Attention to Details: Finding Hidden IDORs
How a huge travel portalâs customer PII data couldâve leaked through some remanant functionality.This lead me to discover a few IDORs.
Goa has always been an adventure paradise. This tale is no exception.
A few of us friends were planning a Goa trip. Searching for cheap tickets on skyscanner, led me to this website, henceforth called as âwhereIDORsLive.comâ, which had amazing offers. This is a big travel portal in India and elsewhere, with offices in Singapore, Dubai and London too. Since its beginning, last decade, it has gained quite some traction in recent days, due to some big Bollywood celebrities advertising for them.
Note these IDORs are in the sequence of which I found them and not on the basis of severity.
1st IDOR : Download Anyoneâs Ticket
I went on to book my tickets and on the transaction confirmation page, there were options to âSMSâ, âEmailâ and âDownloadâ the ticket as pdf.
I went on to download the ticket as PDF. It has pdf with encrypted name, at first I thought it was just base64 encoded but âdecodingâ it ( after adjusting proper padding ) gave something gibberish. Itâs usually the case that encrypted strings are then âencodedâ in base64 so that they can be converted to printable characters for smooth transfer and rendering amongst the applications.
Whenever I see encryption on website, I get curious to explore that as in my experience, most of these have some wrong implementation or worse âcustom implementationâ.
My suspicions were raised cause the site was not using SSL certificate for their API and was doing âencryptionâ shit on their pdf name, something really âhackyâ must be going on. These were all indications of slap dash work done on the websiteâs end. So, I went on to do âInspect Elementâ on the âDownload PDFâ button.
One cannot fail to notice that thereâs a downloadPdf
function being called with the âBooking IDâ. Now, the very first thing I did was call the same function with the incremental next booking ID i.e. â66786694'. That also opened the same pdf i.e. my ticketâs pdf, no matter what ID you put in the downloadPdf
function, it spit out the current ticket. Then I went on to look at the code of downloadPdf
function.
The Code was simple, it was taking in the bookind id number ( here 66786693 ) as âtidâ but instead of using it reassigning that to âhdnBookingIdâ, the encrypted string. So, when you clicked on it, a new tab would open with your pdf :
http://api.whereIDORsLive.com/XYZService/EticketPdf/hdnBookingId.pdf
function downloadPdf(tid) { | |
if (document.getElementById("hdnBookingId") != null && document.getElementById("hdnBookingId").value != "") | |
tid = document.getElementById("hdnBookingId").value; | |
if (tid != null && tid != "" && tid != undefined) | |
window.open("http://api.whereIDORsLive.com/XYZService/EticketPdf/" + tid + ".pdf", '_blank'); | |
} |
Now, this raises question as to why would someone do that, why not straightaway call the downloadPdf
function, why to pass the booking number , when not using it.
There was only one thing that came to my mind, it would be legacy code and earlier it could be that the function was substituting the âbookingIdâ straightaway into the URL.
So, earlier the links couldâve been like :
http://api.whereIDORsLive.com/XYZService/EticketPdf/bookingId.pdf
Now, just to check whether that backend still lives I went on to this link:
http://api.whereIDORsLive.com/XYZService/EticketPdf/66786693.pdf
And yup, it gave the PDF, iterating over the booking Ids , I could fetch other peopleâs tickets too. I promptly and responsibly disclosed this to their concerned team.
Why Did This Happen ?
Probably because, at the backend the files were still being saved as bookingId.pdf
 , and there would be a middleware decrypting the hdnBookingId
to bookingId
or there could be two files being saved for each ticket. One with hdnBookingId.pdf
and the other with bookingId.pdf
 .
Mitigation
If the application only kept the âencrypted filename.pdfâ this whole thing couldâve been mitigated ( but then again, how come I wouldâve written this blog đ ).
2nd IDOR : Another Day, another endpoint, Same Company
This day I started looking at the android app of the company. I found that the traffic was being routed to one endpoint :
http://cloud.whereIDORsLive.in/XYZService/dboperation.svc
Now, this was a treasure trove (atleast for a hacker :p). It was a documentation of all the endpoints, when clicking on the hyperlink corresponding to the endpoint there was also JSON and XML sample payload and response you could expect from the endpoint. It was like swagger even better except the trying out feature was missing (then it wouldâve been like serving on a platter).
Going through the endpoints, I found one that could probably lead to some information leakage.
/GetETicket/{TransactionscreenID}/{UserName}/{Password}/{ProcessType}
Now it required TransactionscreenID
 , UserName
and Password
 , of which I didnât have any clue at the moment.
Exploring the application a bit and fetching the ticket through the app, triggered this endpoint and then I could see the values required to get the ticket details.
The endpoint returns passenger details in html table form ( instead of pdf as earlier ). Letâs verify the IDOR.
Now, documentation helps us even more. Remember the ProcessType
parameter, weâve only looked at process type 1
, what about other values đ
Passing the ProcessType
parameter as 3
raises an exception and we get a sneak-peek into the underlying code.
3rd IDOR : Same Day, another endpoint, Same Company
Looking through the documentation, there was another endpoint which looked like it would return sensitive information.
/GetPaxBookingDetails/{TransactionscreenID}/{UserName}/{Password}
Requesting data from this endpoint, returned PII of the customer. Any user who had ever booked a ticket from the companyâs website, their data could be fetched.
Why did these Happen ?
This happened because there wasnât any access control or âstrong authenticationâ on the endpoint. It was lying there waiting to be found đ.
Mitigation
One possible way Iâve seen in other applications protecting their endpoints is by having proper access control. Usually itâs JWT or any other token that identifies the user and thus gives access to only resources related to them.
Key Takeaways
- Be Curious: Curiosity doesnât always kill the cat đ. Questioning and understanding why the input parameter was booking id but the request being made by hdnBookingId, led me to these bugs.
- Expand your search area: In this case, as I had checked the web app, going through the android app, led me to customer PII, which is a P0 data for any company. BTW I didnât get the time to look at the iOS app, in case someone figures out which company it is đ
- Learn your tools right: Linux can be your friend. A lot of linux commands used properly will save a lot of time and would be a great learning experience altogether. Also, a lot of small things like base64 encoding/decoding, URI encoding/decoding can be done in browserâs console itself and you donât have to latch on to a 3rd party website or app.
- No secret sauce : Bugs are simple, persistence is the key.
Other Titbits
- Getting all the hardcoded endpoints from a decompiled apk or similar crawling, run this from the root of your recon/decompiled apk folder :
grep -rE "https?://.*companyName.*" .
Â
This works for *nix systems or any system withgrep
installed.
-
Base64 encoding/decoding in chrome :Â
Decoding : ( helpful in JWT decoding too )atob('eW91IGxlYXJudCB0aGF0IHJpZ2h0') <- try this in your browser's console
Encoding :
btoa('this is how you encode in base64')
-
URI decoding : Decoding
decodeURIComponent('[https://example.com/?query=%22this%20is%20a%20url%20encoded%20string%22'](https://example.com/?query=%22this%20is%20a%20url%20encoded%20string%22%27))
Thank you everyone :)