what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New

Maxthon / Avant Browser XCS / Same Origin Bypass

Maxthon / Avant Browser XCS / Same Origin Bypass
Posted Dec 6, 2012
Authored by Roberto Suggi Liverani | Site security-assessment.com

Maxthon and Avant browsers suffer from various flaws such as same origin policy bypass, cross context scripting, and various other vulnerabilities.

tags | advisory, vulnerability
SHA-256 | 87028c638482f39ab332b895dec18a8784addddc5267fa402799450cab84cc65

Maxthon / Avant Browser XCS / Same Origin Bypass

Change Mirror Download
Hi,

Below you can find a short summary of discovered vulnerabilities in Maxthon
and Avant browsers.
Such vulnerabilities were demonstrated during HITBAMS2012 security
conference and more recently at HackPra.

Affected Products

- Maxthon (www.maxthon.com)
- Avant Browser (www.avantbrowser.com)

Security advisories

- [advisory] Maxthon multiple vulnerabilities:
http://www.security-assessment.com/files/documents/advisory/Maxthon_multiple_vulnerabilities_advisory.pdf
- [advisory] Avant multiple vulnerabilities:
http://www.security-assessment.com/files/documents/advisory/Avant_multiple_vulnerabilities_advisory.pdf

Individual security advisories, exploit modules and video links can be
found below.

[1] Maxthon - Cross Context Scripting - about: history - Remote Code
Execution

[advisory]
http://blog.malerisch.net/2012/12/maxthon-cross-context-scripting-xcs-about-history-rce.html
[metasploit module]
https://github.com/malerisch/metasploit-framework/blob/maxthon3/modules/exploits/windows/browser/maxthon_history_xcs.rb
[demo] http://www.youtube.com/watch?v=d-55asVLqNI


[2] Maxthon - Cross Context Scripting (XCS) - RSS - Remote Code Execution

[advisory]
http://blog.malerisch.net/2012/12/maxthon-cross-context-scripting-xcs-rss-rce.html
[metasploit module]
https://github.com/malerisch/metasploit-framework/blob/maxthon3/modules/exploits/windows/browser/maxthon_rss_xcs.rb
[demo] http://www.youtube.com/watch?v=d-55asVLqNI


[3] Maxthon - Privileged APIs on i.maxthon.com

[advisory]
http://blog.malerisch.net/2012/12/maxthon-privileged-api-imaxthoncom.html
[demo] http://www.youtube.com/watch?v=1IqZBS0O2Hs


[4] Maxthon - Cross Context Scripting (XCS) - Bookmark Toolbar and Bookmark
Sidebar - Code Execution

[advisory]
http://blog.malerisch.net/2012/12/maxthon-cross-context-scripting-xcs-bookmark.html
[demo] http://www.youtube.com/watch?v=YR0RQz45t3M


[5] Maxthon - Incorrect Executable File Handling and Same Origin Policy
Implementation

[advisory]
http://blog.malerisch.net/2012/12/maxthon-incorrect-executable-file-sop.html


[6] Avant Browser - Same of Origin Policy Bypass - browser:home

[advisory]
http://blog.malerisch.net/2012/12/avant-browser-same-of-origin-policy.html
[BeEF module]
https://github.com/malerisch/beef/tree/avant_browser/modules/exploits/avant_steal_history
[demo] http://www.youtube.com/watch?v=I4LiSfTmuM0


[7] Avant Browser - Stored Cross Site Scripting - Feed Reader
(browser://localhost/lst?*)

[advisory]
http://blog.malerisch.net/2012/12/avant-browser-stored-cross-site-scripting.html
[demo] http://www.youtube.com/watch?v=-mShxsspxy8


[8] Avant Browser - Cross Context Scripting - browser:home - Most Visited
And History Tabs

[advisory]
http://blog.malerisch.net/2012/12/avant-browser-cross-context-scripting.html
[demo] http://www.youtube.com/watch?v=cHHtsOpYGH4

References

[presentation] HITBAMS2012 - Window Shopping: Browser Bugs Hunting in 2012
-
http://www.security-assessment.com/files/documents/presentations/window_shopping_browser_bug_hunting_in_2012_roberto_suggi_liverani_scott_bell.pdf
[presentation] HackPra - Cross Context Scripting attacks & exploitation -
http://www.slideshare.net/robertosl81/cross-context-scripting-attacks-exploitation

Any further material, comments or updates will be communicated over
Twitter, at https://twitter.com/malerisch

Roberto Suggi Liverani
Login or Register to add favorites

File Archive:

April 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Apr 1st
    10 Files
  • 2
    Apr 2nd
    26 Files
  • 3
    Apr 3rd
    40 Files
  • 4
    Apr 4th
    6 Files
  • 5
    Apr 5th
    26 Files
  • 6
    Apr 6th
    0 Files
  • 7
    Apr 7th
    0 Files
  • 8
    Apr 8th
    22 Files
  • 9
    Apr 9th
    14 Files
  • 10
    Apr 10th
    10 Files
  • 11
    Apr 11th
    13 Files
  • 12
    Apr 12th
    14 Files
  • 13
    Apr 13th
    0 Files
  • 14
    Apr 14th
    0 Files
  • 15
    Apr 15th
    30 Files
  • 16
    Apr 16th
    10 Files
  • 17
    Apr 17th
    22 Files
  • 18
    Apr 18th
    45 Files
  • 19
    Apr 19th
    0 Files
  • 20
    Apr 20th
    0 Files
  • 21
    Apr 21st
    0 Files
  • 22
    Apr 22nd
    0 Files
  • 23
    Apr 23rd
    0 Files
  • 24
    Apr 24th
    0 Files
  • 25
    Apr 25th
    0 Files
  • 26
    Apr 26th
    0 Files
  • 27
    Apr 27th
    0 Files
  • 28
    Apr 28th
    0 Files
  • 29
    Apr 29th
    0 Files
  • 30
    Apr 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close