Paid Advertising

SLA.CKERS.ORG
HA.CKERS SLACKING
sla.ckers.org web application security lab forums
Where you should disclose your vulnerabilities. Go read RFPolicy if you want to do responsible disclosure, and go here for when all else fails. 
Re: So it begins - Redirects Edition
Posted by: trev (IP Logged)
Date: March 11, 2007 07:11AM

That one is actually an XSS: [www.kreditwerk.de]

Re: So it begins - Redirects Edition
Posted by: Spyware (IP Logged)
Date: March 12, 2007 02:28PM

yay, google.

[www.google.com]

Click on "I forgot my password" and it will redirect.

-Spyware | [bitsofspy.net]



Edited 1 time(s). Last edit at 03/12/2007 02:29PM by Spyware.

Re: So it begins - Redirects Edition
Posted by: Spyware (IP Logged)
Date: March 13, 2007 03:53AM


Re: So it begins - Redirects Edition
Posted by: Spyware (IP Logged)
Date: March 13, 2007 05:09AM


Re: So it begins - Redirects Edition
Posted by: Awesome AnDrEw (IP Logged)
Date: March 13, 2007 08:50AM

Spyware Wrote:
-------------------------------------------------------
> yay, google.
>
> [www.google.com].
> py?answer=48598&fpUrl=http://ha.ckers.org
>
> Click on "I forgot my password" and it will
> redirect.

Nice find. I tried to do this with Yahoo!'s signout feature, but it refused to point to the URL I selected.

http://www.awesomeandrew.net/images/banner/88x317.gif
Awesome AnDrEw - That's The Sound Of Your Brain Crackin'
[www.awesomeandrew.net]

Re: So it begins - Redirects Edition
Posted by: trev (IP Logged)
Date: March 13, 2007 04:51PM


Re: So it begins - Redirects Edition
Posted by: Spyware (IP Logged)
Date: March 15, 2007 07:03AM

[login.live.com]

needs some research though.

-Spyware | [bitsofspy.net]

Re: So it begins - Redirects Edition
Posted by: Spyware (IP Logged)
Date: March 16, 2007 09:30AM


Re: So it begins - Redirects Edition
Posted by: trev (IP Logged)
Date: March 16, 2007 10:19AM

Did we already have this one?

[sla.ckers.org] :)

Re: So it begins - Redirects Edition
Posted by: rsnake (IP Logged)
Date: March 16, 2007 05:59PM

What are you talking about trev? :) Click the link and see what happens. ;)

- RSnake
Gotta love it. http://ha.ckers.org

Re: So it begins - Redirects Edition
Posted by: kirke (IP Logged)
Date: March 17, 2007 03:48PM

according trev's gmx.net sample:
note that GMX blocks the URL now according the rfer(r)er, how stupid can developers/admins be?

Re: So it begins - Redirects Edition
Posted by: trev (IP Logged)
Date: March 17, 2007 04:51PM

Yes, that's pretty pointless, spam mails have no referrers...

Re: So it begins - Redirects Edition
Posted by: trev (IP Logged)
Date: March 18, 2007 11:55AM

Three for the price of one!

Redirect: [usercash.com]
XSS: [usercash.com]"/onload="alert("xss")
SQL Injection: [usercash.com]'

Anybody want to improve the balance on his account? :)

Re: So it begins - Redirects Edition
Posted by: Spencer (IP Logged)
Date: March 19, 2007 11:55AM


Re: So it begins - Redirects Edition
Posted by: trev (IP Logged)
Date: March 27, 2007 11:13AM


Re: So it begins - Redirects Edition
Posted by: Awesome AnDrEw (IP Logged)
Date: March 28, 2007 01:40AM

The National Sex Offender Registry. Did id have to tell them he was moving :-X?
[www.familywatchdog.us]

http://www.awesomeandrew.net/images/banner/88x317.gif
Awesome AnDrEw - That's The Sound Of Your Brain Crackin'
[www.awesomeandrew.net]

Re: So it begins - Redirects Edition
Posted by: id (IP Logged)
Date: March 28, 2007 01:02PM

Hey now! They were all legal and mostly willing!

