Sponsored by: █ Sparkhost - Hosting Without Compromises! █ Hybrid Performance Web Hosting █ Spark Host Stream Hosting █ Hybrid IRC & IRCd Server Shell Accounts
Google Images Exploit
#1
Posted 13 February 2006 - 08:52 AM
ok well, not too much of a bug but u could fool someone and steal there cookies or suntin..
well
--http://images.google.com/imgres?imgurl=[URLHERE]&imgrefurl=http://darkdevelopments.com/
replace [URLHERE] with a url. then wen u click view full size image, it will redirect you to that url
Ie:
--http://images.google.com/imgres?imgurl=http://darkdevelopments.com&imgrefurl=http://darkdevelopments.com/
The above will redirect you to this url.
Easily steal someones cookies.
you could even change the imgrefurl= variable to make it display the script straight away.
imgurl= See full-size image link.
imgrefurl= page displayed below in the frame.
Subscribe To Our RSS Feed For the Latest News from GovernmentSecurity.orgWould you like to earn money posting on GSO?
#2
Posted 13 February 2006 - 09:57 AM
SSgroup & GoG as well as many others.. You should feel honored that he added you to his list.. Then again, the honor may be his.. Never know..
Dice
#3
Posted 13 February 2006 - 11:06 AM
#4
Posted 13 February 2006 - 10:13 PM
http://images.google.com/imgres?imgurl=http://snickerbars.com&imgrefurl=http://pablo_m123.tripod.com/cs.html&imgrefurl=http://pablo_m123.tripod.com/cs.htmlYou can make it link to itself to make the url long so less chance of any one noticeing the hidden url, well kind of. Got my friends good with that...
-toe
#5
Posted 13 February 2006 - 10:19 PM
setthesun me = new setthesun();
#6
Posted 14 February 2006 - 07:32 AM
The above will display your ip. Using a similar method, you could easily steal cookies, etc, etc.
after knowledge... and you call us criminals. We exist without skin color,
without nationality, without religious bias... and you call us criminals.
You build atomic bombs, you wage wars, you murder, cheat, and lie to us
and try to make us believe it's for our own good, yet we're the criminals.
[Quote By: The Mentor]
#7
Posted 14 February 2006 - 11:47 AM
http://images.google...om/extra/ip.php
The above will display your ip. Using a similar method, you could easily steal cookies, etc, etc.
Sorry but no you can not,
setthesun me = new setthesun();
#8
Posted 16 February 2006 - 12:53 AM
Else, it would be too easy, just let google index your site, and voila...
crk,
#9
Posted 16 February 2006 - 07:59 AM
But this XSS is harmless maybe usefull for phishing but not likely.
We have contacted google also for a remote source disclosure and there where some members working on a remote DoS against google servers.
But the bug you found is a RXSS ( Redirect XSS ), devilbox had developped that technique several years ago when XSS was named HTML Piggy Jack and sql injection know as SQL Piggy Jack he says, I guess he and idespinner developped it.
I can't post the whitepaper because he hasn't disclosed it still after all those years.
And setthesun is right you can't steal cookies from the google page (because your javascript code is on a different page so you can only get the cookies from that page) but you can execute javascript in a victim his browser.
Here's a test link
http://images.google.com/imgres?imgurl=http://darkdevelopments.com&imgrefurl=http://tinyurl.com/blyzc
Former security researcher for KAPDA.
http://www.kapda.ir OFFLINE FOREVER
http://www.kapda.net Archived website
Iranian Computer Security Science Researchers Institute.
http://en.wikipedia.org/wiki/KAPDA
Search bugtrack and many other mailing lists for my old advisory's, exploits and 0day's.
Search google with keywords: cvh kapda
#10
Posted 16 February 2006 - 08:42 AM
best wishesh for kapda
#11
Posted 17 February 2006 - 11:03 AM
We have contacted google also for a remote source disclosure and there where some members
wow it's serious dude do you mean you see source code of some pages from google?
What is the language ? Java, some kind of scripting over C++, perl ?
setthesun me = new setthesun();
#12
Posted 17 February 2006 - 11:14 AM
So not critical and still unpatched I just checked, but it was confirmed by google as a source disclosure.
Black_death found that bug at Jan 14 2006, so a month ago.
Former security researcher for KAPDA.
http://www.kapda.ir OFFLINE FOREVER
http://www.kapda.net Archived website
Iranian Computer Security Science Researchers Institute.
http://en.wikipedia.org/wiki/KAPDA
Search bugtrack and many other mailing lists for my old advisory's, exploits and 0day's.
Search google with keywords: cvh kapda
#13
Posted 22 February 2006 - 04:49 AM
you were talking about rxss/xss and my old whitepaper ...
the bug you were talking about and `v never been published was :
http://www.google.co...ttp://kapda.ir/
donno if it`s published by nother person yet ,just opened my old back-up files and pasted the URL above.
there were many in google as I remember specialy in its new services (translate,gmail and etc)
think some of them were reported.
Note : RXSS and XSS ( the same DOM hijacking) are low-risk vulnerbilities cause they affect client-side but notice if RXSS exists potential of HTTP Response Spilitting vulnerabilities is high (if CR/LF/Null are allowed)and there is no doubt RXSS is more dangerous than XSS cause validating local source(user input must contain client-side executable script [mobile code]) is much easier than validating contents of Remote Page (user input is just URL) which is not a threat by itself.
while ago (about two,three years ago) I was devloping a method to avoid XSS/RXSS and any malicious client side scrips,I never published the results donno if it still works ( as I tested recently AJAX and Syle .behaviour (HTC) are domains my method might cause limitations ).If there is anyone intrested into such researches i`d be glad to share my info with them.
Tnx
#14
Posted 12 March 2006 - 09:24 AM
0 user(s) are reading this topic
0 members, 0 guests, 0 anonymous users












