This is some strange xss, the alert box pops up but with nothing in it, if you check the source code you can see that in all places apart from one the < > and appended to lt & gt yet they've left one place open. Anyway for those of you who aren't English this is quite a major ISP.
This site has countless XSS holes, prints the password in the returned form if you passed something wrong, returns server errors when feed with unexpected data, etc. etc.
A Showcase for your Imagination (to use their words;-)
I guess it's worth to open its own thread here, if someone diggs deeper ...
Edited 1 time(s). Last edit at 01/06/2007 02:01PM by kirke.
Hah thx, I tested it with a few willing victims and it steals cookies nicely. Don't know about worm. I tried embedding a getURL() in an SWF but i think a recent update means not even allowNetworking=internal works...
[Kthx again.] I don't know if this belongs here [as the thread seems based on xss (>html)] but here's another thing I found much time ago... I never really mentioned it until the other day and don't want someone else taking credit... :p
SHTML; nasty one that... half the crap after the (GET) injection part probs isn't necessary but there you are anyway. I suppose you can then use <!--#include--> or cmd="cat" from there, amongst certain others... :D
Wow, that's amazing, SystemOfAHack. That is literally the very first example of SSI injection I've ever seen outside of a lab environment, ever. Amazing!
A terribly unfiltering asp (from what I can tell, it filters nothing). Got annoyed with redirect so I plaintext'd the HTML... I'll try come up with something better in the morning. *yawn*
I heard there was an xss in gmail, so I'm on the hunt for that. But they seem to have themselves well-covered...
Haha, seems that images.com is down. Either someone's very irresponsible or images.com just so happened to realise they had an SSI injection right around the time I posted about it... hmm; I guess I should have just kept it private.
#edt - OK, since I posted that SSI vuln images.com hasn't been accessible, but www.images.com is. Did I post it wrong in the first place or something?... If so, I was tired
Edited 1 time(s). Last edit at 01/11/2007 06:58PM by SystemOfAHack.
Adultspace.com seems to have now atleast tried to filter user input a litte this time. <script> gets completely removed but if you put in <s\0cr\0ipt> it gets filtered to <script> and it'll execute.
Theres probably a few other ways to bypass it as well.
---------------
Digital footprints suck. Learn to walk on your hands.
http://www.youfucktard.com
Luny Wrote:
-------------------------------------------------------
> No url for this one.
>
> Adultspace.com seems to have now atleast tried to
> filter user input a litte this time. gets
> completely removed but if you put in it gets
> filtered to and it'll execute.
>
> Theres probably a few other ways to bypass it as
> well.
Why no Url? Didn't manage to find a XSS within the first few secs but I did find a sql injection problem and it seems pretty nasty ;)
Edited 1 time(s). Last edit at 01/10/2007 10:22PM by malorn.
since i don't really think myspace deserves a 7th thread (plus it's unrelated to filter evasion), it's going back here..
This requires SE as they have to click the 'Click Here' button.. i went ahead and added a convincing sentence that can be combined with a worm pm'ing people about free Premier MySpace accounts if they go there and change the address to their own..