-id

Re: So it begins - Redirects Edition
Posted by: Awesome AnDrEw (IP Logged)
Date: March 28, 2007 05:09PM

I found that all the INPUT elements on that site go unsanitized, and are ready for XSS but only via POST requests.

id Wrote:
-------------------------------------------------------
> Hey now! They were all legal and mostly willing!
I remember when I was 16 I told my mom that when I started driving I was going to go to all the local clubs, and pick up drunk and drugged out girls to take advantage of. Then I told her, "It's not rape. It's surprise sex. SURPRISE!"

http://www.awesomeandrew.net/images/banner/88x317.gif
Awesome AnDrEw - That's The Sound Of Your Brain Crackin'
[www.awesomeandrew.net]

Re: So it begins - Redirects Edition
Posted by: hackathology (IP Logged)
Date: March 31, 2007 04:11AM

I must say that i am learning hell lot of techniques down here. Redirect and XSS, it will be useful for my pentest. Thank you guys.

hackathology

[hackathology.blogspot.com]

Re: So it begins - Redirects Edition
Posted by: trev (IP Logged)
Date: April 04, 2007 06:18AM


Re: So it begins - Redirects Edition
Posted by: tx (IP Logged)
Date: April 04, 2007 11:19PM

[dect.myspace.com]

-tx @ lowtech-labs.org

Re: So it begins - Redirects Edition
Posted by: CrYpTiC_MauleR (IP Logged)
Date: April 05, 2007 12:03AM

[www.poopreport.com] =oP

________________________________________________________________________
www.crypticmauler.com
"You must be the change you wish to see in the world."

Re: So it begins - Redirects Edition
Posted by: trev (IP Logged)
Date: April 05, 2007 08:09AM

CrYpTiC_MauleR: Nice find! That one is actually an HTTP Response Splitting vulnerability in Openads 2.0:

[www.poopreport.com] (try this in Firefox)

Funny thing: looking at the source code of adclick.php, it already "protects" against HTTP Response Splitting - \r\n in the destination isn't allowed, using \n is still possible however :)

This is a pretty popular script. Want to post this on the Full Disclosure mailing list? It will get more attention there.

Re: So it begins - Redirects Edition
Posted by: CrYpTiC_MauleR (IP Logged)
Date: April 05, 2007 12:25PM

You can post it, your find. I didn't bother to check it out any further, just bored last night =oP and no I wasn't reading the latest poop news.

________________________________________________________________________
www.crypticmauler.com
"You must be the change you wish to see in the world."

Re: So it begins - Redirects Edition
Posted by: trev (IP Logged)
Date: April 06, 2007 12:55PM


Re: So it begins - Redirects Edition
Posted by: nEUrOO (IP Logged)
Date: April 08, 2007 08:30PM


Re: So it begins - Redirects Edition
Posted by: CrYpTiC_MauleR (IP Logged)
Date: April 08, 2007 10:49PM

[www.hackers.org] =oP

________________________________________________________________________
www.crypticmauler.com
"You must be the change you wish to see in the world."

Re: So it begins - Redirects Edition
Posted by: CrYpTiC_MauleR (IP Logged)
Date: April 15, 2007 07:19PM

[search.verisign.com]

Also HTTP Response Splitting
[search.verisign.com]

________________________________________________________________________
www.crypticmauler.com
"You must be the change you wish to see in the world."

Re: So it begins - Redirects Edition
Posted by: FR3DC3RV (IP Logged)
Date: April 23, 2007 12:23PM

Some sort of cgi proxy:

[www.min-edu.pt]

-------------------------------
[fr3dc3rv.blogspot.com]

Re: So it begins - Redirects Edition
Posted by: Foo (IP Logged)
Date: April 24, 2007 04:30AM

Sorry if this one is an oldie, but here it comes.

[www.google.com]?

Googles redirect service ;p



Sorry, only registered users may post in this forum.