurs="1" maxOccurs="1" name="first" type="s:boolean" /> 
 <s:element name="UploadFileResponse">
 <s:element minOccurs="1" maxOccurs="1" name="UploadFileResult" type="s:boolean" /> 
 </s:element> ... 

2. Attach a test virus attachment using a non-destructive virus like EICAR, to a SOAP message and post to the target Web Service. In this example, EICAR is used.

SOAP message with EICAR attachment (as Base64 data):

POST /Service/Service.asmx HTTP/1.1
Host: somehost
Content-Type: text/xml; charset=utf-8
Content-Length: length
SOAPAction: http://somehost/service/UploadFile

<?xml version="1.0" encoding="utf-8"?>
<soap:Envelope xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" 
<UploadFile xmlns="http://somehost/service">

Result Expected:

A SOAP response with the UploadFileResult parameter set to true (this will vary per service). The EICAR test virus file is allowed to be stored on the host server and can be redistributed as a PDF.

Testing for SOAP with Attachment vulnerabilities

The testing is similar, however, the request would be similar to the following (note the EICAR base64 info):

POST /insuranceClaims HTTP/1.1
Host: www.risky-stuff.com
Content-Type: Multipart/Related; boundary=MIME_boundary; type=text/xml;
Content-Length: XXXX
SOAPAction: http://schemas.risky-stuff.com/Auto-Claim
Content-Description: This is the optional message description.

Content-Type: text/xml; charset=UTF-8
Content-Transfer-Encoding: 8bit
Content-ID: <claim061400a.xml@claiming-it.com>

<?xml version='1.0' ?>
<claim:insurance_claim_auto id="insurance_claim_document_id"
<theSignedForm href="cid:claim061400a.tiff@claiming-it.com"/>
<theCrashPhoto href="cid:claim061400a.jpeg@claiming-it.com"/>
<!-- ... more claim details go here... -->

Content-Type: image/tiff
Content-Transfer-Encoding: base64
Content-ID: <claim061400a.tiff@claiming-it.com>

Content-Type: image/jpeg
Content-Transfer-Encoding: binary
Content-ID: <claim061400a.jpeg@claiming-it.com>

...Raw JPEG image..

Result Expected:

The EICAR test virus file is allowed to be stored on the host server and can be redistributed as a TIFF file.