COMMON ATTACK PATTERN ENUMERATION AND CLASSIFICATIONLive MITRE record

CAPEC-85

AJAX Footprinting

This attack utilizes the frequent client-server roundtrips in Ajax conversation to scan a system. While Ajax does not open up new vulnerabilities per se, it does optimize them from an attacker point of view. A common first step for an attacker is to footprint the target environment to understand what attacks will work. Since footprinting relies on enumeration, the conversational pattern of rapid, multiple requests and responses that are typical in Ajax applications enable an attacker to look for many vulnerabilities, well-known ports, network locations and so on. The knowledge gained through Ajax fingerprinting can be used to support other attacks, such as XSS.

Abstraction

Detailed

Typical severity

Low

Likelihood of attack

High

Understand the attack

What is this attack pattern?

This attack utilizes the frequent client-server roundtrips in Ajax conversation to scan a system. While Ajax does not open up new vulnerabilities per se, it does optimize them from an attacker point of view. A common first step for an attacker is to footprint the target environment to understand what attacks will work. Since footprinting relies on enumeration, the conversational pattern of rapid, multiple requests and responses that are typical in Ajax applications enable an attacker to look for many vulnerabilities, well-known ports, network locations and so on. The knowledge gained through Ajax fingerprinting can be used to support other attacks, such as XSS.

Execution flow

How does the attack proceed, step by step?

1

Explore

Send request to target webpage and analyze HTML

Using a browser or an automated tool, an adversary sends requests to a webpage and records the received HTML response. Adversaries then analyze the HTML to identify any known underlying JavaScript architectures. This can aid in mappiong publicly known vulnerabilities to the webpage and can also helpo the adversary guess application architecture and the inner workings of a system.

Techniques used

  • Record all "src" values inside script tags. These JavaScript files are compared to lists of files for known architectures. If there is a large match between the "src" values and architecture files, then it can be assumed that particular architecture is being used.

Requirements

What does the attack require?

Prerequisites

  • The user must allow JavaScript to execute in their browser

Skills required

  • Medium: To land and launch a script on victim's machine with appropriate footprinting logic for enumerating services and vulnerabilities in JavaScript

Resources required

  • None: No specialized resources are required to execute this type of attack.

Impact

What does a successful attack lead to?

Read Data

Affected scopes: Confidentiality

Defence

How is it prevented and mitigated?

1
Design: Use browser technologies that do not allow client side scripting.
2
Implementation: Perform input validation for all remote content.

Real world

MITRE example instances

Example instance 1Detail
Footprinting can be executed over almost any protocol including HTTP, TCP, UDP, and ICMP, with the general goal of gaining further information about a host environment to launch further attacks. The attacker can probe the system for banners, vulnerabilities, filenames, available services, and in short anything the host process has access to. The results of the probe are either used to execute javascript (for example, if the attackers' footprint script identifies a vulnerability in a firewall permission, then the client side script executes a javascript to change client firewall settings, or an attacker may simply echo the results of the scan back out to a remote host for targeting future attacks) or to inform other data gathering activities in order to craft atta.
CAPEC-85: AJAX Footprinting — DayBreach Saldırı Sözlüğü · DayBreach