{"id":47617,"date":"2022-09-23T10:42:13","date_gmt":"2022-09-23T08:42:13","guid":{"rendered":"https:\/\/cyberant.com\/wat-is-een-mass-assignment-aanval\/"},"modified":"2023-04-12T16:02:27","modified_gmt":"2023-04-12T14:02:27","slug":"what-is-a-mass-assignment-attack","status":"publish","type":"post","link":"https:\/\/cyberant.com\/en\/what-is-a-mass-assignment-attack\/","title":{"rendered":"What is a mass-assignment attack?"},"content":{"rendered":"\n<style type=\"text\/css\" data-created_by=\"avia_inline_auto\" id=\"style-css-av-l8e8c0xw-d70ad30f0314667e631caea5cb164231\">\n#top .av_textblock_section.av-l8e8c0xw-d70ad30f0314667e631caea5cb164231 .avia_textblock{\nfont-size:40px;\n}\n<\/style>\n<section  class='av_textblock_section av-l8e8c0xw-d70ad30f0314667e631caea5cb164231 '   itemscope=\"itemscope\" itemtype=\"https:\/\/schema.org\/BlogPosting\" itemprop=\"blogPost\" ><div class='avia_textblock'  itemprop=\"text\" ><h1>What is a mass-assignment attack?<\/h1>\n<\/div><\/section>\n\n<style type=\"text\/css\" data-created_by=\"avia_inline_auto\" id=\"style-css-av-av_hr-8ddc7023771561a08c2d1878cbb01bdc\">\n#top .hr.hr-invisible.av-av_hr-8ddc7023771561a08c2d1878cbb01bdc{\nheight:30px;\n}\n<\/style>\n<div  class='hr av-av_hr-8ddc7023771561a08c2d1878cbb01bdc hr-invisible  avia-builder-el-1  el_after_av_textblock  el_before_av_textblock '><span class='hr-inner '><span class=\"hr-inner-style\"><\/span><\/span><\/div>\n\n<style type=\"text\/css\" data-created_by=\"avia_inline_auto\" id=\"style-css-av-l8e8daie-064eb2942e8e508a4d3b816c9674e577\">\n#top .av_textblock_section.av-l8e8daie-064eb2942e8e508a4d3b816c9674e577 .avia_textblock{\nfont-size:16px;\n}\n<\/style>\n<section  class='av_textblock_section av-l8e8daie-064eb2942e8e508a4d3b816c9674e577 '   itemscope=\"itemscope\" itemtype=\"https:\/\/schema.org\/BlogPosting\" itemprop=\"blogPost\" ><div class='avia_textblock'  itemprop=\"text\" ><h3><img decoding=\"async\" class=\"attachment-large wp-post-image webpexpress-processed aligncenter\" style=\"font-size: 16px;\" src=\"https:\/\/cyberant.com\/wp-content\/uploads\/2022\/08\/mailbox-g974b67b12_1280-1024x768.jpg\" sizes=\"(max-width: 640px) 100vw, 640px\" srcset=\"https:\/\/cyberant.com\/wp-content\/uploads\/2022\/08\/mailbox-g974b67b12_1280-1024x768.jpg 1024w, https:\/\/cyberant.com\/wp-content\/uploads\/2022\/08\/mailbox-g974b67b12_1280-300x225.jpg 300w, https:\/\/cyberant.com\/wp-content\/uploads\/2022\/08\/mailbox-g974b67b12_1280-768x576.jpg 768w, https:\/\/cyberant.com\/wp-content\/uploads\/2022\/08\/mailbox-g974b67b12_1280-400x300.jpg 400w, https:\/\/cyberant.com\/wp-content\/uploads\/2022\/08\/mailbox-g974b67b12_1280.jpg 1280w\" alt=\"over posting\" width=\"428\" height=\"321\" \/><\/h3>\n<p><span class=\"lead\">Mass-assignment, sometimes also referred to as an over-posting attack, is an attack on (web) applications in which an attacker can arbitrarily modify elements of an object. Applications that use model binding in a request in particular can be vulnerable to this attack. With model binding, a developer does not have to write code which fields are entered within a form. This is used to save code. However, an attacker can use this to change other fields from the database\/object.<\/span><\/p>\n<h3>How does mass assignment work?<\/h3>\n<p>Suppose an application has an object or table with the following fields:<\/p>\n<p><code>name = \"John\"<br \/>\nisAdmin = False<\/code><\/p>\n<p>The application has a form to change the name. When this is sent, the client sends the following request:<\/p>\n<p><code>POST \/profile HTTP\/1.1<br \/>\nHost: example.com<\/code><\/p>\n<p>field[name]=John<\/p>\n<p>Now we modify the request to the following:<\/p>\n<p><code>POST \/profile HTTP\/1.1<br \/>\nHost: example.com<\/code><\/p>\n<p>field[isAdmin]=True<\/p>\n<p>If the application is vulnerable, it will modify the isAdmin field instead of the name field.<\/p>\n<h3>In practice<\/h3>\n<p>Mass-assignment vulnerabilities are often difficult to find manually, because the attacker needs to know how the data model of the application works. In the above example, the attacker just needs to know that the &#8220;isAdmin&#8221; property exists. Yet such vulnerabilities do occur, often with major consequences. A well-known example is the vulnerability on GitHub, which allows the <a href=\"https:\/\/homakov.blogspot.co.uk\/2012\/03\/how-to.html\" target=\"_blank\" rel=\"noopener\"> attacker to take over random repositories via over posting<\/a>. The best way to detect such vulnerabilities is to use a Static Code Analyzer, such as Fortify. In the case of Fortify, the tool will give a finding called &#8220;Mass assignment secure binder&#8221;.<\/p>\n<h3>How to prevent?<\/h3>\n<p>The solution is not immediately obvious, since each framework has its own implementation of binding. However, it is often possible to indicate which properties may and may not be modified. A more generic solution is to check which fields come in before binding. During a <a href=\"https:\/\/cyberant.com\/pentest\/\">pentest<\/a> we check for mass-assignment attacks. Wondering if your application is vulnerable? Please <a href=\"https:\/\/cyberant.com\/contact\/\">contact<\/a> with us.<\/p>\n<\/div><\/section>\n","protected":false},"excerpt":{"rendered":"","protected":false},"author":11,"featured_media":47618,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"inline_featured_image":false,"footnotes":""},"categories":[195,216],"tags":[182,183,197,191,185,205],"class_list":["post-47617","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-hacken","category-knowledge-base","tag-cyber-security-en","tag-cyberaanval-en","tag-cybercriminelen-en","tag-etisch-hacker-en","tag-hacker-en","tag-mass-assignment-aanval-en"],"_links":{"self":[{"href":"https:\/\/cyberant.com\/en\/wp-json\/wp\/v2\/posts\/47617","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/cyberant.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cyberant.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/cyberant.com\/en\/wp-json\/wp\/v2\/users\/11"}],"replies":[{"embeddable":true,"href":"https:\/\/cyberant.com\/en\/wp-json\/wp\/v2\/comments?post=47617"}],"version-history":[{"count":0,"href":"https:\/\/cyberant.com\/en\/wp-json\/wp\/v2\/posts\/47617\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cyberant.com\/en\/wp-json\/wp\/v2\/media\/47618"}],"wp:attachment":[{"href":"https:\/\/cyberant.com\/en\/wp-json\/wp\/v2\/media?parent=47617"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cyberant.com\/en\/wp-json\/wp\/v2\/categories?post=47617"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cyberant.com\/en\/wp-json\/wp\/v2\/tags?post=47617"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}