Hey hackers!!!
Today we are going to discuss about what are Web application filters and how to bypass client side filter ?
What is Web Application Filters ?
When you visit a website and register yourself it asks you for some information such as email address, mobile number, delivery address(in case if it is a shopping website ) , first name ,last name etc .
Now have you ever tried adding alphabets in the Phone number field , if you try doing so application will throw you an error saying “field should only contain numbers ” ,and also when you left the terms and condition check box uncheck it throws error saying ” please accept T &C “, now what are such pop ups why do they occur , These are various Web Application filters that does not allow user to enter invalid content or malicious content in particular field.
We can say that Web application filters ensure that the input given by the user is in the correct format.
There are two types of Web Application Filters:
- Client Side Filters .
- Server Side Filters.
What are Client Side Filters ?
The Client Sider filters are the type of filters which checks whether the enter data is valid or not on the client side (i.e browser) .
When user enters a data browser checks whether the data is entered in a correct format or not ,if data entered is correct it passes particular data to the server , if data entered is not correct it throws error .
What are Server Side Filters ?
The Server Side filters are the types of filters in which the entered data is forwarded to the server directly without checking it into browser or client side ,Server checks whether the data entered is valid or not.
If the entered data is valid ,respective response is forwarded to the client or else server throws error .
You may have observed that the role of both client and server side filter is same but the working is different ,imagine that you are able to bypass these filters and manipulate the entered data according to yourself ,This is what we call Web Application filter bypass .
It is little bit difficult to bypass server side filter but we can try bypassing client side filters .
How to bypass client side filters?
Lets try bypassing a shopping website .
As you always wanted to buy a headphone , you add a headphone in your cart and proceed to pay.
While making a payment you notice that you don’t have enough balance to place your order .What now?
Well being a Hacker you try to change the values (such as reduce Cost of headphone , increase the discount amount or increase your balance ) by bypassing the filters .
So let’s intercept the request using burp suite .
Turn your intercepter on in burp suite and click on “Pay “.As soon as you click on pay the request is intercepted by burp and you will be present a screen similar to this:
Now if you observe the above picture carefully , you will notice that you can change the values of price ,discount and balance ,as my balance is “0” i will try to increase the discount by “3000”,by changing the value of discount from “300” to “3000” .
Now forward the request by clicking on forward button on top left .Once you forward the request the order is placed successfully .
This happened because Web Application was using client side filters ,It is easier to bypass the client side filters as compare to server side filters .
Even in client side filters you need to find particular field where you can forward you own values to the server (discount in this case) .
Keep Coming for more!!!
Thank you.