exploit the possibilities
Home Files News &[SERVICES_TAB]About Contact Add New

superXSS.txt

superXSS.txt
Posted Jan 15, 2006
Authored by Mustafa Can Bjorn | Site nukedx.com

Superonline.com is susceptible to a cross site scripting attack.

tags | advisory, xss
SHA-256 | 230f660f7f9eb9febae0cf5667fb136fce656d584f13c15347c8454a71588538

superXSS.txt

Change Mirror Download
--Security Report--
Advisory: XSS attack on Superonline.com email service.


---
Author: Mustafa Can Bjorn "nukedx a.k.a nuker" IPEKCI
---
Date: 01/01/06 04:18 AM
---
Contacts:{
ICQ: 10072
MSN/Email: nukedx_at_nukedx.com
Web: http://www.nukedx.com
}
---
About: Via this method,the Superonline Mails are being subjected to an attack
namely XSS attack a.k.a "Cross Site Scripting" .The attacker ,with the help of
the mail user clicking on the mail received, is able to inject a code with the
mail. The only thing necessary is to click on the mail,no need to open and read
it.As known,some E-mail providers use some scripts in web interfaces and some
bugs on "print or output scripts" grants us the chance to see what we can do
about them.
---
How: The name as following written as From: Name <sender_at_attacker.com> and
being
send to the server and the victim receives it as From: [XSS-text]
<sender_at_attacker.com> and kaboom! , the mail user(namely our victim) is being
injected via XSS code . If we set our name with 28 chars and then add our XSS
code , victim reads this mail's sender as our name without XSS code injection
and gets infected.I used my name as "Mustafa Can<script></script>" ( not with
quotation marks ) and converted it to 28 chars and injected it with XSS code.
The mail user may be infected with a 28-char XSS code while viewing inbox
too.The XSS code personally used was:
Can<script></script><script>alert(document.cookie);</script><script>alert('You
have just been infected with XSS
code');</script><script>location.href('http://www.nukedx.com/pwned.htm');</script>
---
Bonus: This bug is currently available on some OTHER mail providers too.(Don't
get excited,not on so-called Famous and Safe ones such as
Hotmail,Gmail,ICQmail,MyNet ) but some other ones such as Superonline and the
ones which are awaiting you to harass on them.
For further information,please contact me from the contact I have left above,I
am not able to provide more information via mails,indisputably.
Pictures of XSS
Inbox: http://www.nukedx.com/gelenmail.png
IN Mail: http://www.nukedx.com/superxss.png
Regards,
>>From the NWPX team,
nuker a.k.a nukedx

Login or Register to add favorites

File Archive:

September 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Sep 1st
    261 Files
  • 2
    Sep 2nd
    17 Files
  • 3
    Sep 3rd
    38 Files
  • 4
    Sep 4th
    52 Files
  • 5
    Sep 5th
    23 Files
  • 6
    Sep 6th
    27 Files
  • 7
    Sep 7th
    0 Files
  • 8
    Sep 8th
    1 Files
  • 9
    Sep 9th
    16 Files
  • 10
    Sep 10th
    38 Files
  • 11
    Sep 11th
    21 Files
  • 12
    Sep 12th
    40 Files
  • 13
    Sep 13th
    18 Files
  • 14
    Sep 14th
    0 Files
  • 15
    Sep 15th
    0 Files
  • 16
    Sep 16th
    0 Files
  • 17
    Sep 17th
    0 Files
  • 18
    Sep 18th
    0 Files
  • 19
    Sep 19th
    0 Files
  • 20
    Sep 20th
    0 Files
  • 21
    Sep 21st
    0 Files
  • 22
    Sep 22nd
    0 Files
  • 23
    Sep 23rd
    0 Files
  • 24
    Sep 24th
    0 Files
  • 25
    Sep 25th
    0 Files
  • 26
    Sep 26th
    0 Files
  • 27
    Sep 27th
    0 Files
  • 28
    Sep 28th
    0 Files
  • 29
    Sep 29th
    0 Files
  • 30
    Sep 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2024 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close